---
name: azion-exempt-one-request-header
description: >-
  Name a single header in a WAF exception from the API, and avoid the condition shape that silently covers every header.
---

# Exempt one request header

You can create a WAF exception that names a single request header from the API. The exception below stops rule `1005`, the pipe-character rule, firing on the `Cookie` header, and leaves it firing on the body, the path, and the query string.

---

## Prerequisites

- The rule set that blocked the request, such as `storefront-waf`.
- A personal token.

---

## Create the exception

Send a `POST` request to the rule set's exceptions endpoint, with `specific_http_header_name` as the match value:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/wafs/<waf-id>/exceptions \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "rule_id": 1005,
  "name": "Allow the session cookie on the storefront",
  "path": "/",
  "operator": "contains",
  "active": true,
  "conditions": [
    { "match": "specific_http_header_name", "name": "cookie" }
  ]
}'
```

```json
{
  "state": "pending",
  "data": {
    "id": 123465,
    "rule_id": 1005,
    "name": "Allow the session cookie on the storefront",
    "path": "/",
    "conditions": [
      { "match": "specific_http_header_name", "name": "cookie" }
    ],
    "operator": "contains",
    "active": true,
    "last_editor": "user@example.com",
    "last_modified": "2026-01-01T12:00:00.000000Z"
  }
}
```

The API answers `202` and echoes the exception under `data`, with the `name` key of the condition intact. The Azion CLI sends the same body from a file with `azion create waf-exceptions --waf-id <waf-id> --file exception.json`.

> **Note**
>
> A condition carries only the keys its own shape declares, and a key the shape does not declare is dropped rather than refused. Sending `{"match": "any_http_header_value", "name": "cookie"}` answers `202` and reads back as `{"match": "any_http_header_value"}`: the exception now covers every header, and no response, read-back, or screen reports the difference. Read the stored condition after you create one. The API also stores the header name exactly as sent, so `cookie`, `Cookie`, and `HTTP_COOKIE` are each kept as written.

For the key each of the fifteen match values carries, refer to [WAF Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules/).

---

## Next steps

- [Exempt one query string parameter](/en/documentation/guides/application-security/firewall-and-waf/exempt-query-parameter.md): The same shape for a named query string argument, with the Console and CLI procedures.
- [WAF Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules.md): All fifteen match values, and the key each one carries.
