A retail operations team once called me because their order-sync job had stopped working overnight. A developer had pasted the full function URL, including the access key, into a shared spreadsheet so the integration team could use it. Someone later copied that sheet into a ticket, the ticket went to a contractor, and the key ended up in a vendor’s email thread. We had to rotate the key and update six systems before lunch.
The mistake started with a simple question: how to get Azure Function URL and share it with another system. Finding the URL takes a minute. Finding it safely, and understanding what is in it, takes more care. A function URL is not just an address. It can also carry a credential.
In this guide, you will learn how to find the URL in the portal, with Azure CLI, and with Azure PowerShell, how to understand keys and authorization levels, how to secure the endpoint, and how to fix the errors that appear when a URL does not work.
What an Azure Function URL Contains
An Azure Function is a small piece of code that runs in response to an event. Only some triggers have URLs. An HTTP trigger exposes an endpoint, but timer, queue, and blob triggers do not. If you need a refresher, read what Azure Functions is and how the HTTP trigger works. For other trigger types, see how to trigger Azure Functions.
A typical function URL looks like this:
https://<function-app-name>.azurewebsites.net/api/<function-route>?code=<function-key>Each part has a job:
- Host name: The address of your function app. Newer apps may get a longer default host name that includes a unique suffix and region, so copy it from Azure instead of guessing.
- /api: The default route prefix. You can change it in
host.jsonwith theroutePrefixsetting. - Function route: The function’s name, or a custom route like
orders/{orderId}that you set on the trigger. - code parameter: An access key, which is only present when the function requires one.
That last part is the sensitive piece. Treat any URL that contains code= like a password.
Pro Tip: In my experience, I split every function URL into two values in documentation: the base address, which is safe to share, and the key, which goes only into a secret store. That habit alone would have prevented the spreadsheet incident.
Understand Authorization Levels and Keys
Before you copy a URL, check how the function is protected. The HTTP trigger has an authorization level that controls who can call it.
| Level | What it requires | Typical use |
|---|---|---|
| Anonymous | No key | Public endpoints, or endpoints protected by another layer |
| Function | A function key or host key | Service-to-service calls with a shared secret |
| Admin | The master key | Management only, never for apps |
Keys are shared secrets that Azure generates for your function app. There are three kinds:
- Function keys: Work for one function only. This is the narrowest option.
- Host keys: Work for every function in the app.
- Master key: Gives admin-level access to the whole app, including the runtime admin endpoints.
Use the narrowest key that does the job. A function key for one function is much safer than a host key, and the master key should never leave the portal or your secret vault.
Keys have limits you should understand. They prove that a caller knows a secret, but they do not prove who the caller is. Anyone with the key looks the same to the function. For user-level identity, use Microsoft Entra ID authentication, which I cover later.
Pro Tip: I create a separate function key for each consumer, such as one for the ERP system and one for the reporting tool. When one partner leaves, I revoke only their key.
Method 1: Get the Function URL in the Azure Portal
The portal is the fastest option when you need one URL. These steps work for HTTP-triggered functions.
- Sign in to the Azure portal and open your Function App.
- In the left menu, select Functions, then select the function name.
- Choose Get function URL from the toolbar.
- Pick the key to include from the dropdown, such as
default (function key). - Copy the URL.
If you do not see your function, the app may not have finished deploying, or the host may not be running. For the portal flow of building the app in the first place, see how to create a function app in the Azure portal and deploy a function app in the Azure portal.
To view or rotate keys, open the function and select Function Keys, or open the app and