# Origin IP ACL and HMAC

An origin can check two things before it answers a request: the address the connection comes from, and a signature inside the request. An address check refuses every connection from a source outside a known set, while a signature check refuses every request that was not signed with a key the origin trusts.

[Origin Shield](/en/documentation/platform/connectors/#origin-shield) gives a [connector](/en/documentation/platform/connectors/) of type `http` both checks. Origin IP ACL covers the address, and HMAC covers the signature. For where Origin Shield acts on a request, refer to [How Connectors works](/en/documentation/platform/connectors/how-it-works/#origin-shield).

The sections cover activation, Origin IP ACL, HMAC authentication, what each mechanism proves, and how the address list is updated.

---

## Activation

Origin Shield is off on a new connector, and it turns on at two levels. One switch enables Origin Shield on the connector. Inside it, Origin IP ACL and HMAC each have their own switch, and each stays off until you turn it on.

In Azion Console, the connector form carries the **Origin Shield** switch. Turning it on shows the **Origin IP ACL** switch and the **HMAC** section, which holds its own switch and the credentials. In the API, the three switches are `attributes.modules.origin_shield.enabled`, `config.origin_ip_acl.enabled`, and `config.hmac.enabled`, each `false` by default. For the fields and the errors that guard them, refer to [Connector settings](/en/documentation/platform/connectors/settings/#origin-shield).

Origin Shield applies to a connector of type `http` alone. A connector of type `storage` or `live_ingest` holds no addresses and no connection options, and it takes no Origin Shield settings. On a connector of type `http`, Origin Shield and Load Balancer can both be on.

Origin IP ACL also decides whether your account receives the address list. The `Azion Origin Shield` list appears in the account once at least one connector has Origin IP ACL on.

A change to these switches reaches traffic the way every connector change does, over several minutes and at different moments per data center. For example, right after you turn HMAC off, some data centers still sign requests while others already send them unsigned. For more information, refer to [How Connectors works](/en/documentation/platform/connectors/how-it-works/#propagation).

---

## Origin IP ACL

An IP access control list (ACL) allows or refuses a connection by its source address. With Origin IP ACL, the list your origin applies is `Azion Origin Shield`, a network list that Azion maintains in [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists/). It holds every IPv4 and IPv6 prefix that Azion's infrastructure uses to connect to origins.

Your origin's firewall enforces the allowlist, not Azion. You allow inbound traffic from each prefix of the list and deny every other source. The check filters on the source address of each connection, at layers 3 and 4, so it acts before your server reads a request. Only Azion's infrastructure can then connect to the origin, and a client that connects to the origin's address directly is refused.

The cost is upkeep at your end. The allowlist at your origin is a copy of the list, and keeping that copy current is your responsibility. Automate the update, because a copy that misses a prefix refuses the connections Azion opens from it. For example, when Azion adds a prefix and your copy still lacks it after those servers go into production, your origin refuses the requests they forward.

To read the list from Azion Console, Azion CLI, or the API and apply it at your origin, refer to [Allow Azion's IP ranges at your origin](/en/documentation/support/retrieve-azion-ip-ranges/).

---

## HMAC authentication

A hash-based message authentication code (HMAC) signs a request with a secret key. The receiver computes the signature again with its own copy of the key, and it refuses the request when the two differ.

With HMAC on, the connector signs each request it sends to the origin with AWS Signature Version 4, the scheme of AWS S3 and S3-compatible storage. The type is `aws4_hmac_sha256`, and the Console shows it as read-only. The credentials come from your object storage provider: a region that the provider supports, the service, an access key, and a secret key. The service defaults to `s3`.

Use HMAC to deliver private content from an S3-compatible bucket through an [application](/en/documentation/platform/applications/). The bucket stays closed to the public, and the connector reads it with your credentials. For example, a connector that reaches the S3 endpoint `s3.us-east-005.azionstorage.net` of [Object Storage](/en/documentation/platform/object-storage/), with a credential scoped to one bucket, receives the private object with `200`.

The `modules` object of that connector's `attributes` carries the credentials in this shape:

```json
{
  "origin_shield": {
    "enabled": true,
    "config": {
      "origin_ip_acl": { "enabled": false },
      "hmac": {
        "enabled": true,
        "config": {
          "type": "aws4_hmac_sha256",
          "attributes": {
            "region": "us-east-005",
            "service": "s3",
            "access_key": "<access-key>",
            "secret_key": "<secret-key>"
          }
        }
      }
    }
  }
}
```

With HMAC off, the same request reaches the endpoint unsigned, and the endpoint answers `401`, not `403`:

```text
HTTP/2 401 
content-type: application/xml
server: azion webserver
…
<Error>
    <Code>UnauthorizedAccess</Code>
    <Message>bucket is not authorized: <bucket></Message>
</Error>
```

One set of credentials signs the requests to every address of the connector, and an address cannot carry its own. Turning HMAC off removes the stored credentials, so you enter them again when you turn it back on. The signature protects only an origin that verifies it.

For the endpoint, the region, and the credentials that Object Storage accepts, refer to [S3 compatibility](/en/documentation/platform/object-storage/s3-compatibility/). To sign the requests to a private bucket step by step, refer to [Sign origin requests with HMAC](/en/documentation/guides/application-development/getting-started/sign-origin-requests-with-hmac/).

---

## What each mechanism proves

Origin IP ACL and HMAC answer different questions about a request. Origin IP ACL answers where the connection came from, and HMAC answers whose credentials signed the request.

A source address on the `Azion Origin Shield` list proves that the connection came from Azion's infrastructure. It does not prove that the connection came from your connector, because the list holds the addresses Azion uses to reach origins, not addresses tied to your account. A valid HMAC signature proves that the request carries the access key and secret key stored on your connector. Only a holder of those credentials can produce it.

Each mechanism leaves open what the other one closes. With an allowlist alone, the origin accepts any request that arrives from Azion's infrastructure. With a signature alone, the origin's address stays open to connections from any source, and the origin must refuse the unsigned ones itself. For example, a private bucket behind HMAC still answers a direct request, with `401`. Turn both on when the origin must accept only requests that come through Azion and carry your credentials.

---

## List updates

Azion updates the prefixes of `Azion Origin Shield`, and the list can change often. Azion emails every account with Origin Shield each time the list changes. The servers behind the prefixes that a change adds go into production 7 days after Azion publishes the list. Those 7 days are your window to update the allowlist at your origin and every automation that reads the list.

Azion Console keeps a history of the list, which shows the prefixes each change added and removed. For example, after an update email, the history tells you which entries your origin's firewall must add or drop.

The list carries IPv6 prefixes for all of Azion's data centers, beside its IPv4 prefixes, so it holds more entries than an IPv4-only list. An allowlist that holds only the IPv4 prefixes refuses the connections Azion opens over IPv6. A job that reads the list on a schedule shorter than 7 days picks up each added prefix before its servers go into production. For the read that such a job runs, refer to [Allow Azion's IP ranges at your origin](/en/documentation/support/retrieve-azion-ip-ranges/).

---

## Related resources

- [Connector settings](/en/documentation/platform/connectors/settings.md#origin-shield): Every Origin Shield and HMAC field, with its API path, default, and the error that guards it.
- [Allow Azion's IP ranges at your origin](/en/documentation/support/retrieve-azion-ip-ranges.md): The steps that read the Azion Origin Shield list and apply it at your origin's firewall.
- [Sign origin requests with HMAC](/en/documentation/guides/application-development/getting-started/sign-origin-requests-with-hmac.md): The procedure that turns HMAC on for a connector that reads a private S3-compatible bucket.
- [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists.md): The network lists Azion maintains, including Azion Origin Shield, and the fields every list shares.
