Install the Secure Token integration
Install Secure Token from Azion Marketplace and run it on a firewall, so only requests with a valid, unexpired token reach your content.
You install the Secure Token integration from Azion Marketplace and run it on a Firewall, from Azion Console. Secure Token protects your content with token-based, time-limited URLs. You can use the tokens to create and validate signatures for cookies, authentication headers, and other security measures. A common use is to protect video assets for live streaming and on-demand content, delivered through HLS or Progressive Download.
Five objects have to exist before a token is checked: the installed function, a firewall carrying the Functions module, a function instance holding the arguments, a Rules Engine rule with the Run Function behavior, and a workload deployment bound to the firewall. Each section below creates one of them.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload, whose deployment you bind to the firewall in the last section.
- A way to generate tokens: the example scripts in Azion’s Secure Token repository, or your own code. The next sections show how.
- The Azion CLI installed and authorized, for the last section.
- Turning on a product or a module can generate usage costs. For more information, refer to Pricing.
Install the integration
The function is installed once per account. To install it:
Access Azion Console > Marketplace.
Enter Secure Token in the Search on Marketplace field, then select the integration’s card. Browsing the cards and the categories reaches the same page.
The card shows Successfully installed! and Latest version installed!, and the function appears in the Function list of the Create Instance drawer.
Generate the token
The function validates tokens that you generate with a secret of your choice. You generate them outside Azion, then add them to the URLs you share. To generate a token:
Go to Azion’s Secure Token GitHub repository. The repository explains how the token is generated and how to use it, and holds code snippet examples.
The repository has two example scripts that generate tokens: a Python script and a PHP script. Run one of them locally, or generate the tokens on your own platform with your own code.
Store the generated token, whichever way you generated it.
The Python script has this source code:
| Variable | Description |
|---|---|
secret | A string of your choice that generates the token |
uri | The URI that uses the token |
expire | The expiration time of the token |
Keep the secret value. The function instance takes it as an argument.
Create the firewall
The firewall is where the function is instanced and where the rule that runs it lives. To create one:
Access Azion Console > Firewalls, then create a firewall.
In the General section, enter a Name. For example: secure-token-firewall.
In the Modules section, turn on the Functions switch.
The firewall shows a Functions Instances tab while the Functions module stays on. To use an existing firewall instead, turn on its Functions module and save it. For every setting on this form, refer to Set a firewall’s main settings.
Create the function instance
The instance holds the secret the function uses to validate each token. To create it:
In Firewalls, select your firewall, then select the Functions Instances tab.
A firewall that has no instance shows the same action as Function Instance. The Create Instance drawer opens.
In Name, enter a name. For example: secure-token.
In Function, select the Secure Token function. The list holds only the functions that run on a firewall.
In Arguments, the editor is prefilled with the integration’s default arguments in JSON. Enter your secret, as the next section describes.
The instance is listed in the Functions Instances tab.
Arguments
The instance takes one argument:
| Variable | Description |
|---|---|
secure_token_secret | The secret string you passed in the code when you generated the token |
Create the rule
The instance checks nothing until a rule runs it. A Rules Engine for Firewall rule selects the requests that reach the instance, through a Run Function behavior. To create the rule:
In Firewalls, select your firewall, then select the Rules Engine tab.
In Name, enter a name. For example: Run Secure Token.
In the Criteria section, select the domains that run the integration. For example: if Host matches yourdomain.com.
In the Behaviors section, select Run Function, then select the instance by the name you gave it.
The firewall runs the instance on every request to the domain in the criterion.
Bind the firewall to the workload
The binding is on the workload’s deployment, so create a deployment that names both the application and the firewall:
The command prints the id of the new deployment:
Requests to the workload’s domain reach the firewall, and the rule runs the Secure Token instance on each one.
How it works
The function performs two checks on each token: whether the current time is greater than the expiration time in the token, and whether the signature matches the token signature.
- If the signature is invalid, the function returns a
403error. - If the expiration time is exceeded, the function returns a
410error.
A user cannot change the expiration time of a token without breaking its signature.