To be successfully validated, the org.acegisecurity.providers.anonymous.AnonymousAuthenticationToken.getKeyHash must match this class' AnonymousAuthenticationProvider.getKey() .