---
name: azion-install-the-signed-cookies-integration
description: >-
  Install the Signed Cookies Hash Generator and Hash Validator from Azion Marketplace and run them on an application to detect tampered cookies.
---

# Install the Signed Cookies integration

Signed Cookies protects the cookies you list against changes made on the client side. It is two integrations that run on the same application, and both are among the [Marketplace integrations](/en/documentation/platform/marketplace/integrations/). In the response phase, the **Hash Generator** appends an encrypted version of each listed cookie to the response. In the request phase, the **Hash Validator** checks the cookies against their encrypted versions and adds violation headers to the request when they differ.

A signed cookie lets your application verify that no third party altered the session data, which defends against session hijacking. Seven objects must exist before a request is checked: the two installed functions, an application with the **Functions** and **Application Accelerator** modules turned on, one function instance per integration, and one Rules Engine rule per instance.

---

## Prerequisites

- An Azion account. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An [application](/en/documentation/platform/applications/) served by a [workload](/en/documentation/platform/workloads/). To create one, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- Turning on a product or a module can generate usage costs. For more information, refer to [Pricing](/en/documentation/fundamentals/pricing/).

---

## Install the integrations

Each install adds one function to your account: *Signed Cookies - Hash Generator* and *Signed Cookies - Hash Validator*. To install them from Azion Console:

1. **Open Marketplace**

   Access [Azion Console](https://console.azion.com/) > **Marketplace**.

2. **Find the Hash Generator**

   Enter `Signed Cookies` in the **Search on Marketplace** field, then select the **Signed Cookies - Hash Generator** card. Browsing the cards and the categories reaches the same page.

3. **Select Install**

4. **Install the Hash Validator**

   Return to **Marketplace**, select the **Signed Cookies - Hash Validator** card, then select **Install**.

Each card shows `Successfully installed!` and `Latest version installed!`, and both functions appear in the **Function** list of the **Create Instance** drawer.

---

## Turn on the Functions module

An application runs an installed function only when its **Functions** module is on. The rule that runs the Hash Validator also uses the **Forward Cookies** behavior, which requires the **Application Accelerator** module. To turn on both modules:

1. **Open your application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Open the Modules section**

   In the **Main Settings** tab, go to the **Modules** section.

3. **Turn on the Functions switch**

4. **Turn on the Application Accelerator switch**

5. **Select Save**

Azion Console confirms that the application was updated.

---

## Create the function instances

Each integration needs its own function instance with its own arguments. The Hash Generator runs in the response phase and the Hash Validator in the request phase. To create the two instances in your application:

1. **Open the Functions Instances tab**

   In **Applications**, select your application, then select the **Functions Instances** tab.

2. **Select + Function**

   An application with no instance yet offers the same action as **Function Instance**. The **Create Instance** drawer opens.

3. **Name the instance**

   In **Name**, enter a unique name that identifies the instance. For example: `signed-cookies-generator`.

4. **Select the function**

   In **Function**, select the *Signed Cookies - Hash Generator* function. The **Arguments** editor fills with the default arguments of the integration.

5. **Edit the arguments**

   In **Arguments**, enter the Hash Generator arguments described below.

6. **Select Save**

7. **Create the Hash Validator instance**

   Repeat these steps with a name such as `signed-cookies-validator`, the *Signed Cookies - Hash Validator* function, and the Hash Validator arguments.

Both instances appear in the **Functions Instances** tab with the names you entered.

### Hash Generator arguments

```json
{
  "cookie_list": ["yummy_cookie", "tasty_cookie"],
  "cookie_secret": "ItIsASecret",
  "tampering_cookie_prefix": "tampering_protection"
}
```

| Key                       | Description                                                                                                          |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| `cookie_list`             | The cookies to protect. For each cookie in this list, an encrypted version of the cookie is appended to the response |
| `cookie_secret`           | A secret that protects the encrypted cookie against client-side manipulation                                         |
| `tampering_cookie_prefix` | The prefix of the names of the encrypted cookies                                                                     |

The prefix sets the names of the encrypted cookies. With the value `tampering_protection` and the cookies `yummy_cookie` and `tasty_cookie`, the function creates `tampering_protection_yummy_cookie` and `tampering_protection_tasty_cookie`.

If `tampering_cookie_prefix` has no valid value, the function uses the default `azion_tampering`. The encrypted cookies are then `azion_tampering_yummy_cookie` and `azion_tampering_tasty_cookie`.

### Hash Validator arguments

```json
{
  "cookie_list": ["yummy_cookie", "tasty_cookie"],
  "cookie_secret": "ItIsASecret",
  "tampering_cookie_prefix": "tampering_protection",
  "tampering_violation_header_prefix": "azion-tampering-violation"
}
```

The Hash Validator takes the same keys as the Hash Generator, plus `tampering_violation_header_prefix`. This key sets the prefix of the headers the function appends to the request when it detects a cookie violation.

With the value `Cookie-Violation`, the function creates the `Cookie-Violation-Any`, `Cookie-Violation-Counter`, and `Cookie-Violation-List` headers. If the key has no valid value, the defaults are `Azion-Tampering-Violation-Any`, `Azion-Tampering-Violation-Counter`, and `Azion-Tampering-Violation-List`.

---

## Create the rules

Each instance runs only when a Rules Engine rule calls it. The Hash Generator rule runs in the response phase. The Hash Validator rule runs in the request phase and adds the **Forward Cookies** behavior, which requires the **Application Accelerator** module. Both rules below match every request. To create the rules:

1. **Open the Rules Engine tab**

   In **Applications**, select your application, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the Hash Generator rule**

   In **Name**, enter a name for the rule. For example: `Sign cookies on every response`.

4. **Select the response phase**

   In the **Phase** section, select *Response Phase*.

5. **Set the criterion**

   In the **Criteria** section, keep the `${uri}` variable and the *starts with* operator, then enter `/` as the argument.

6. **Add the Run Function behavior**

   In the **Behaviors** section, select *Run Function*, then select the Hash Generator instance by its name.

7. **Select Save**

8. **Create the Hash Validator rule**

   Select **+ Rule** again. Enter a name, select *Request Phase*, and set the same criterion.

9. **Add the Run Function behavior**

   In the **Behaviors** section, select *Run Function*, then select the Hash Validator instance by its name.

10. **Add the Forward Cookies behavior**

    Select **Add Behavior**, then select *Forward Cookies*.

11. **Select Save**

The **Rules Engine** tab lists one rule under the response phase and one under the request phase. A request whose protected cookies were altered reaches your application with the violation headers.

For every criterion and behavior a rule accepts, refer to [Rules Engine](/en/documentation/platform/applications/rules-engine/).

---

## Next steps

- [Marketplace integrations](/en/documentation/platform/marketplace/integrations.md): The integrations Marketplace offers, and the application or firewall each one runs on.
- [Rules Engine](/en/documentation/platform/applications/rules-engine.md): The criteria and behaviors a rule accepts, including Run Function and Forward Cookies.
- [Install the Request Variation Controller integration](/en/documentation/guides/application-development/integrations/request-variation-controller.md): How to detect users who change request arguments too often, with a signed cookie.
- [Update an integration](/en/documentation/guides/application-development/integrations/update-an-integration.md): How to get the latest version of an installed integration, and what an update creates.
