For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
LogoLogo
HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
Login
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
  • General
    • About Enforcers
    • Support first-party HUMAN calls
    • Deploy Tool
    • Troubleshoot Enforcer configurations
  • Enforcer frameworks
    • Akamai ESI
    • Apache - C Module
    • ASP.NET
    • Callout Enforcer
    • Envoy Proxy
    • F5 BIGIP
    • Fastly JavaScript Compute@Edge
      • Changelog
      • Installation
      • API
      • Configuration
    • Google Cloud Platform (GCP) Callout Enforcer
    • Kong Plugin
    • NGINX - C Module
    • NGINX - LUA Module
    • PHP
    • Python
    • Ruby
    • Salesforce Commerce Cloud Cartridge
  • About Enforcers
  • Support first-party HUMAN calls
  • Deploy Tool
  • Troubleshoot Enforcer configurations
  • Akamai EdgeWorker changelog
  • Installation
  • Manual installation
  • Configuration
  • API
  • Upgrading
  • Supported Features
  • Install the Akamai EdgeWorker Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Akamai ESI
  • Akamai ESI changelog
  • Installation
  • Configuration
  • First Party Configuration
  • Apache - C Module
  • Apache changelog
  • Module Configuration
  • Configuration Options
  • First Party Configuration
  • Apigee Edge changelog
  • Installation
  • Configuration
  • ASP.NET
  • ASP.NET changelog
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • Configuration
  • AWS Lambda@Edge changelog
  • Installation
  • Manual installation
  • API
  • Configuration
  • Upgrading
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Changelog
  • Install the Azure Front Door Enforcer
  • Manually install the Azure Front Door Enforcer
  • API
  • Configuration
  • Callout Enforcer
  • Changelog
  • Supported Features
  • Envoy configuration
  • Enforcer Configuration
  • Advanced Configuration
  • Docker Image
  • Complete Example
  • Cloudflare Worker changelog
  • Installation
  • Installation with Terraform
  • Manual installation
  • Deploy the Cloudflare Enforcer for Shopify applications
  • API
  • Configuration
  • Configuration (v5 and Below)
  • Upgrading to Version 6
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Envoy Proxy
  • Changelog
  • Installation
  • Configuration Options
  • First Party Configuration
  • F5 BIGIP
  • Changelog
  • Installation
  • First Party Integration
  • Configuration
  • Configurational Classes
  • Advanced Customization
  • Troubleshooting
  • Fastly JavaScript Compute@Edge
  • Changelog
  • Installation
  • API
  • Configuration
  • Fastly Rust Compute@Edge changelog
  • Supported Features
  • Installation
  • Configuration
  • Changelog
  • Installation
  • Manual installation
  • Configuration
  • How it works
  • Upgrade to V12
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V11
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V10
  • Installing the Enforcer
  • GraphQL Support
  • Sensitive GraphQL Operations
  • Basic Configuration
  • Customized Subroutines
  • Additional Activity Handler
  • Advanced Blocking Response
  • Creating and Configuring the Edge-Dictionary
  • Custom CSS
  • Custom First Party Sensor Endpoint
  • Custom Logo
  • Custom JS Script
  • Custom Parameters
  • Filter Requests
  • Filter by HTTP Method
  • Filter by Route
  • Filter by Extension
  • Filter by IP
  • Filter by User Agent
  • Data Enrichment
  • First Party
  • First Party Snippet
  • Enforced Routes
  • Login Credentials Extraction
  • Modify First Party Response
  • Module Context Object
  • Module Enabled
  • Module Mode
  • Monitored Routes
  • Returning A Custom Block Page
  • Sensitive Routes
  • Test Block Flow on Monitoring Mode - Bypass Monitor Header
  • Upgrading the Enforcer
  • Changelog
  • Installation
  • API
  • Configuration
  • Installing the Enforcer
  • Supported Features
  • Configuration Options
  • Upgrading the Enforcer
  • Google Cloud Platform (GCP) Callout Enforcer
  • Integrate the GCP Callout Enforcer
  • HAProxy changelog
  • Supported Software Versions
  • Supported Features
  • Installation
  • Configuration
  • Java changelog
  • Installation
  • Configuration
  • Upgrading
  • Kong Plugin
  • Changelog
  • NGINX Gateway Fabric with the HUMAN Enforcer
  • NGINX Gateway Fabric Enforcer configurations
  • Ingress NGINX controller
  • Ingress NGINX Enforcer configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation (Next.js 16)
  • Installation (Next.js 15 and lower)
  • Configuration
  • NGINX - C Module
  • NGINX changelog
  • Supported Features
  • Installation
  • Module Configuration
  • Configuration Options
  • Enrichment
  • First Party Configuration
  • Nginx Docker Image
  • Ingress NGINX Controller with HUMAN Enforcer
  • NGINX - LUA Module
  • Changelog
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • HUMAN Plugin Configuration
  • First Party Configuration
  • Enrichment
  • Changelog
  • Installation
  • API
  • Configuration
  • Configuration Options (7.9.0 and below)
  • Upgrading to Version 8
  • PHP
  • Changelog
  • Upgrading
  • Configuration Options
  • Advanced Configuration
  • Python
  • Changelog
  • Installation
  • Required Configuration
  • Configuration Options
  • Upgrading
  • First Party Configuration
  • Ruby
  • Changelog
  • Installation
  • Configuration
  • Additional Information
  • Salesforce Commerce Cloud Cartridge
  • Changelog
  • Importing the Cartridge
  • Registering the Cartridge
  • Importing Metadata and Services
  • Configuring the Cartridge
  • Using the Cartridge
  • SCAPI Protection Considerations
  • Upgrading
  • Customized Block Page
  • Configuration options
  • First Party
  • Varnish changelog
  • Supported Software Versions
  • Installation
  • Configuration Options
  • Enforcer Configuration
  • Example configuration
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • May 25, 2026
  • Version 2.0.0
  • May 17, 2026
  • Version 1.3.0
  • October 10, 2024
  • Version 1.2.0
  • March 6, 2024
  • Version 1.1.0
  • October 24, 2023
  • Version 1.0.0
  • March 20, 2023
  • Version 0.2.0
  • February 10, 2023
  • Version 0.1.0
Enforcer frameworksFastly JavaScript Compute@Edge

Changelog

May 25, 2026
May 25, 2026

May 17, 2026
May 17, 2026

October 10, 2024
October 10, 2024

March 6, 2024
March 6, 2024

October 24, 2023
October 24, 2023

March 20, 2023
March 20, 2023

February 10, 2023
February 10, 2023
Built with
Login

Version 2.0.0

Added

  • Support cookie v3 and set default cookie version to v3

Version 1.3.0

Added

  • Support for MCP Protection (Agentic Trust) via px_agentic_trust_enabled and px_agentic_trust_mcp_endpoint_path configurations
  • Support for snippet injection via px_snippet_injection_enabled and px_create_custom_snippet configurations
  • Support for proxy URL via px_proxy_url configuration
  • Support for data enrichment header via px_data_enrichment_header_name configuration
  • Support for async timeout via px_async_timeout configuration
  • Support for configuring whether async HTTP requests are awaited via px_await_async_http_requests configuration
  • Support for response custom parameters 11-20 extracted from the origin response via px_enrich_response_custom_parameters
  • Support for Hard Block action
  • Support for regex-formatted strings (e.g., "/^\/path$/i") in route and user-agent filter configurations (px_sensitive_routes, px_monitored_routes, px_enforced_routes, px_graphql_routes, px_filter_by_route, px_filter_by_user_agent, px_graphql_keywords, px_sensitive_graphql_operation_names)
  • Support for regular expressions in px_filter_by_user_agent
  • orig_cookie_vid field added to all Enforcer activities
  • is_sensitive_route field added to risk API and async activities
  • Request object now passed to response custom parameters function (px_enrich_response_custom_parameters)

Changed

  • Updated perimeterx-js-core to v0.37.1
  • Telemetry activity update_reason field now reflects the reason for telemetry (command or risk) and includes a request_id field

Version 1.2.0

  • Added GraphQL query keyword extraction via string/regex (px_graphql_keywords) and custom function (px_extract_graphql_keywords)
  • Added support for cookie secret rotation
  • Modified telemetry activity to include all types of config and include redacted sensitive configuration fields
  • Changed default value for px_bypass_monitor_header changed from empty string to “x-px-block”
  • Changed configuration px_sensitive_graphql_operation_names expanded to include regular expressions and applies to extracted GraphQL keywords as well
  • Fixed issue where unvalidated _pxvid value was added to the captcha page
  • Fixed issue where regular expressions occasionally failed on calls to test() due to global flag
  • Fixed BodyLoginSuccessfulParser bug by implementing text() method in OutgoingResponse
  • Replaced \\/ with / in the telemetry regex fields value
  • Fixed GraphQL operation name extraction issue

Version 1.1.0

  • Added support for URL decode reserved characters feature
  • Added risk_start_time and enforcer_start_time fields to enforcer activities
  • Added base64-encoded URL and HTTP method to captcha script query parameters on block pages
  • Added configuration for adding the Secure flag to PXHD cookie
  • Added custom function configurations for filtered, enforced, monitored, and sensitive requests
  • Changed Bot Defender captcha page to include client-side first party timeout
  • Fixed JSON parsing issue with generated package.json for CommonJS library build
  • Fixed inaccurate types for px_filter_by_route, px_monitored_routes, px_enforced_routes, px_sensitive_routes, px_graphql_routes configs to be Array<string | RegExp>

Version 1.0.0

  • Added support for Credential Intelligence
  • Added support for Account Defender (user identifiers)
  • Added support for CORS
  • Added support for custom first party endpoints
  • Added support for header-based logger
  • Updated HUMAN JavaScript Core to v0.9.0
  • Updated Fastly JS Compute SDK to v3.4.0

Version 0.2.0

  • Updated HUMAN JavaScript Core to v0.3.0
  • Updated additional dependencies
  • Added support for GraphQL including:
    • Customized GraphQL routes
    • Multiple GraphQL operations
    • Sensitive GraphQL operations by name or type
  • Fixed minor fixes to align activities to spec (px_orig_cookie, async activity headers)
  • Fixed bug that disregarded block action returned from risk v2 response
  • Custom cookie header is processed in addition to (not instead of) default cookie header
  • Custom cookie header default value has been set to x-px-cookies

Version 0.1.0

  • Support for a variety of basic and advanced features including:
    • Additional activity handler
    • Advanced blocking response
    • Block activity
    • Block page captcha
    • Block page rate limit
    • Bypass monitor header
    • Client IP extraction
    • Cookie v2
    • Custom cookie header
    • CSS ref
    • Custom logo
    • Custom parameters
    • Filter by extension
    • Filter by IP
    • Filter by HTTP method
    • Filter by route
    • Filter by user agent
    • First party
    • JS ref
    • Logger
    • Mobile support
    • Module enable
    • Module mode
    • Monitored routes
    • Page requested activity
    • HUMANDE
    • HUMANHD
    • Risk API
    • Sensitive headers
    • Sensitive routes
    • Telemetry command
    • VID extraction