Set up a paywall with the JWT function
Validate a JSON Web Token on each request to restricted content and control access by subscription with the JWT function from Azion Marketplace.
A paywall built with the JWT function has two parts: a function instance that validates the token, and a Rules Engine rule that runs the instance on the content you restrict. The JWT function is a serverless solution available in Azion Marketplace.
The origin application generates the token and sets its expiration. It also decides how access is controlled:
- The authentication method, such as OAuth, OpenID Connect, Auth0, or Keycloak.
- The number of access attempts or bytes a visitor spends before the sign-in prompt.
- How long a visitor browses without further authorization.
The token follows the Bearer Authentication Scheme, the standard for HTTP authentication. Every request carries a JSON object of authentication information in its header.
The JWT function validates that token on each request the application receives. It follows the business rules defined in the token, and those rules combine with the criteria you set in Rules Engine. The result decides the behavior: the request reaches the content, or it goes to the sign-in page of the origin application. Validation runs before the request reaches the origin, so the origin does not process an unauthorized request.
Prerequisites
- An application. To create one, refer to Applications quickstart.
- The JWT function installed on the account. To install it, refer to How to Install the JWT Integration.
- The list of KID and secret key pairs that the origin application uses to sign the token.
Instantiate the JWT function on the application
An application runs a function through a function instance, and the instance carries the Args passed into the execution context. For the full procedure on Azion Console and the Azion API, refer to Instantiate a function on an application.
The instance form shows the source code of the function in the Code field. That field is informational, and you cannot change it. The Args tab takes the list of KID (key ID) and secret key pairs that generate the signature of the token.
The origin application defines the pairs. To pass them to the instance:
Enter the pairs in this format:
The instance appears in the Functions Instances tab of the application. It does not run until a Rules Engine rule selects it.
Add the rule that runs the function
A rule states the conditions a request meets for its behaviors to run. A criterion reads as a logical operator, a variable, a comparison operator, and a string. A behavior reads as a logical operator, an action, and a function. The behavior that runs the function goes on the Default Rule of the application, or on a rule you create. Match the criteria to the paths you sell by subscription, and to the authentication the origin application already uses.
To put the behavior on a new rule:
Access Azion Console > Applications > your application.
Enter a name for the rule. For example: Paywall on news.
In the Criteria section, select the ${uri} variable.
Enter /news as the string. The criterion reads If ${uri} starts with /news.
Select the instance you named when you instantiated the function.
The rule runs the JWT function on every request whose URI starts with /news. New rules can take a few minutes to propagate.