Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Asp.Net Core

ASP.NET Core: Why Antiforgery Token Validation Fails Only on Your Load-Balanced Servers

- 05.09.26 - ErcanOPAK

⚙️ Antiforgery Validation Passes Locally – Fails Randomly Once Load-Balanced

A form submission with antiforgery token protection works reliably in local development and single-server staging, and once deployed behind a load balancer across multiple servers, users start hitting random 400 errors – ‘the antiforgery token could not be decrypted’ – despite submitting the form normally, without doing anything unusual.

🐞 The Problem

BadHttpRequestException: The antiforgery cookie token and form
field token were not decrypted using the same key.

// Happens intermittently - specifically when the request that
// generated the form and the request that RECEIVED the submission
// were served by two DIFFERENT servers behind the load balancer.

🔍 Why This Happens

ASP.NET Core's antiforgery (and Data Protection more broadly) uses
encryption keys to protect the token - by default, each server
instance generates and stores its OWN keys locally, with no
built-in sharing between separate server processes. If server A
issues a form with a token encrypted using its own key, and the
form submission later lands on server B (a completely normal
outcome behind a load balancer with no session affinity), server B
cannot decrypt a token that was encrypted with a key it never had -
producing exactly this intermittent, server-dependent failure.

✅ The Fix: Share the Data Protection Keys Across All Servers

  • Configure ASP.NET Core’s Data Protection system to persist its keys to a SHARED location every server instance can read – a shared network file path, a Redis cache, Azure Blob Storage, or a shared database table – instead of each server’s own local, isolated storage.
  • Set an explicit, consistent Application Name across all server instances via SetApplicationName() – Data Protection uses this to isolate keys between different applications, and a mismatch here causes the exact same symptom even with shared key storage.
  • As an alternative fix specifically for antiforgery (if a full Data Protection key-sharing setup isn’t practical), enabling sticky sessions/session affinity on the load balancer ensures a user’s requests consistently hit the same server – simpler, but less resilient than proper key sharing.

📦 Sharing Data Protection Keys via a Shared Path

builder.Services.AddDataProtection()
    .PersistKeysToFileSystem(new DirectoryInfo(@"\\shared-server\keys"))
    .SetApplicationName("MyApp"); // must match EXACTLY across all servers

A load balancer promising ‘any server can handle any request’ only holds if every server actually shares what it needs to — an antiforgery key born on one machine was never meant to be understood by another.

— Backend Architect

Related posts:

.NET Core — ProblemDetails Improves API Debugging

ASP.NET Core: Why Two Environments Return Different Results From the Same Endpoint

Cleaner .NET APIs Using IEndpointFilter for Validation

Post Views: 2

Post navigation

Kubernetes: Fix Pods Evicted Because of Node Memory Pressure
Photoshop: Fix Layer Styles That Disappear After Converting a Layer to a Smart Object

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (624)
  • Add Constraint to SQL Table to ensure email contains @ (590)
  • Average of all values in a column that are not zero in SQL (553)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (526)
  • Find numbers with more than two decimal places in SQL (468)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps
  • Photoshop: Fix a Color Profile Mismatch That Makes Printed Output Look Nothing Like What You Saw On Screen
  • WordPress: Fix Search Results That Return Pages From a Theme You Deactivated Months Ago
  • Visual Studio: Fix a Test Project That Builds Fine Alone but Fails to Discover Any Tests After a NuGet Restore
  • ASP.NET Core: Fix a File Upload That Times Out on Slow Connections Only Because Kestrel’s Minimum Data Rate Feature Kicked In
  • JavaScript: Fix an Array Destructuring Default Value That Silently Never Applies Because null Was Passed Instead of Undefined

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com