---
name: azion-install-an-integration
description: >-
  Install a Marketplace integration in your account, then run it on an application or a firewall with a function instance and a Rules Engine rule.
---

# Install an integration

You install an integration from Azion Marketplace, then run it on an application or a firewall from Azion Console. This page is the procedure every integration shares. Each integration also has its own guide, with the arguments it takes. For that list and where each integration runs, refer to [Marketplace integrations](/en/documentation/platform/marketplace/integrations/).

Integrations install in one of two ways. Some open an install drawer that sets the integration up on an application you select. Others add the integration's function to your account at once. You then turn on the **Functions** module of an application or a firewall, create a function instance there, and create a Rules Engine rule that runs the instance.

---

## Prerequisites

- An Azion account. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An [application](/en/documentation/platform/applications/) served by a [workload](/en/documentation/platform/workloads/). To create one, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- For an integration that runs on a [firewall](/en/documentation/platform/firewall/), a firewall and the [Azion CLI](/en/documentation/devtools/cli/) installed and authorized. The CLI binds the firewall to the workload.
- Turning on a product or a module can generate usage costs. For more information, refer to [Pricing](/en/documentation/fundamentals/pricing/).

---

## Install the integration

You install an integration once per account. To install it from Azion Console:

1. **Open Marketplace**

   Access [Azion Console](https://console.azion.com/) > **Marketplace**.

2. **Find the integration**

   Enter the integration's name in the **Search on Marketplace** field, then select its card. Browsing the cards and the **Categories** reaches the same page.

3. **Select Install**

What happens next depends on the integration.

If the **Install an Integration** drawer opens, the integration ships an install template. To complete the drawer:

1. **Select the application**

   In the **Select an Application** section, select an **Application**. To create one, select **Create New**.

2. **Fill in the integration's fields**

   The drawer renders a form with the integration's own arguments. The integration's guide describes each one.

3. **Review the permissions**

   The drawer lists the privileges Azion Marketplace requires on the selected application. For what each one allows, refer to [Marketplace permissions](/en/documentation/platform/marketplace/permissions-marketplace/).

4. **Select Deploy**

Azion Console confirms that the integration was installed, and the integration runs on the selected application. The sections below do not apply to it.

If no drawer opens, the install completes at once. The card shows `Successfully installed!` and `Latest version installed!`, and the function is listed in the **Function** list of the **Create Instance** drawer. Continue with [Run it on an application](#run-it-on-an-application) or [Run it on a firewall](#run-it-on-a-firewall), as the integration's guide states.

---

## Run it on an application

An integration that runs on an application needs three changes on that application. Do them in the order below.

### Turn on the Functions module

An application runs an installed function only while its **Functions** module is on. To turn on the module:

1. **Open your application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Open the Modules section**

   In the **Main Settings** tab, go to the **Modules** section.

3. **Turn on the Functions switch**

4. **Select Save**

The application shows a **Functions Instances** tab where you instantiate the function.

### Create the function instance

A function instance holds the arguments the integration reads on one application. To create the instance:

1. **Open the Functions Instances tab**

   In **Applications**, select your application, then select the **Functions Instances** tab.

2. **Select + Function**

   An application with no instance yet offers the same action as **Function Instance**. The **Create Instance** drawer opens.

3. **Name the instance**

   In **Name**, enter a unique name that identifies the instance.

4. **Select the installed function**

   In **Function**, select the integration. The **Arguments** editor fills with the integration's default arguments in JSON.

5. **Edit the arguments**

   In **Arguments**, replace the default values with your own. The integration's guide describes each key.

6. **Select Save**

The instance appears in the **Functions Instances** tab with the name you entered.

### Create the rule

The instance runs only when a [Rules Engine](/en/documentation/platform/applications/rules-engine/) rule calls it with the **Run Function** behavior. The rule below matches every request. To create it:

1. **Open the Rules Engine tab**

   In **Applications**, select your application, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   In **Name**, enter a name. For example: `Run my integration`.

4. **Select the phase**

   In the **Phase** section, select *Request Phase*.

5. **Set the criterion**

   In the **Criteria** section, keep the `${uri}` variable and the *starts with* operator, then enter `/` as the argument.

6. **Add the Run Function behavior**

   In the **Behaviors** section, select *Run Function*, then select the instance by the name you gave it.

7. **Select Save**

The rule appears in the **Rules Engine** tab, under the request phase, and runs the instance on every request. Some integrations need more behaviors in the same rule, such as *Bypass Cache* or *Forward Cookies*. Those behaviors and extra criteria require the **Application Accelerator** module, and the integration's guide lists them.

---

## Run it on a firewall

An integration that runs on a firewall needs three changes on the firewall, then a binding between the firewall and your workload.

### Turn on the Functions module

A firewall shows its **Functions Instances** tab only while its **Functions** module is on. To turn on the module:

1. **Open your firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls** > **your firewall**.

2. **Open the Modules section**

   In the **Main Settings** tab, go to the **Modules** section.

3. **Turn on the Functions switch**

4. **Select Save**

The firewall shows the **Functions Instances** tab. For every setting on this form, refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).

### Create the function instance

A firewall function instance holds the arguments the integration reads on that firewall. To create the instance:

1. **Open the Functions Instances tab**

   In **Firewalls**, select your firewall, then select the **Functions Instances** tab.

2. **Select + Function**

   A firewall with no instance yet offers the same action as **Function Instance**. The **Create Instance** drawer opens.

3. **Name the instance**

   In **Name**, enter a unique name that identifies the instance.

4. **Select the installed function**

   In **Function**, select the integration. The list holds only the functions that run on a firewall.

5. **Edit the arguments**

   In **Arguments**, replace the default values in the JSON editor with your own. The integration's guide describes each key.

6. **Select Save**

The instance is listed in the **Functions Instances** tab.

### Create the rule

A [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule selects the requests that reach the instance, through the **Run Function** behavior. To create the rule:

1. **Open the Rules Engine tab**

   In **Firewalls**, select your firewall, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   In **Name**, enter a name. For example: `Run my integration`.

4. **Set the criterion**

   In the **Criteria** section, select the requests that run the integration. For example: if `Hostname` *is equal* `xxxxxxxxxxxx.map.azionedge.net`.

5. **Add the Run Function behavior**

   In the **Behaviors** section, select **Run Function**, then select the instance by the name you gave it.

6. **Select Save**

The firewall runs the instance on every request that matches the criterion.

### Bind the firewall to the workload

A firewall inspects a workload's requests only when the workload's deployment names it. To create a deployment that names both the application and the firewall:

```bash
azion create workload-deployment --workload-id <workload-id> --name <deployment-name> \
  --application-id <application-id> --firewall-id <firewall-id> --strategy-type default \
  --active true --current true
```

The command prints the ID of the new deployment:

```text
Created Workload Deployment with ID <deployment-id>
```

Requests to the workload's domain reach the firewall, and the rule runs the instance on the requests that match its criterion.

---

## Third-party integrations

Some integrations call a tool from another vendor. Before you install one of them, you may need an account with that vendor or an initial setup on its side. Some of these integrations can also generate usage costs with the vendor.

The **Third-party account** column of [Marketplace integrations](/en/documentation/platform/marketplace/integrations/) says which integrations need a vendor account. The integration's own guide describes the setup.

---

## Find and update installed integrations

Each installed integration is listed in the **Function** list of the **Create Instance** drawer. The **Functions** list can also show an installed integration, marked by a cart icon in the **Vendor** column.

Azion and its partners publish new versions of integrations. Updating creates a new instance of the integration's function. To update an integration and move your instances to the new version, refer to [Update an integration](/en/documentation/guides/application-development/integrations/update-an-integration/).

---

## Next steps

- [Marketplace integrations](/en/documentation/platform/marketplace/integrations.md): Every integration, where it runs, and the guide with its arguments.
- [Update an integration](/en/documentation/guides/application-development/integrations/update-an-integration.md): Get the latest version of an installed integration and move your instances to it.
- [Marketplace permissions](/en/documentation/platform/marketplace/permissions-marketplace.md): The privileges an integration requests on an application or a firewall.
- [How Marketplace works](/en/documentation/platform/marketplace/how-it-works.md): How installing, instantiating, and running an integration fit together.
