The HTTP trigger turns a function into a web endpoint at a route under /api/ by default. Its authorization level controls whether a key is required. ANONYMOUS needs no key. FUNCTION requires a function-specific key or a host key, passed in the x-functions-key header or the code query parameter. ADMIN requires the master key. Keys are not user authentication; for real users, put App Service Authentication (Easy Auth), API Management or your own token validation in front. Locally, keys are not enforced.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.