For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
LogoLogo
HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
Login
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
  • General
    • About Enforcers
    • Support first-party HUMAN calls
    • Deploy Tool
    • Troubleshoot Enforcer configurations
  • Enforcer frameworks
    • Akamai ESI
    • Apache - C Module
    • ASP.NET
    • Callout Enforcer
    • Envoy Proxy
    • F5 BIGIP
    • Fastly JavaScript Compute@Edge
    • Google Cloud Platform (GCP) Callout Enforcer
    • Kong Plugin
    • NGINX - C Module
    • NGINX - LUA Module
      • Changelog
      • Installation
      • API
      • Configuration
      • Configuration Options (7.9.0 and below)Deprecated
      • Upgrading to Version 8
    • PHP
    • Python
    • Ruby
    • Salesforce Commerce Cloud Cartridge
  • About Enforcers
  • Support first-party HUMAN calls
  • Deploy Tool
  • Troubleshoot Enforcer configurations
  • Akamai EdgeWorker changelog
  • Installation
  • Manual installation
  • Configuration
  • API
  • Upgrading
  • Supported Features
  • Install the Akamai EdgeWorker Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Akamai ESI
  • Akamai ESI changelog
  • Installation
  • Configuration
  • First Party Configuration
  • Apache - C Module
  • Apache changelog
  • Module Configuration
  • Configuration Options
  • First Party Configuration
  • Apigee Edge changelog
  • Installation
  • Configuration
  • ASP.NET
  • ASP.NET changelog
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • Configuration
  • AWS Lambda@Edge changelog
  • Installation
  • Manual installation
  • API
  • Configuration
  • Upgrading
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Changelog
  • Install the Azure Front Door Enforcer
  • Manually install the Azure Front Door Enforcer
  • API
  • Configuration
  • Callout Enforcer
  • Changelog
  • Supported Features
  • Envoy configuration
  • Enforcer Configuration
  • Advanced Configuration
  • Docker Image
  • Complete Example
  • Cloudflare Worker changelog
  • Installation
  • Installation with Terraform
  • Manual installation
  • Deploy the Cloudflare Enforcer for Shopify applications
  • API
  • Configuration
  • Configuration (v5 and Below)
  • Upgrading to Version 6
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Envoy Proxy
  • Changelog
  • Installation
  • Configuration Options
  • First Party Configuration
  • F5 BIGIP
  • Changelog
  • Installation
  • First Party Integration
  • Configuration
  • Configurational Classes
  • Advanced Customization
  • Troubleshooting
  • Fastly JavaScript Compute@Edge
  • Changelog
  • Installation
  • API
  • Configuration
  • Fastly Rust Compute@Edge changelog
  • Supported Features
  • Installation
  • Configuration
  • Changelog
  • Installation
  • Manual installation
  • Configuration
  • How it works
  • Upgrade to V12
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V11
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V10
  • Installing the Enforcer
  • GraphQL Support
  • Sensitive GraphQL Operations
  • Basic Configuration
  • Customized Subroutines
  • Additional Activity Handler
  • Advanced Blocking Response
  • Creating and Configuring the Edge-Dictionary
  • Custom CSS
  • Custom First Party Sensor Endpoint
  • Custom Logo
  • Custom JS Script
  • Custom Parameters
  • Filter Requests
  • Filter by HTTP Method
  • Filter by Route
  • Filter by Extension
  • Filter by IP
  • Filter by User Agent
  • Data Enrichment
  • First Party
  • First Party Snippet
  • Enforced Routes
  • Login Credentials Extraction
  • Modify First Party Response
  • Module Context Object
  • Module Enabled
  • Module Mode
  • Monitored Routes
  • Returning A Custom Block Page
  • Sensitive Routes
  • Test Block Flow on Monitoring Mode - Bypass Monitor Header
  • Upgrading the Enforcer
  • Changelog
  • Installation
  • API
  • Configuration
  • Installing the Enforcer
  • Supported Features
  • Configuration Options
  • Upgrading the Enforcer
  • Google Cloud Platform (GCP) Callout Enforcer
  • Integrate the GCP Callout Enforcer
  • HAProxy changelog
  • Supported Software Versions
  • Supported Features
  • Installation
  • Configuration
  • Java changelog
  • Installation
  • Configuration
  • Upgrading
  • Kong Plugin
  • Changelog
  • NGINX Gateway Fabric with the HUMAN Enforcer
  • NGINX Gateway Fabric Enforcer configurations
  • Ingress NGINX controller
  • Ingress NGINX Enforcer configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation (Next.js 16)
  • Installation (Next.js 15 and lower)
  • Configuration
  • NGINX - C Module
  • NGINX changelog
  • Supported Features
  • Installation
  • Module Configuration
  • Configuration Options
  • Enrichment
  • First Party Configuration
  • Nginx Docker Image
  • Ingress NGINX Controller with HUMAN Enforcer
  • NGINX - LUA Module
  • Changelog
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • HUMAN Plugin Configuration
  • First Party Configuration
  • Enrichment
  • Changelog
  • Installation
  • API
  • Configuration
  • Configuration Options (7.9.0 and below)
  • Upgrading to Version 8
  • PHP
  • Changelog
  • Upgrading
  • Configuration Options
  • Advanced Configuration
  • Python
  • Changelog
  • Installation
  • Required Configuration
  • Configuration Options
  • Upgrading
  • First Party Configuration
  • Ruby
  • Changelog
  • Installation
  • Configuration
  • Additional Information
  • Salesforce Commerce Cloud Cartridge
  • Changelog
  • Importing the Cartridge
  • Registering the Cartridge
  • Importing Metadata and Services
  • Configuring the Cartridge
  • Using the Cartridge
  • SCAPI Protection Considerations
  • Upgrading
  • Customized Block Page
  • Configuration options
  • First Party
  • Varnish changelog
  • Supported Software Versions
  • Installation
  • Configuration Options
  • Enforcer Configuration
  • Example configuration
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • June 18, 2026
  • Version 8.7.0
  • March 4, 2026
  • Version 8.6.0
  • November 25, 2025
  • Version 8.5.0
  • November 3, 2025
  • Version 8.4.1
  • March 6, 2025
  • Version 8.3.0
  • September 23, 2024
  • Version 8.2.1
  • September 5, 2024
  • Version 8.2.0
  • February 21, 2024
  • Version 8.1.0
  • January 18, 2024
  • Version 8.0.1
  • January 10, 2024
  • Version 8.0.0
Enforcer frameworksNodeJS Express

Changelog

June 18, 2026
June 18, 2026

March 4, 2026
March 4, 2026

November 25, 2025
November 25, 2025

November 3, 2025
November 3, 2025

March 6, 2025
March 6, 2025

September 23, 2024
September 23, 2024

September 5, 2024
September 5, 2024

February 21, 2024
February 21, 2024

January 18, 2024
January 18, 2024

January 10, 2024
January 10, 2024
Older posts
Next
Built with
Login

Version 8.7.0

  • Use undici as the HTTP client instead of Phin, which is no longer maintained.
  • Added undici HTTP client implementation
  • Added risk_rtt field to activities in case of S2S timeout
  • Support for JWT key names that contain dots (such as URLs) when extracting the user id and additional fields
  • Custom block on error message configuration support
  • Pass request object to response custom parameters custom function
  • MCP Protection support
  • Send original vid from cookie on all activities under orig_cookie_vid
  • Added Hard Block Support

Version 8.6.0

  • Changed response headers being set as arrays instead of strings

Version 8.5.0

  • Added support for custom_proxy feature (px_proxy_url configuration)

Version 8.4.1

  • Added support for the custom_sensitive_request feature, which enables using a custom function to identify sensitive routes
  • Added is_sensitive_route field in activities

Version 8.3.0

  • Added support for running the Enforcer as a standalone Node.js process without requiring a code bundle.
  • Added remote_config_id field to risk and async activities
  • Added remote_config_id and remote_config_version fields to telemetry activity
  • DefaultGraphQLParser modified to extract operationName and variables even when the query is not present
  • Specifying token version (v2 or v3) with px_token_version always for consistency in telemetry activities
  • Fixed issue where telemetry would fail for array of cookie strings
  • Fixed issue where UrlImpl constructor would throw an error for @ character in the path or search params
  • CD process fix

Version 8.2.1

  • Decode the request URL, send it on the enforcer activities URL field, and use it for all enforcer processing.

Version 8.2.0

  • Added px_token_version configuration to support both v2 and v3 (default is v3)
  • GraphQL query keyword extraction via string/regex (px_graphql_keywords) and custom function (px_extract_graphql_keywords)
  • Support for cookie secret rotation
  • Configuration px_sensitive_graphql_operation_names expanded to include regular expressions and applies to extracted GraphQL keywords as well
  • Telemetry activity includes redacted sensitive configuration fields
  • Default value for px_bypass_monitor_header changed from an empty string to “x-px-block”
  • Modify telemetry activity to include all types of config
  • Updated the captcha template
  • Using raw URL instead of parsed URL in block page captcha script query parameter
  • Converted fields login_successful_reporting_method, sent_through of CredentialEndpointConfiguration to optional
  • Fixed issue where unvalidated _pxvid value was added to the captcha page
  • Fixed issue where regular expressions occasionally failed on calls to test() due to global flag

Version 8.1.0

  • Added base64-encoded request HTTP method to captcha script query parameters on block pages
  • JSON parsing issue with generated package.json for CommonJS library build fixed
  • Issue with mix-ups in header-based logs fixed
  • Issue where block activities may contain http_status_code field fixed

Version 8.0.1

  • Issue with duplicate sending of batched activities fixed
  • Memory issue with header-based logger fixed

Version 8.0.0

  • Refactor to base on JS Core library
  • Maintains support for:
    • Additional activity handler
    • Advanced blocking response
    • Block activity
    • Block page captcha
    • Block page rate limit
    • Bypass monitor header
    • Client IP extraction
    • Cookie v3
    • CORS support
    • Credentials intelligence
    • CSS ref
    • Custom cookie header
    • Custom first-party endpoints
    • Custom logo
    • Custom parameters
    • Enforced routes
    • Filter by extension
    • Filter by HTTP method
    • Filter by IP
    • Filter by route
    • Filter by user agent
    • First party
    • GraphQL support
    • Header-based logger
    • Hype sale challenge
    • JS ref
    • Logger
    • Mobile support
    • Module enable
    • Module mode
    • Monitored routes
    • Page requested activity
    • PXDE
    • PXHD
    • Risk API
    • Sensitive headers
    • Sensitive routes
    • Telemetry command
    • URL decode reserved characters
    • User identifiers
    • VID extraction