iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
ASP.NET Core MVC filters run inside MVC after it selects an action. They let you add behavior around specific stages—such as authorization, model binding, action execution, or result rendering—without repeating it in every action method. Use a filter when the behavior needs MVC-specific context; use middleware for concerns that apply more broadly across requests, and authorization policies for access rules.
Where filters fit in the request pipeline
Filters are part of MVC’s action-invocation pipeline, not a substitute for ASP.NET Core middleware. They run after MVC has selected an action. The sequence is:
- Authorization filters
- Resource filters
- Model binding
- Action filters and action execution
- Action result conversion
- Exception filters, when an eligible exception occurs
- Result filters
- Result execution, such as rendering a view or serializing an API response
Resource filters wrap most of the remaining MVC pipeline. Result and resource filters also run on the outward path after inner work completes. Exception filters are not a normal step that always runs; they handle certain unhandled exceptions from specified MVC stages.
What each filter type does
Authorization filters
Authorization filters run first. They can stop the filter pipeline when access is denied. For access rules, Microsoft recommends authorization policies rather than custom authorization filters. Do not throw an exception from an authorization filter expecting an exception filter to handle it; that exception will not be handled there.
#1 Best Overall
Resource filters
Resource filters run after authorization and surround most of what follows, including work before model binding. Choose one when code must run before model binding or needs to short-circuit much of MVC processing.
Action filters
Action filters run immediately before and after an action method. They can inspect or modify action arguments and results. Implement synchronous behavior with IActionFilter or asynchronous behavior with IAsyncActionFilter.
An action filter can stop action execution by setting ActionExecutingContext.Result and not calling the next delegate. This also prevents subsequent action filters in that chain from running.
Exception filters
Exception filters handle certain unhandled exceptions raised while creating a controller or Razor Page, during model binding, in action filters, or in an action method. They do not catch exceptions from resource filters, result filters, or MVC result execution.
Microsoft recommends exception-handling middleware for general exception handling. An exception filter is more appropriate when error output needs to vary by action—for example, returning JSON for an API endpoint and HTML for a view.
Result filters
Result filters surround execution of an action result, such as Razor view processing or API serialization. Standard result filters do not run when authorization or resource filters short-circuit, or when an exception filter produces a result. Use IAlwaysRunResultFilter or its asynchronous counterpart when the result filter must also cover action results created through those short-circuit paths.
Rank #3
After the response has been sent, an after-result callback cannot change it.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Endpoint and Razor Page filters
Endpoint filters are a separate, adjacent mechanism that can be used with controller actions and route-handler endpoints. They are not supported in Razor Pages. Razor Page filters surround page handlers; filter attributes cannot be applied directly to Razor Page handler methods, and action filters are not supported in Razor Pages.
How filter order works
Filters can be registered globally, applied to a controller or Razor Page model, or applied to an action where that filter type is supported. By default, global filters wrap controller-level filters, which wrap action-level filters. Before code runs from the outer scope inward; after code runs in reverse.
Implement IOrderedFilter to specify an Order. The order value takes precedence over scope: lower values run earlier on the way in and later on the way out. Built-in filters generally use order zero; controller-level filters have a documented int.MinValue order detail. Check ordering when combining filters from different scopes, since explicit order can change the default nesting.
How to create and register a custom action filter
For a synchronous filter, implement IActionFilter and put pre-action logic in OnActionExecuting and post-action logic in OnActionExecuted. For asynchronous work, implement IAsyncActionFilter and control the action pipeline through its next delegate.
Register a filter globally through MVC options when it should apply across MVC actions, or apply it at controller or action scope when the behavior is narrower. For dependency injection, Microsoft documents ServiceFilterAttribute and TypeFilterAttribute as construction options. Select the pattern that matches how the filter’s dependencies are registered and supplied.
Best Value
Be deliberate about instance lifetime. Adding a filter instance directly rather than its type makes that instance a singleton; Microsoft warns that this is not thread-safe. Avoid storing mutable per-request data on a shared filter instance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choosing between a filter, middleware, and a policy
- Use an authorization policy for access-control rules.
- Use middleware for general exception handling and concerns that should apply across the request pipeline rather than depend on an MVC action.
- Use a filter when behavior needs MVC action-pipeline context or a specific MVC boundary, such as action arguments, action results, or action-specific error presentation.
- Use a resource filter when logic must run before model binding.
- Use a result filter to surround view rendering or formatter execution, accounting for the short-circuit paths that bypass standard result filters.
For endpoints using [ApiController], automatic model-state validation and 400 responses may already cover validation handling, making a custom model-validation action filter redundant.
Microsoft’s filter guidance
Microsoft identifies authorization and response caching among built-in filter concerns, and describes logging, configuration, caching, authorization, and error handling as examples of cross-cutting behavior that custom filters can support. The framework documentation also distinguishes filters from broader middleware and recommends policies and exception middleware for the cases where those mechanisms fit better.
Free tools Windows power users keep installed
One-click scans. No signup required.
For implementation details, see Microsoft Learn: Filters in ASP.NET Core, the ASP.NET Core MVC filters API reference, and Microsoft’s ASP.NET Core MVC overview.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

