---
title: "HTTP-Only Anti-Forgery Token in ASP.NET Zero"
description: "ASP.NET Zero is the base solution for building robust and scalable web applications. Unlock your full potential today!"
url: "https://aspnetzero.com/blog/http-only-anti-forgery-token-in-asp.net-zero"
image: "https://aspnetzero.com/Images/Blog/http-only-anti-forgery-token-in-asp.net-zero.png"
---

[Blog](https://aspnetzero.com/blog)

# HTTP-Only Anti-Forgery Token in ASP.NET Zero

09 March 2023 2 min read [Security](https://aspnetzero.com/blog/topics/security)

![HTTP-Only Anti-Forgery Token in ASP.NET Zero](https://aspnetzero.com/Images/Blog/http-only-anti-forgery-token-in-asp.net-zero.png)

Share [X](https://twitter.com/intent/tweet?url=https%3A%2F%2Faspnetzero.com%2Fblog%2Fhttp-only-anti-forgery-token-in-asp.net-zero&text=HTTP-Only+Anti-Forgery+Token+in+ASP.NET+Zero) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Faspnetzero.com%2Fblog%2Fhttp-only-anti-forgery-token-in-asp.net-zero) [Reddit](https://reddit.com/submit?url=https%3A%2F%2Faspnetzero.com%2Fblog%2Fhttp-only-anti-forgery-token-in-asp.net-zero&title=HTTP-Only+Anti-Forgery+Token+in+ASP.NET+Zero) [Hacker News](https://news.ycombinator.com/submitlink?u=https%3A%2F%2Faspnetzero.com%2Fblog%2Fhttp-only-anti-forgery-token-in-asp.net-zero&t=HTTP-Only+Anti-Forgery+Token+in+ASP.NET+Zero)

# Enhancing Security with HTTP-Only Anti-Forgery Tokens in ASP.NET Zero

In this article, we'll explore how to set **AntiForgery** cookie **HttpOnly** in ASP.NET Zero. We'll start by **explaining** what **AntiForgery** is and why it's **important**, then provide code examples to help you **implement** HttpOnly AntiForgery in **your** own **ASP.NET Zero** MVC projects.

First, let me explain what AntiForgery is and why it's important.

AntiForgery is a commonly used **security** measure in **web** applications. This method is used to **validate** that a user's **session** is still valid between one page and the next. This provides **protection** against **malicious individuals** taking over **sessions** or performing **fake** transactions.

So, what does making the AntiForgery cookie HttpOnly mean? HttpOnly means that a cookie **cannot be accessed by JavaScript**. This prevents malicious users from **accessing** the **cookie** with **JavaScript** code and **taking over** the **session**.

Now, we can create a project to make the AntiForgery cookie HttpOnly and add the incoming cookie to the **request headers** through **middleware**.

To make the AntiForgery cookie HttpOnly, update the following code inside `Layout\_Layout.cshtml`:

**Note:** If you are using many layouts, you can add this code to all of them. (Example: `Account\Login.cshtml`)

```csharp
AbpAntiForgeryManager.SetCookie(Context, null, new CookieOptions
{
    HttpOnly = true
});
```

This code sets the **AntiForgery** cookie to be **HttpOnly**.

Next, we'll **create** a **middleware** to add the **incoming cookie** to the **request headers**. To do this, create a middleware class named `XsrfMiddleware` in the `Startup` folder of your project. Then, add the following code to the class:

```csharp
using Microsoft.AspNetCore.Builder;

namespace MvcAntiForgeryExample.Web.Startup;

public static class XsrfMiddleware
{
    public static IApplicationBuilder UseHttpOnlyAntiForgeryToken(this IApplicationBuilder app)
    {
        return app.Use(async (ctx, next) =>
        {
            var tokens = ctx.Request.Cookies["XSRF-TOKEN"];
            if (string.IsNullOrEmpty(tokens) == false)
            {
                ctx.Request.Headers.Add("X-XSRF-TOKEN", tokens);
            }
            await next();
        });
    }
}
```

Then add the following code to the `Configure` method of `Startup.cs`:

```csharp
public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    app.UseHttpOnlyAntiForgeryToken();

    .
    .
    .
}
```

That's it! With these changes, your application is now **more secure** against session **hijacking** and **fake transactions**.

![AntiForgery](https://aspnetzero.com/Images/Blog/http-only-antiforgery-token.png)

## Ready to build?

Get full source code, premium support, and enterprise-ready features with ASP.NET Zero.

[See pricing plans](https://aspnetzero.com/pricing)

## Have questions before purchasing?

Schedule a free consultation with our team to find the right plan for your project.

[Schedule a meeting](https://aspnetzero.com/schedule-meeting)

## You might also like

### [Business Benefits of Using ASP.NET Zero for Enterprise Software Development](https://aspnetzero.com/blog/business-benefits-of-aspnetzero)

11 September 2026

### [Common Mistakes and Errors When Hosting ASP.NET Core Apps](https://aspnetzero.com/blog/common-mistakes-and-errors-hosting-aspnet-core-apps)

26 August 2026

### [Using AutoMapper After Migrating to Mapperly](https://aspnetzero.com/blog/using-automapper-after-migrating-to-mapperly)

04 August 2026

## Recent posts

### [Business Benefits of Using ASP.NET Zero for Enterprise Software Development](https://aspnetzero.com/blog/business-benefits-of-aspnetzero)

11 September 2026

### [Common Mistakes and Errors When Hosting ASP.NET Core Apps](https://aspnetzero.com/blog/common-mistakes-and-errors-hosting-aspnet-core-apps)

26 August 2026

### [Using AutoMapper After Migrating to Mapperly](https://aspnetzero.com/blog/using-automapper-after-migrating-to-mapperly)

04 August 2026

## Start building with ASP.NET Zero

Full source code, premium support, Angular, React & MVC UI options.

[View pricing](https://aspnetzero.com/pricing)

## Topics
