.NET Core 2 MVC客户端+IdentityServer4获取外部用户AccessToken问题咨询
Hey there! Let's work through the issue you're hitting with your authentication setup. When you added options.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme to your AddAuthentication configuration, you likely ran into a conflict because of how .NET Core 2.x handles default authentication schemes.
Why the Exception Happens
In .NET Core 2.x, the DefaultScheme acts as a fallback for all other default scheme types (Authenticate, Challenge, SignIn, SignOut) if they aren't explicitly set. When you explicitly set DefaultAuthenticateScheme while already having DefaultScheme pointed to the cookie scheme, you're creating redundant configuration that can confuse the authentication pipeline. This often leads to exceptions like conflicting scheme registrations or missing handler errors.
Correct Configuration for Your Scenario
For an MVC client integrating with IdentityServer4 (especially when you need to retrieve external user access tokens), here's the standard, working configuration you should use:
services.AddAuthentication(options => { // Default scheme for all auth operations (authenticate, sign-in/sign-out) is the cookie options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; // When we need to challenge the user (redirect to login), use OIDC options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme; }) // Register the cookie authentication handler .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme) // Register the OpenID Connect handler for interacting with IdentityServer4 .AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme, options => { options.Authority = "https://your-identityserver-instance-url"; options.ClientId = "your-mvc-client-id"; options.ClientSecret = "your-client-secret"; // Required if using Authorization Code flow options.ResponseType = "code id_token"; // Hybrid flow (common for MVC apps) options.SaveTokens = true; // Critical: saves access/refresh/id tokens to the cookie // Add scopes for the resources you need access to options.Scope.Add("openid"); options.Scope.Add("profile"); options.Scope.Add("your-target-api-scope"); });
Key Notes for Retrieving the Access Token
Once your configuration is fixed, you can easily fetch the access token in your controller actions using:
var accessToken = await HttpContext.GetTokenAsync("access_token");
Just make sure options.SaveTokens = true is set in your OIDC configuration—this tells the handler to persist the tokens in the authentication cookie so you can retrieve them later.
Additional Troubleshooting Steps
If you still encounter exceptions after adjusting the configuration:
- Verify
app.UseAuthentication()is called in yourConfiguremethod (it must come beforeapp.UseMvc()). - Ensure both the cookie and OIDC authentication handlers are properly registered with their respective scheme names.
- Check the exact exception message—common issues include "No authentication handler registered for scheme" (if you misspell a scheme name) or scheme conflicts (if you set conflicting defaults).
内容的提问来源于stack exchange,提问作者Saifal Maluk

