Azion API
Call the Azion API v4 with a personal token, read its list pages and errors, and check the version and rate limits that apply to your requests.
An application programming interface (API) lets a program act on a service without its web interface. A REST API gives each object of the service its own URL: the client reads the object with GET, creates it with POST, changes it with PUT or PATCH, and removes it with DELETE. Because every action is an HTTP request, the same call runs from a terminal, a script, or a CI/CD pipeline.
Azion API exposes the resources of your Azion account as a REST API over HTTPS, at the base URL https://api.azion.com/v4. Each request carries a personal token, responses return JSON, and each change also appears in Azion Console. Use the Azion API to create, read, update, and delete applications, firewalls, functions, network lists, workloads, and the other resources of your account from your own code.
You can also manage the same resources with the Azion CLI or the Azion Terraform Provider. To query metrics, events, billing, and consumption data, use the GraphQL API.
Get started Go to the API referenceRequest structure
A request names a resource path under the base URL and sends the personal token in a header. This request lists the IDs of the workloads in an account:
A 200 returns one page of results:
- Path: resource endpoints sit under
/v4/workspace/, such as/v4/workspace/workloadsand/v4/workspace/network_lists. - Header:
Authorizationcarries the personal token with theTokenscheme. - Query parameters:
page_size=100asks for up to 100 results on the page, andfields=idkeeps only theidof each result. - List envelope:
countis the number of workloads in the account,total_pagesandpageplace the page in the list, andresultsholds the workloads.nextandpreviousarenullbecause the list has one page.
If you have called a REST API that returns JSON, the model transfers unchanged: a method, a URL, a credential header, and a JSON body. The Azion API reference lists every path, method, parameter, and response. The API serves its OpenAPI specification at https://api.azion.com/v4/openapi/openapi.yaml.
API clients
Your own code is one client of the Azion API among several. The Azion CLI and the Azion Terraform Provider reach the same endpoints.
- Your code, or an HTTP client such as
curl, sends a request tohttps://api.azion.com/v4with your personal token in theAuthorizationheader. - The Azion CLI and the Azion Terraform Provider call the same API.
- The API authenticates the token, then creates, reads, changes, or deletes the resources of your account.
- Azion Console shows the same resources, so a change made through the API appears there too.
Methods and errors
Most endpoints take the same methods, split between a collection path and an item path, and errors share one response shape:
- Methods: a collection path, such as
/v4/workspace/network_lists, takesGETto list andPOSTto create. An item path, such as/v4/workspace/network_lists/<network-list-id>, takesGET,PUT,PATCH, andDELETE. Another method returns405with code10007, and theAllowheader of the response lists the methods the path takes. - Success bodies: a request for one resource returns it inside
data. APOSTor aPATCHreturns"state": "executed"besidedata, and aDELETEreturns only{"state": "executed"}. - Error bodies: an error returns an
errorsarray. Each item carries acode, atitle, adetail, astatuswritten as a string, and usually asourcethat names the header or the body field at fault. APOSTthat omits two required fields returns two items, one per field.
For the errors a request can return and how to fix each one, refer to Troubleshoot Azion API.
Authentication
Every request to the Azion API carries a personal token in the Authorization header, with the Token scheme:
The API also accepts a personal token with the Bearer scheme, as Authorization: Bearer [TOKEN VALUE], and accepts the Token scheme written in lowercase. You create a personal token in Azion Console or with the Azion CLI, and Azion shows its value only once, at creation. To create one, refer to Manage personal tokens.
A request without the header returns 401 with code 10002. A request whose token the API does not accept returns 401 with code 10001. Both responses carry the header WWW-Authenticate: Bearer realm="api".
Pagination and query parameters
A list request returns one page of results, and five query parameters choose which page and what each result holds. The page count comes back in total_pages, and next and previous are null when no next or previous page exists. To read the following page, send the same request with page increased by one.
| Parameter | Effect |
|---|---|
page | Selects one page of the list, counted from 1. |
page_size | Sets the number of results per page: 10 by default, 100 at most. |
fields | Keeps only the fields in a comma-separated list, such as fields=id,name. |
ordering | Sorts the list by one field, such as ordering=name. A - before the field sorts in descending order, as in ordering=-id. |
search | Narrows the list to the results that match a search term, such as search=astro. |
An ordering value that names no field is ignored: the request returns 200 and the list keeps its default order by ID. On a single resource, fields can return more than the fields you named: on a network list, fields=id,name also returns is_versioned and version. For the terms the API uses, refer to Glossary.
API versions
Azion API v4 is the version that these pages document, served at https://api.azion.com/v4, and its OpenAPI specification declares version 4.0.0. An account moves to it from API v3 through a migration. For the resources and endpoints that change, refer to API v4 Migration. To check the version of your account, refer to Verify your account’s API version.
Limits
Two bounds apply to every list request, and each returns an error past its value:
| Limit | Value | Past the value |
|---|---|---|
Results per page, page_size | 10 by default, 100 at most | 400, code 10097 |
Page number, page | From 1 to the total_pages value of the list | 404, code 10004 |
Every authenticated response also carries four rate limit headers. The headers look like this:
X-RateLimit-Limit is 200 and X-RateLimit-Scope is global-default on every response. X-RateLimit-Remaining counts down from the limit as you send requests. X-RateLimit-Reset gives the time of the next reset as an ISO 8601 timestamp with no time zone, about one minute after the request.