# Azion CLI waf-exceptions

The Azion CLI `waf-exceptions` commands create, list, describe, update, and delete the [exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules/) of a Web Application Firewall (WAF). An exception exempts part of a request from a WAF rule. Every command takes the `--waf-id` of the WAF that holds the exceptions. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create waf-exceptions` creates an exception on a WAF from a JSON file:

```bash
azion create waf-exceptions [flags]
```

| Flag           | Short | Type   | Default  | Description                                                                                                                                                                                                                                                                          |
| -------------- | ----- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--active`     | —     | string | `"true"` | Turns the exception on (`true`) or off (`false`).                                                                                                                                                                                                                                    |
| `--conditions` | —     | string | —        | Conditions of the exception, in JSON format.                                                                                                                                                                                                                                         |
| `--file`       | —     | string | —        | **Required.** Path to a JSON file with the attributes of the exception. Use `-` to read the JSON from standard input. Without it, the command fails with `Error: failed to create the WAF Exception: ["Ensure this field has at least 1 elements."]`, whatever `--conditions` holds. |
| `--name`       | —     | string | —        | Name of the exception.                                                                                                                                                                                                                                                               |
| `--operator`   | —     | string | —        | Operator that matches the conditions: `regex` or `contains`.                                                                                                                                                                                                                         |
| `--path`       | —     | string | —        | Path the exception applies to.                                                                                                                                                                                                                                                       |
| `--rule-id`    | —     | int    | —        | ID of the WAF rule the exception applies to.                                                                                                                                                                                                                                         |
| `--waf-id`     | —     | int    | —        | ID of the WAF that holds the exception.                                                                                                                                                                                                                                              |

This file describes an active exception named `my-exception`. It exempts the query string parameter named `docs` from WAF rule `1000` on requests whose path contains `/my-path`:

```json
{
  "name": "my-exception",
  "rule_id": 1000,
  "path": "/my-path",
  "operator": "contains",
  "active": true,
  "conditions": [
    {
      "match": "specific_query_string_name",
      "name": "docs"
    }
  ]
}
```

This command creates the exception from the file `exception.json` on the WAF with ID `12347`:

```bash
azion create waf-exceptions --waf-id 12347 --file exception.json
```

The command prints the ID of the exception:

```text
Created WAF Exception with ID 123486
```

---

## List

`azion list waf-exceptions` lists the exceptions of one WAF, 50 to a page:

```bash
azion list waf-exceptions [flags]
```

| Flag          | Short | Type   | Default | Description                                                                                                      |
| ------------- | ----- | ------ | ------- | ---------------------------------------------------------------------------------------------------------------- |
| `--details`   | —     | —      | —       | Adds the `LAST EDITOR` and `LAST MODIFIED` columns to the `ID`, `NAME`, `RULE ID`, `PATH`, and `ACTIVE` columns. |
| `--filter`    | —     | string | —       | Name to filter the list by.                                                                                      |
| `--order-by`  | —     | string | —       | Field to sort the list by.                                                                                       |
| `--page`      | —     | int    | `1`     | Number of the page to return.                                                                                    |
| `--page-size` | —     | int    | `50`    | Number of exceptions on each page.                                                                               |
| `--waf-id`    | —     | int    | —       | ID of the WAF whose exceptions to list.                                                                          |

This command lists the exceptions of the WAF with ID `12347`:

```bash
azion list waf-exceptions --waf-id 12347
```

The command prints one row per exception:

```text
ID      NAME          RULE ID         PATH      ACTIVE
123486  my-exception  86463130383232  /my-path  true
```

---

## Describe

`azion describe waf-exceptions` prints the settings of one exception:

```bash
azion describe waf-exceptions [flags]
```

| Flag             | Short | Type | Default | Description                             |
| ---------------- | ----- | ---- | ------- | --------------------------------------- |
| `--exception-id` | —     | int  | —       | ID of the exception to describe.        |
| `--waf-id`       | —     | int  | —       | ID of the WAF that holds the exception. |

This command describes the exception with ID `123486` on the WAF with ID `12347`:

```bash
azion describe waf-exceptions --waf-id 12347 --exception-id 123486
```

The command prints the rule, the path, the operator, and the state of the exception:

```text
ID:              123486
Rule ID:         1000
Name:            my-exception
Path:            "/my-path"
Operator:        contains
Active:          true
Last Editor:     you@example.com
Last Modified:   "2026-01-01T12:00:00.490688Z"
```

With `--format json`, the command prints the full object: `active`, `conditions`, `id`, `last_editor`, `last_modified`, `name`, `operator`, `path`, and `rule_id`. The `conditions` array is in the JSON output only.

---

## Update

`azion update waf-exceptions` changes the name, the rule, the path, the conditions, or the state of an exception:

```bash
azion update waf-exceptions [flags]
```

| Flag             | Short | Type   | Default  | Description                                                                                      |
| ---------------- | ----- | ------ | -------- | ------------------------------------------------------------------------------------------------ |
| `--active`       | —     | string | `"true"` | Turns the exception on (`true`) or off (`false`).                                                |
| `--conditions`   | —     | string | —        | Conditions of the exception, in JSON format.                                                     |
| `--exception-id` | —     | int    | —        | ID of the exception to update.                                                                   |
| `--file`         | —     | string | —        | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input. |
| `--name`         | —     | string | —        | New name of the exception.                                                                       |
| `--operator`     | —     | string | —        | Operator that matches the conditions: `regex` or `contains`.                                     |
| `--path`         | —     | string | —        | Path the exception applies to.                                                                   |
| `--rule-id`      | —     | int    | —        | ID of the WAF rule the exception applies to.                                                     |
| `--waf-id`       | —     | int    | —        | ID of the WAF that holds the exception.                                                          |

---

## Delete

`azion delete waf-exceptions` deletes an exception from a WAF:

```bash
azion delete waf-exceptions [flags]
```

| Flag             | Short | Type | Default | Description                             |
| ---------------- | ----- | ---- | ------- | --------------------------------------- |
| `--exception-id` | —     | int  | —       | ID of the exception to delete.          |
| `--waf-id`       | —     | int  | —       | ID of the WAF that holds the exception. |

---

## Use a JSON file

`azion create waf-exceptions` reads the attributes of an exception from a JSON file with `--file`. The file carries `name`, `rule_id`, `path`, `operator`, `active`, and `conditions`, and the WAF ID goes on the command line with `--waf-id`.

Each entry of `conditions` takes a `match` value, which names the part of the request the exception covers. The `specific_query_string_name` value also takes a `name` key, which holds the name of the query string parameter. For every value `match` accepts and the keys each one takes, refer to [Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules/#match-zones).

When the platform refuses a condition, the error the command prints does not name the field. A `match` value the platform does not accept fails with this error:

```text
Error: failed to create the WAF Exception: ["\"any_query_string\" is not a valid choice."]
```

A `specific_query_string_name` condition that carries `value` in place of `name` fails with `Error: failed to create the WAF Exception: ["This field is required."]`. To see which field the platform refused, add `--debug` and keep the line that carries the detailed error:

```bash
azion create waf-exceptions --waf-id 12347 --file exception.json --debug 2>&1 | grep 'Detailed error message'
```

The line names the field by its JSON pointer, after `Source:`:

```text
2026-01-01T12:00:00.320-0300	DEBUG		{"Detailed error message from API": "Error: Required Field - Source: /data/conditions/0/name - Message: This field is required.\n"}
```

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules.md): The fields of an exception, the match zones its conditions take, and the errors the platform returns.
- [Azion CLI waf](/en/documentation/devtools/cli/resources/waf.md): The commands that create and manage the WAF an exception belongs to.
- [Azion CLI firewall](/en/documentation/devtools/cli/resources/firewall.md): The commands that create and manage the firewall a WAF runs on.
