For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
LogoLogo
HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
Login
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
  • General
    • About Enforcers
    • Support first-party HUMAN calls
    • Deploy Tool
    • Troubleshoot Enforcer configurations
  • Enforcer frameworks
    • Akamai ESI
    • Apache - C Module
    • ASP.NET
      • AWS Lambda@Edge changelog
    • Callout Enforcer
    • Envoy Proxy
    • F5 BIGIP
    • Fastly JavaScript Compute@Edge
    • Google Cloud Platform (GCP) Callout Enforcer
    • Kong Plugin
    • NGINX - C Module
    • NGINX - LUA Module
    • PHP
    • Python
    • Ruby
    • Salesforce Commerce Cloud Cartridge
  • About Enforcers
  • Support first-party HUMAN calls
  • Deploy Tool
  • Troubleshoot Enforcer configurations
  • Akamai EdgeWorker changelog
  • Installation
  • Manual installation
  • Configuration
  • API
  • Upgrading
  • Supported Features
  • Install the Akamai EdgeWorker Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Akamai ESI
  • Akamai ESI changelog
  • Installation
  • Configuration
  • First Party Configuration
  • Apache - C Module
  • Apache changelog
  • Module Configuration
  • Configuration Options
  • First Party Configuration
  • Apigee Edge changelog
  • Installation
  • Configuration
  • ASP.NET
  • ASP.NET changelog
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • Configuration
  • AWS Lambda@Edge changelog
  • Installation
  • Manual installation
  • API
  • Configuration
  • Upgrading
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Changelog
  • Install the Azure Front Door Enforcer
  • Manually install the Azure Front Door Enforcer
  • API
  • Configuration
  • Callout Enforcer
  • Changelog
  • Supported Features
  • Envoy configuration
  • Enforcer Configuration
  • Advanced Configuration
  • Docker Image
  • Complete Example
  • Cloudflare Worker changelog
  • Installation
  • Installation with Terraform
  • Manual installation
  • Deploy the Cloudflare Enforcer for Shopify applications
  • API
  • Configuration
  • Configuration (v5 and Below)
  • Upgrading to Version 6
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Envoy Proxy
  • Changelog
  • Installation
  • Configuration Options
  • First Party Configuration
  • F5 BIGIP
  • Changelog
  • Installation
  • First Party Integration
  • Configuration
  • Configurational Classes
  • Advanced Customization
  • Troubleshooting
  • Fastly JavaScript Compute@Edge
  • Changelog
  • Installation
  • API
  • Configuration
  • Fastly Rust Compute@Edge changelog
  • Supported Features
  • Installation
  • Configuration
  • Changelog
  • Installation
  • Manual installation
  • Configuration
  • How it works
  • Upgrade to V12
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V11
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V10
  • Installing the Enforcer
  • GraphQL Support
  • Sensitive GraphQL Operations
  • Basic Configuration
  • Customized Subroutines
  • Additional Activity Handler
  • Advanced Blocking Response
  • Creating and Configuring the Edge-Dictionary
  • Custom CSS
  • Custom First Party Sensor Endpoint
  • Custom Logo
  • Custom JS Script
  • Custom Parameters
  • Filter Requests
  • Filter by HTTP Method
  • Filter by Route
  • Filter by Extension
  • Filter by IP
  • Filter by User Agent
  • Data Enrichment
  • First Party
  • First Party Snippet
  • Enforced Routes
  • Login Credentials Extraction
  • Modify First Party Response
  • Module Context Object
  • Module Enabled
  • Module Mode
  • Monitored Routes
  • Returning A Custom Block Page
  • Sensitive Routes
  • Test Block Flow on Monitoring Mode - Bypass Monitor Header
  • Upgrading the Enforcer
  • Changelog
  • Installation
  • API
  • Configuration
  • Installing the Enforcer
  • Supported Features
  • Configuration Options
  • Upgrading the Enforcer
  • Google Cloud Platform (GCP) Callout Enforcer
  • Integrate the GCP Callout Enforcer
  • HAProxy changelog
  • Supported Software Versions
  • Supported Features
  • Installation
  • Configuration
  • Java changelog
  • Installation
  • Configuration
  • Upgrading
  • Kong Plugin
  • Changelog
  • NGINX Gateway Fabric with the HUMAN Enforcer
  • NGINX Gateway Fabric Enforcer configurations
  • Ingress NGINX controller
  • Ingress NGINX Enforcer configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation (Next.js 16)
  • Installation (Next.js 15 and lower)
  • Configuration
  • NGINX - C Module
  • NGINX changelog
  • Supported Features
  • Installation
  • Module Configuration
  • Configuration Options
  • Enrichment
  • First Party Configuration
  • Nginx Docker Image
  • Ingress NGINX Controller with HUMAN Enforcer
  • NGINX - LUA Module
  • Changelog
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • HUMAN Plugin Configuration
  • First Party Configuration
  • Enrichment
  • Changelog
  • Installation
  • API
  • Configuration
  • Configuration Options (7.9.0 and below)
  • Upgrading to Version 8
  • PHP
  • Changelog
  • Upgrading
  • Configuration Options
  • Advanced Configuration
  • Python
  • Changelog
  • Installation
  • Required Configuration
  • Configuration Options
  • Upgrading
  • First Party Configuration
  • Ruby
  • Changelog
  • Installation
  • Configuration
  • Additional Information
  • Salesforce Commerce Cloud Cartridge
  • Changelog
  • Importing the Cartridge
  • Registering the Cartridge
  • Importing Metadata and Services
  • Configuring the Cartridge
  • Using the Cartridge
  • SCAPI Protection Considerations
  • Upgrading
  • Customized Block Page
  • Configuration options
  • First Party
  • Varnish changelog
  • Supported Software Versions
  • Installation
  • Configuration Options
  • Enforcer Configuration
  • Example configuration
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • July 22, 2026
  • 4.11.0
  • May 27, 2026
  • 4.10.1
  • March 31, 2026
  • Version 4.10.0
  • March 8, 2026
  • Version 4.9.0
  • January 27, 2026
  • Version 4.8.1
  • November 9, 2025
  • Version 4.8.0
  • October 16, 2025
  • Version 4.7.0
  • August 20, 2025
  • Version 4.6.0
  • May 31, 2025
  • Version 4.5.0
  • March 25, 2025
  • Version 4.4.0
Enforcer frameworksAWS Lambda@Edge

AWS Lambda@Edge changelog

July 22, 2026
July 22, 2026

May 27, 2026
May 27, 2026

March 31, 2026
March 31, 2026

March 8, 2026
March 8, 2026

January 27, 2026
January 27, 2026

November 9, 2025
November 9, 2025

October 16, 2025
October 16, 2025

August 20, 2025
August 20, 2025

May 31, 2025
May 31, 2025

March 25, 2025
March 25, 2025
Older posts
Next
Built with
Login

4.11.0

Added

  • Redirect Action support
  • Added undici HTTP client implementation
  • Added risk_rtt field to activities in case of S2S timeout
  • Added PhinHttpClientOptions to PhinHttpClient constructor to support custom agents
  • Telemetry by risk on GET method - adjusted telemetry requested flag on risk_api response
  • MCP Protection support
  • Send original vid from cookie on all activities under orig_cookie_vid
  • Support for JWT key names that contain dots (such as URLs) when extracting the user id and additional fields
  • Custom block on error message configuration support

4.10.1

Added

  • Pass request object to response custom parameters custom function
  • Custom block on error message configuration support

Version 4.10.0

  • MCP Protection support
  • Send original vid from cookie on all activities under orig_cookie_vid

Version 4.9.0

  • Added Hard Block support, which lets you customize the Hard Block page that’s displayed to users when a request is blocked without a challenge. Hard Block customization options use the same configuration options as the regular Challenge page. Be sure to update the appropriate configuration options to customize the Hard Block page, not the block page template. The relevant configuration options are:
    • px_custom_logo: Adds a custom logo to the Challenge and Hard Block pages. Maps to {{customLogo}} in the block page template.
    • px_css_ref: Adds a custom CSS file to the Challenge and Hard Block pages. Maps to {{cssRef}} in the block page template.
    • px_js_ref: Adds a custom JS file to the Challenge and Hard Block pages. Maps to {{jsRef}} in the block page template.
    • px_first_party_enabled: A boolean flag to enable first party mode. Maps to {{firstPartyEnabled}} in the block page template.

Version 4.8.1

  • Added compression for px-context header to avoid AWS CloudFront request size limits (20KB) for HumanActivities Lambda

Version 4.8.0

  • Added is_sensitive_route field to risk api and async activities
  • Added request_id to telemetry activity details
  • Telemetry activity update_reason field updated to reflect the reason for telemetry activity:
    • command - incoming telemetry request received
    • risk - telemetry triggered via risk response field

Version 4.7.0

  • Added internal tool for generating deployment manifests

Version 4.6.0

  • Support for adding a data enrichment header (new px_data_enrichment_header_name configuration)
  • Added response custom parameters to supported features and supported it in the CI workflows
  • Added Documentation enforcement workflow - verify that the documentation is up to date with the latest changes in the codebase

Version 4.5.0

  • Improvements to request RTT and Lambda execution time by sending async HTTP requests in subsequent Lambda invocations
  • Added support for interpreting regex-formatted strings (e.g., "/^/regex/path$/i") as regular expressions for the following configurations:
    • px_sensitive_routes
    • px_monitored_routes
    • px_enforced_routes
    • px_graphql_routes
    • px_filter_by_route
    • px_filter_by_user_agent
    • px_graphql_keywords
    • px_sensitive_graphql_operation_names
    • px_login_credentials_extraction object fields path (when path_type is "regex") and login_successful_body_regex

Version 4.4.0

  • Added px_token_version configuration to enable support for cookie v2 (cookie v3 is default)
  • Support for regular expressions in px_filter_by_user_agent
  • Extracting GraphQL operationName and variables even if the query field is not present
  • Fixed issue where telemetry would fail if px_cookie_secret was an array of cookie strings