Configuration Options

Documentation Index

Our GraphQL support provides the following features to enhance detection for customers who use GraphQL:

  • Sensitive GraphQL operations

Updated on: 29 May 2023


Application ID / AppId and HUMAN Token / Auth Token can be found in the Portal, under Applications section. Cookie Encryption Key can be found in the portal, under Policies section.

Updated on: 11 May 2023


To complete the configuration of additional features, it is required to modify customized subroutines available in the px_custom.vcl file with instructions.

Updated on: 11 May 2023


The Additional Activity Handler is a callback function that processes activities before forwarding to the next pipeline step.

Updated on: 11 May 2023


Provides a JSON object for rendering custom Captcha challenges for specific cases, such as XHR post requests.

Updated on: 11 May 2023


Configuration required to support Code Defender CSP Capability in Fastly Enforcer.

Updated on: 11 May 2023


Allows setting a custom CSS file for the block page.

Updated on: 11 May 2023


Defines the default first-party endpoint to retrieve the HUMAN sensor.

Updated on: 11 May 2023


Adds a custom logo to the block page, with specific size and format requirements.

Updated on: 11 May 2023


Allows adding a custom JS script to the block page.

Updated on: 11 May 2023


Enriches activities with additional data like user ID or session ID.

Updated on: 11 May 2023


Features to filter out specific requests from Enforcer verification flow.

Updated on: 11 May 2023


Provides a hook function to process data enrichment payloads.

Updated on: 11 May 2023


Prevents suspicious behavior by using first-party resources.

Updated on: 26 May 2023


Instructions to deploy the HUMAN First-Party JS Snippet.

Updated on: 11 May 2023


Defines routes that are fully enforced even in Monitor mode.

Updated on: 16 May 2023


Extracts and sends hashed credentials to HUMAN for additional risk analysis.

Updated on: 11 May 2023


Allows editing response headers for first-party requests.

Updated on: 11 Jul 2023


Explains the module context object, including headers for enrichment and identifiers.

Updated on: 11 May 2023


Enables or disables the Enforcer module based on configuration.

Updated on: 11 May 2023


Sets the working mode of the Enforcer (Monitor or Active Blocking).

Updated on: 22 Aug 2023


Specifies routes to monitor while in Active Blocking mode.

Updated on: 26 May 2023


Customizes the block page returned by Fastly Enforcer.

Updated on: 11 May 2023


Identifies routes requiring stricter protection against bot attacks.

Updated on: 13 Nov 2023


Tests the Enforcer’s blocking flow while in Monitor Mode using a bypass header.

Updated on: 11 May 2023