---
name: azion-refuse-requests-above-the-threshold
description: >-
  Set action to deny on a Bot Manager Lite instance, from Azion Console, the Azion CLI, or the API, and read what a refused request receives.
---

# Refuse requests above the threshold

You can set a [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/) instance to refuse a request whose score reaches the threshold, from Azion Console, the Azion CLI, or the API. A refused request receives `HTTP 403` with the page titled `Azion - Default error page`, and nothing in that answer names Bot Manager.

---

## Prerequisites

- A [firewall](/en/documentation/platform/firewall/) bound to the workload that serves your application, with Bot Manager Lite installed. Refer to the [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).
- The scores your own traffic produces, read from an observation window. To run one, refer to [Run Bot Manager in observation mode](/en/documentation/guides/application-security/bots-and-network/observation-mode/).
- The [Azion CLI](/en/documentation/devtools/cli/) installed and a configured personal token, for the CLI procedure.
- A personal token, for the API procedure. To create one, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Set the action to deny

The object below is one value away from the observation object: `action` reads `deny`, so the instance answers `403` to a request whose score reaches `threshold` instead of serving it. At `30`, the threshold Bot Manager Lite ships, a browser is not refused. A Chrome request carrying `Accept`, `Accept-Language`, `Accept-Encoding`, four `Sec-Fetch-*` headers, and `Upgrade-Insecure-Requests` reaches the application under this object. `internal_logs` at `2` keeps a report line for every request, so a refusal leaves a record of the score behind it.

```json
{
  "threshold": 30,
  "action": "deny",
  "internal_logs": 2,
  "log_tag": "storefront-bots"
}
```

For every argument an instance accepts, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/#fields).

**Console**

To set the action from Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select that firewall.

2. **Select the Functions Instances tab**

3. **Open the instance you want to change**

   On a firewall carrying no instance yet, select **+ Function**, enter a **Name**, and select the Bot Manager Lite function in the **Function** section.

4. **Enter the object in the Arguments section**

   The section holds a JSON editor, because Bot Manager Lite carries no argument schema to build a form from.

5. **Select Save**

The instance holds the new object. An instance already named by a rule keeps that rule: the arguments change under it, and no rule has to be touched.

**CLI**

To create the instance with the Azion CLI, save the object as `bmargs.json`:

```json
{
  "threshold": 30,
  "action": "deny",
  "internal_logs": 2,
  "log_tag": "storefront-bots"
}
```

The `--args` flag of `azion create firewall-instance` takes the path to that file, and no inline JSON:

```bash
azion create firewall-instance --name bot-manager-lite --firewall-id <firewall-id> \
  --function-id <function-id> --args bmargs.json --active true
```

```text
Created Firewall Function Instance with ID 12346
```

The Azion CLI confirms the instance with the id it received. Record that id: a [Rules Engine rule](/en/documentation/guides/application-security/bots-and-network/run-on-every-request/) names the instance by it, never by the id of the function.

**API**

Send a `POST` request to the `functions` collection of your firewall. Replace `<firewall-id>` with the id of your firewall, `[TOKEN VALUE]` with your personal token, and `12345` with the id of the installed Bot Manager Lite function:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/firewalls/<firewall-id>/functions \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "bot-manager-lite",
  "function": 12345,
  "active": true,
  "args": {
    "threshold": 30,
    "action": "deny",
    "internal_logs": 2,
    "log_tag": "storefront-bots"
  }
}'
```

The call answers `202` and returns the instance as the platform stored it:

```json
{
  "state": "pending",
  "data": {
    "id": 12348,
    "name": "bot-manager-lite",
    "args": {
      "threshold": 30,
      "action": "deny",
      "internal_logs": 2,
      "log_tag": "storefront-bots"
    },
    "azion_form": {},
    "function": 12345,
    "active": true
  }
}
```

`"state": "pending"` says the write was accepted and has yet to reach Azion's distributed infrastructure. `"azion_form": {}` is why Azion Console renders a JSON editor for this function instead of a form.

> **Note**
>
> Allow about two minutes after any change before you read anything into a response. The object is not validated: an instance whose `action` is misspelled looks configured to refuse and refuses nothing. A `threshold` of `0` refuses every request the rule matches. A client that neither runs JavaScript nor keeps cookies never reaches a `403`, and never reaches the application either. For what that client receives, refer to [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting/#bot-manager).

---

## Next steps

- [Read the report log for one instance](/en/documentation/guides/application-security/bots-and-network/read-the-report-log.md): Confirm which instance refused a request, and what it scored.
- [Arguments](/en/documentation/platform/firewall/bot-manager/arguments.md): Every argument an instance accepts, and what each action does at the threshold.
