---
name: azion-install-the-datadome-bot-protection-integration
description: >-
  Install DataDome Bot Protection from Azion Marketplace and run it on a firewall, to detect and block automated threats on each request.
---

# Install the DataDome Bot Protection integration

You install the DataDome Bot Protection integration from Azion Marketplace and run it on a [Firewall](/en/documentation/platform/firewall/), from Azion Console. DataDome uses AI and machine learning to detect and block OWASP automated threats in real time, in less than 2 milliseconds per request. These threats include credential stuffing, layer 7 DDoS, SQL injection from bots, and scraping. The integration protects websites, mobile apps, and APIs, and you do not change your existing architecture to use it.

Five objects have to exist before a request is analyzed: the installed function, a firewall carrying the **Functions** module, a function instance holding your DataDome key, a Rules Engine rule with the **Run Function** behavior, and a workload deployment bound to the firewall. Each section below creates one of them.

---

## Prerequisites

- An Azion account. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An application served by a [workload](/en/documentation/platform/workloads/), whose deployment you bind to the firewall in the last section.
- An active DataDome subscription, with a DataDome server-side API key. For the plans and their prices, refer to [datadome.co](https://datadome.co).
- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized, for the last section.
- Turning on a product or a module can generate usage costs. For more information, refer to [Pricing](/en/documentation/fundamentals/pricing/).

---

## Install the integration

The function is installed once per account. To install it:

1. **Open Marketplace**

   Access [Azion Console](https://console.azion.com/) > **Marketplace**.

2. **Find the integration**

   Enter `DataDome Bot Protection` in the **Search on Marketplace** field, then select the **DataDome Bot Protection** card. Browsing the cards and the categories reaches the same page.

3. **Select Install**

The card shows `Successfully installed!` and `Latest version installed!`, and the function appears in the **Function** list of the **Create Instance** drawer.

---

## Create the firewall

The firewall is where the function is instanced and where the rule that runs it lives. To create one:

1. **Open the Firewalls page**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then create a firewall.

2. **Name the firewall**

   In the **General** section, enter a **Name**. For example: `datadome-firewall`.

3. **Turn on the Functions module**

   In the **Modules** section, turn on the **Functions** switch.

4. **Save the firewall**

The firewall shows a **Functions Instances** tab while the **Functions** module stays on. To use an existing firewall instead, turn on its **Functions** module and save it. For every setting on this form, refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).

---

## Create the function instance

The instance holds your DataDome server-side API key. To create it:

1. **Open the Functions Instances tab**

   In **Firewalls**, select your firewall, then select the **Functions Instances** tab.

2. **Select + Function**

   A firewall that has no instance shows the same action as **Function Instance**. The **Create Instance** drawer opens.

3. **Name the instance**

   In **Name**, enter a name. For example: `datadome`.

4. **Select the installed function**

   In **Function**, select the DataDome Bot Protection function. The list holds only the functions that run on a firewall.

5. **Enter the arguments**

   In **Arguments**, the editor is prefilled with the integration's default arguments in JSON. Enter your key, as the next section describes.

6. **Select Save**

The instance is listed in the **Functions Instances** tab.

### Arguments

| Variable  | Required | Description                       |
| --------- | -------- | --------------------------------- |
| `api_key` | Yes      | Your DataDome server-side API key |

---

## Create the rule

The instance analyzes nothing until a rule runs it. A [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule selects the requests that reach the instance, through a **Run Function** behavior. To create the rule:

1. **Open the Rules Engine tab**

   In **Firewalls**, select your firewall, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   In **Name**, enter a name. For example: `Run DataDome`.

4. **Set the criterion**

   In the **Criteria** section, select the domains to protect. For example: if `Host` *matches* `yourdomain.com`.

5. **Add the Run Function behavior**

   In the **Behaviors** section, select **Run Function**, then select the DataDome Bot Protection instance you created.

6. **Select Save**

The firewall runs the instance on every request to the domains in the criterion.

---

## Bind the firewall to the workload

The binding is on the workload's deployment, so create a deployment that names both the application and the firewall:

```bash
azion create workload-deployment --workload-id <workload-id> --name <deployment-name> \
  --application-id <application-id> --firewall-id <firewall-id> --strategy-type default \
  --active true --current true
```

The command prints the id of the new deployment:

```text
Created Workload Deployment with ID 123456
```

Requests to the workload's domain reach the firewall, and DataDome Bot Protection runs on each one.

---

## How it works

For each incoming request, the DataDome function:

1. Collects the request metadata: the IP address, the User-Agent, the headers, and the cookies.
2. Sends the data to the DataDome API for analysis in real time.
3. Allows the request, or blocks or challenges it, from the DataDome response and the configuration of your DataDome dashboard.

The DataDome AI engine analyzes billions of requests each day and updates continuously, to identify and prevent known threats and zero-day threats.

---

## Monitor bot activity

Two Azion observability products show what the integration does:

- [Real-Time Events](/en/documentation/platform/real-time-events/): in the **Functions** data source, inspect the log of each request and the DataDome responses.
- [Data Stream](/en/documentation/platform/data-stream/): create a stream with the *Functions Event Collector* template, to send the logs to your endpoint for long-term analysis.

---

## Next steps

- [Marketplace integrations](/en/documentation/platform/marketplace/integrations.md): Every integration Azion Marketplace offers, and where each one runs.
- [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine.md): Every criterion and behavior a firewall rule accepts.
- [Templates and payload](/en/documentation/platform/data-stream/templates-and-payload.md): The variables the Functions Event Collector template sends.
- [Update an integration](/en/documentation/guides/application-development/integrations/update-an-integration.md): Move an installed integration to its latest version.
