---
name: azion-connect-an-application-to-an-origin
description: >-
  Create a connector to an HTTP origin, then send the requests of an application to it with a Rules Engine rule, from Azion Console or the API.
---

# Connect an application to an origin

You can connect an [application](/en/documentation/platform/applications/) to an origin with a [connector](/en/documentation/platform/connectors/) and a [Rules Engine](/en/documentation/platform/applications/rules-engine/) rule that sets it. The origin, also called the backend, is the server Azion retrieves your content from. It can be an object storage service, a cloud server, or other infrastructure that hosts your application's assets or data. You create both from Azion Console or the API.

To serve the objects of a bucket, refer to [Use a bucket as an application origin](/en/documentation/guides/application-development/data/use-bucket-as-origin/). To spread requests across several addresses, refer to [Balance traffic across multiple origins](/en/documentation/guides/application-performance/availability/multiple-origins/). An account that [has not migrated to API v4](/en/documentation/guides/application-security/access-and-compliance/verify-account-migration/) configures origins in the legacy Origins of the application. For more information, refer to [Origins](/en/documentation/platform/connectors/origins/).

---

Choose the interface you work in. The prerequisites and the procedures change with your choice.

## Prerequisites

- An application served by a [workload](/en/documentation/platform/workloads/). To create both, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**API**

- A personal token, sent in the `Authorization` header as `Token [TOKEN VALUE]`. To create one, refer to [Manage a personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/).
- `curl`, or another HTTP client.
- The ID of the application. Azion Console shows it in the address of the application's page, after `/applications/edit/`.

---

## Create a connector to the origin

A connector holds the address of the origin and the options Azion uses to connect to it. In Azion Console, you set up connectors in the Connectors menu, not in a tab of the application. For each field of that form, refer to [Connector settings](/en/documentation/platform/connectors/settings/#addresses). The connector in this section reaches `httpbin.org` over HTTPS.

**Console**

To create the connector in Azion Console:

1. **Open the Connectors page**

   Access [Azion Console](https://console.azion.com/) > **Connectors**.

2. **Start a new connector**

3. **Name the connector**

   In the **General** section, enter `httpbin-connector` in **Name**.

4. **Select the HTTP type**

   In the **Connector Type** section, select the HTTP type.

5. **Enter the address of the origin**

   In the **Address Management** section, enter `httpbin.org` in **Address**. An address with a protocol or a port is refused with `Address must be a valid IPv4, IPv6, or hostname, without protocol or port.`

6. **Send httpbin.org in the Host header**

   Enter `httpbin.org` as the host the connector sends in the `Host` header to the origin.

7. **Connect to the origin over HTTPS**

   In **Transport Protocol Policy**, select the option that forces HTTPS.

8. **Select Create**

Azion Console shows `Connector successfully created`.

**API**

To create the connector with the API, send a `POST` request to the connectors endpoint:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/connectors \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "httpbin-connector",
  "type": "http",
  "attributes": {
    "addresses": [
      {
        "address": "httpbin.org"
      }
    ],
    "connection_options": {
      "transport_policy": "force_https",
      "host": "httpbin.org"
    }
  }
}'
```

The body sets four values:

| Key                | What it sets                                                                                           |
| ------------------ | ------------------------------------------------------------------------------------------------------ |
| `type`             | `http` connects to an HTTP or HTTPS origin.                                                            |
| `addresses`        | The address of the origin. A connector to a single origin carries one address.                         |
| `transport_policy` | `force_https` makes Azion connect to the origin over HTTPS, whatever protocol the user's request used. |
| `host`             | The value Azion sends in the `Host` header to the origin.                                              |

The API answers `202` and returns the connector:

```json
{
  "state": "pending",
  "data": {
    "version_id": null,
    "version_state": null,
    "id": <connector-id>,
    "name": "httpbin-connector",
    "last_editor": "user@example.com",
    "last_modified": "2026-01-01T12:00:00.190116Z",
    "created_at": "2026-01-01T12:00:00.190133Z",
    "active": true,
    "product_version": "1.0",
    "type": "http",
    "attributes": {
      "addresses": [
        {
          "active": true,
          "address": "httpbin.org",
          "http_port": 80,
          "https_port": 443,
          "modules": null
        }
      ],
      "connection_options": {
        "dns_resolution": "both",
        "transport_policy": "force_https",
        "http_version_policy": "http1_1",
        "host": "httpbin.org",
        "path_prefix": "",
        "following_redirect": false,
        "real_ip_header": "X-Real-IP",
        "real_port_header": "X-Real-PORT"
      },
      "modules": {
        "load_balancer": {
          "enabled": false,
          "config": null
        },
        "origin_shield": {
          "enabled": false,
          "config": null
        }
      }
    },
    "is_versioned": false,
    "version": null
  }
}
```

The response fills in what the body left out. The connector and its address are active, the address uses port `80` for HTTP and `443` for HTTPS, and [Load Balancer](/en/documentation/platform/connectors/#load-balancer) and [Origin Shield](/en/documentation/platform/connectors/#origin-shield) are disabled under `modules`. Copy the value of `data.id`: the rule that sends requests to the connector names it by this ID.

### Address, path, and Host header

Enter the address as a domain name or an IPv4 or IPv6 address, without `http://` or `https://`. The `transport_policy` key sets the protocol instead. When the content sits under a path, such as `https://bucket.s3.amazonaws.com/applications/your-app`, split the URL. The hostname, `bucket.s3.amazonaws.com`, goes in the address, and the path, `/applications/your-app`, goes in the connector's path prefix, `path_prefix`. An address that carries the path makes the requests to the origin fail.

The `host` key takes a fixed domain name or the `${host}` variable. Azion sends a fixed name, such as `httpbin.org`, whatever domain the user requested. Use a fixed name when the origin serves a single virtualhost, or answers a virtualhost at an address other than the one in DNS. A fixed name also fits an origin that needs a specific hostname for routing, certificate matching, or access control. `${host}`, the default, forwards the `Host` header of the user's request, for an origin that serves several virtualhosts from one address. An empty value is refused.

> **Caution**
>
> Some origins check the `Host` header, through Host-based access controls, an IP allowlist tied to a hostname, or a configuration that validates it. Such an origin can reject requests after the value changes. Check the virtualhost configuration of the origin before you change `host`.

An origin that requires HMAC authentication, such as a private object storage bucket, needs a valid region, access key, and secret key on the connector. Without valid credentials the origin refuses the request: the S3 endpoint of Azion Object Storage answers an unsigned request with `401` and `UnauthorizedAccess`. A change to the address or the Host header of a connector reaches every rule that sets it. Review those rules before you change a connector that serves production traffic.

---

## Send requests to the connector

A connector receives no request until a rule sets it. The rule in this section runs in the Request Phase of the application. Its criterion matches every path, with the `${uri}` variable, the `starts_with` operator, and `/` as the argument, and its behavior sets the connector. An application starts with no rules, so this rule is what sends its requests to the origin.

To send a single path instead, such as `/httpbin`, use the `is_equal` operator with that path as the argument. With that rule alone, a request to any other path receives `404`.

The `${uri}` variable works on every application. A criterion on `${request_uri}` needs [Application Accelerator](/en/documentation/platform/applications/application-accelerator/quickstart/) on the application. For every variable and operator, refer to [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine/#criteria).

**Console**

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications**, then select your application.

2. **Select the Rules Engine tab**

3. **Start a rule**

   Select **+ Rule**.

4. **Name the rule**

   In the **General** section, enter a **Name**, such as `send-to-httpbin`.

5. **Select the phase**

   In the **Phase** section, select *Request Phase*. A rule keeps the phase it is created in.

6. **Set the criterion**

   In the **Criteria** section, set the variable to `${uri}`, the operator to `starts_with`, and the argument to `/`.

7. **Set the connector**

   In the **Behaviors** section, select *Set Connector*, then select your connector in **Connector**.

8. **Save the rule**

   Select **Save**.

The rule appears in the **Rules Engine** tab of the application, under **Request**.

**API**

To create the rule with the API, send a `POST` request to the `request_rules` endpoint of the application. Replace `<application-id>` with the ID of your application, and `<connector-id>` with the ID of the connector:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/applications/<application-id>/request_rules \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "send-to-httpbin",
  "active": true,
  "criteria": [
    [
      {
        "variable": "${uri}",
        "conditional": "if",
        "operator": "starts_with",
        "argument": "/"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_connector",
      "attributes": {
        "value": <connector-id>
      }
    }
  ]
}'
```

The API answers `202` and returns the rule:

```json
{
  "state": "pending",
  "data": {
    "id": <rule-id>,
    "name": "send-to-httpbin",
    "active": true,
    "criteria": [
      [
        {
          "conditional": "if",
          "variable": "${uri}",
          "operator": "starts_with",
          "argument": "/"
        }
      ]
    ],
    "behaviors": [
      {
        "type": "set_connector",
        "attributes": {
          "value": <connector-id>
        }
      }
    ],
    "description": "",
    "order": 0,
    "last_editor": "user@example.com",
    "last_modified": "2026-01-01T12:00:26.750242Z",
    "created_at": "2026-01-01T12:00:26.750262Z"
  }
}
```

The rule is the first of the application's Request Phase, at `order` `0`.

The same rule with `${request_uri}` in place of `${uri}`, on an application without Application Accelerator, is refused with `400`:

```json
{
  "errors": [
    {
      "code": "25047",
      "title": "Missing Required Modules",
      "detail": " It requires any of the following modules to be enabled: ['application_accelerator'].",
      "status": "400",
      "source": {
        "pointer": "/data/criteria/0/0/variable"
      },
      "meta": {
        "message_prefix": "",
        "owner_modules": "any",
        "missing_required_modules": [
          "application_accelerator"
        ]
      }
    }
  ]
}
```

The error points at the variable in `source.pointer` and names the missing Product in `meta.missing_required_modules`.

For the behavior and its attributes, refer to [Set Connector](/en/documentation/platform/applications/rules-engine/#set-connector).

---

## Confirm that the application reaches the origin

The rule takes a few minutes to propagate. Until then, the application answers as it did before the rule existed.

To confirm the route, send a request to the domain of your workload, with that domain in place of `<your-workload-domain>`:

```bash
curl -i https://<your-workload-domain>/
```

The response is the one `httpbin.org` returns for `/`. A workload's domain ends in `.map.azionedge.net`, and the API returns it in `workload_domain` when it creates the workload. If the response does not come from the origin yet, send the request again until it does. If it never does, refer to [Troubleshoot Applications](/en/documentation/platform/applications/troubleshooting/).

---

## Next steps

- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md): Every variable, operator, and behavior a rule accepts, including Set Connector.
- [Connectors](/en/documentation/platform/connectors.md): Every connection option of an HTTP connector, and the other connector types.
- [Balance traffic across multiple origins](/en/documentation/guides/application-performance/availability/multiple-origins.md): Turn on Load Balancer on a connector and weight several origin addresses.
- [Use a bucket as an application origin](/en/documentation/guides/application-development/data/use-bucket-as-origin.md): Serve the objects of an Object Storage bucket through the same kind of rule.
