I made a mistake in the handler which erased anti-forgery token from the session. I was getting error that I have invalid antiforgery token from the client, which was quite confusing. I propose adding some warning when anti-forgery middleware is used but the token is missing in the session, so it is more clear that the problem is not on the client.