AWAF declarative-policy explainer
Paste a BIG-IP Advanced WAF declarative security policy (JSON) and get a section-by-section, plain-language reading grounded in F5's published schema, with security callouts that read the values: transparent enforcement means monitor-only, plus signature staging, Data Guard off, and cookies missing Secure or HttpOnly. Runs entirely in your browser.
Security & WAF🔒 Runs entirely in your browser. Nothing you paste is uploaded or leaves the page.
The decode runs entirely in your browser. Paste a declarative WAF policy JSON and it explains each recognized section in plain language, grounded in F5's published declarative-policy schema, and raises security callouts derived only from values the policy explicitly sets. It is decode-only: it never validates against a live BIG-IP, never evaluates the policy against traffic, and never fetches anything. It honors the template-delta rule, so an absent section is reported as the template default, never as disabled.
- F5 BIG-IP WAF Declarative Policy (index)The published schema versions: v16.0, v16.1, v17.0, v17.1, and v17.5
- F5 Declarative WAF v17.1 SchemaThe field structure and F5's own per-field descriptions; the latest version with a complete published schema
- F5 Declarative WAF v17.1 Schema DescriptionF5's prose descriptions of each policy section
This tool is built from public vendor documentation and may not be fully accurate or current. For production use, always verify against the vendor's official documentation.