---
name: azion-set-up-a-paywall-with-the-jwt-function
description: >-
  Validate a JSON Web Token on each request to restricted content and control access by subscription with the JWT function from Azion Marketplace.
---

# Set up a paywall with the JWT function

A paywall built with the JWT function has two parts: a function instance that validates the token, and a Rules Engine rule that runs the instance on the content you restrict. The JWT function is a serverless solution available in Azion Marketplace.

The origin application generates the token and sets its expiration. It also decides how access is controlled:

- The authentication method, such as OAuth, OpenID Connect, Auth0, or Keycloak.
- The number of access attempts or bytes a visitor spends before the sign-in prompt.
- How long a visitor browses without further authorization.

The token follows the Bearer Authentication Scheme, the standard for HTTP authentication. Every request carries a JSON object of authentication information in its header.

The JWT function validates that token on each request the application receives. It follows the business rules defined in the token, and those rules combine with the criteria you set in Rules Engine. The result decides the behavior: the request reaches the content, or it goes to the sign-in page of the origin application. Validation runs before the request reaches the origin, so the origin does not process an unauthorized request.

---

## Prerequisites

- An application. To create one, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- The JWT function installed on the account. To install it, refer to [How to Install the JWT Integration](/en/documentation/guides/application-development/integrations/jwt/).
- The list of KID and secret key pairs that the origin application uses to sign the token.

---

## Instantiate the JWT function on the application

An application runs a function through a function instance, and the instance carries the Args passed into the execution context. For the full procedure on Azion Console and the Azion API, refer to [Instantiate a function on an application](/en/documentation/guides/application-development/getting-started/instantiate-functions/).

The instance form shows the source code of the function in the **Code** field. That field is informational, and you cannot change it. The **Args** tab takes the list of KID (key ID) and secret key pairs that generate the signature of the token.

The origin application defines the pairs. To pass them to the instance:

1. **Go to the Args tab**

2. **Enter the KID and secret key pairs**

   Enter the pairs in this format:

   ```json
   [{
     "kids": {
       "4546D4AA7F62F01A833A7ABE354030E7": "D6CB2342E44EFB6DD628276F36DA2359",
       "D6CB2342E44EFB6DD628276F36DA2359": "60BD8ED7A768E8BD6925BEB0A691AADB",
       "60BD8ED7A768E8BD6925BEB0A691AADB": "4546D4AA7F62F01A833A7ABE354030E7"
     }
   }]
   ```

3. **Select Save**

The instance appears in the **Functions Instances** tab of the application. It does not run until a Rules Engine rule selects it.

---

## Add the rule that runs the function

A rule states the conditions a request meets for its behaviors to run. A criterion reads as a logical operator, a variable, a comparison operator, and a string. A behavior reads as a logical operator, an action, and a function. The behavior that runs the function goes on the **Default Rule** of the application, or on a rule you create. Match the criteria to the paths you sell by subscription, and to the authentication the origin application already uses.

To put the behavior on a new rule:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Go to the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   Enter a name for the rule. For example: `Paywall on news`.

5. **Select Request Phase**

6. **Select the variable in the Criteria section**

   In the **Criteria** section, select the `${uri}` variable.

7. **Select starts with as the comparison operator**

8. **Enter the string**

   Enter `/news` as the string. The criterion reads `If ${uri} starts with /news`.

9. **In the Behaviors section, select Run Function**

10. **Select the JWT instance**

    Select the instance you named when you instantiated the function.

11. **Select Save**

The rule runs the JWT function on every request whose URI starts with `/news`. New rules can take a few minutes to propagate.

> **Note**
>
> The function returns an HTTP status code `400` or `401` when the token it receives is invalid. The code depends on the error.

---

## Next steps

- [Instantiate a function on an application](/en/documentation/guides/application-development/getting-started/instantiate-functions.md): The Console and API procedures for the instance, and the rules that govern its Args.
- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md): Every variable, comparison operator, and behavior a rule can carry.
- [Create an application rule](/en/documentation/guides/application-development/getting-started/work-with-rules-engine.md): Add, order, and edit the rules of an application.
- [How to Install the JWT Integration](/en/documentation/guides/application-development/integrations/jwt.md): Install JWT from Azion Marketplace and run it on a firewall.
