HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI Reference
Product GuidesEnforcer GuidesMobile SDKAPI Reference
  • Getting Started
    • Overview
  • HUMAN Customer Support
    • HUMAN Customer Support
  • Sightline Cyberfraud Defense
    • Getting Started with Sightline Cyberfraud Defense
    • About the Overview Dashboard
  • Account Defender
    • Account Defender Overview
    • Use Cases
    • Prerequisites
    • Getting Started with Account Defender
    • Optimizing Account Defender Detection
    • Validating Account Defender Integration
    • Risk Triggers
    • About Network Events
    • Troubleshooting
  • Bot Defender
    • Bot Defender Overview
    • Detection
    • Bot Defender Policy Settings
    • Footprint
  • Credential Intelligence
    • Credential Intelligence Overview
    • How to Access the Breached Flag
    • Credential Intelligence FAQ
    • Credential Intelligence Dashboard
  • Code Defender
    • Code Defender Introduction
    • Getting Started with Code Defender
    • Code Defender Glossary
  • Platform
    • Page Type Mapping
    • Integrations
  • Client-Side Integration
    • JavaScript Tag
    • Use of Cookies & Web Storage
    • Advanced Client Integration
  • Third Party Integrations
    • Data Enrichment
    • Enabling Data View from BigQuery
    • Slack Integration
    • Auth0 Integration
LogoLogo
Login
Login
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • Supported Enforcer Types
  • Required Configurations
  • Step 1: Enable the Credential Extraction Flag
  • Step 2: Configure the Credential Extraction Paths
  • Step 3: Configure the Method to Retrieve the Response Status (Fail/Pass)
  • Step 4: Configure Multi-Step Logins if Applicable
Credential IntelligenceIntegrating Credential Intelligence

This section details all the required features that should be configured in the Enforcer (server-side integration) for Credential Intelligence to work.

Supported Enforcer Types
Required Configurations

Supported Enforcer Types

Akamai EdgeWorker Enforcer
Apache - C Module
AWS Lambda Edge
AWS API Gateway Lambda Authorizer
Cloudflare Worker
Fastly
GO
Salesforce Commerce Cloud Cartridge
Java
NGINX - C Module
NGINX - LUA Module
Node.JS Express
PHP

Required Configurations

Step 1: Enable the Credential Extraction Flag

This is a boolean flag on the enforcer configuration to enable the product.

Click here to review an example of Cloudflare configuration.

Step 2: Configure the Credential Extraction Paths

This is an array of extraction configurations that detail which requests have credentials on them and how to extract the credentials from these requests. Please note, that it is important to configure all authentication paths, including account login, new account creation, and password reset/change (for more information on the authentication path guidelines, click here to view top questions during onboarding). Click here to review an example of Cloudflare configuration.

It may be necessary to configure sensitive routes to include all login paths for older enforcer versions. Click here to review an example for Cloudflare configuration.

Step 3: Configure the Method to Retrieve the Response Status (Fail/Pass)

This is a series of configurations that determine how to report whether the login request was successful or not on the additional_s2s activity. Please note, that configuring the  additional_s2s activity allows us to quantify the number of compromised accounts that were observed active on the app.

Click here to review an example of Cloudflare configuration.

Step 4: Configure Multi-Step Logins if Applicable

This step is required only for multi-step authentication methods. Only in cases where usernames and passwords are sent in separate HTTP requests, the px_credentials_intelligence_version configuration value should be set to multistep_sso.

Multiple authentication methods and paths are supported, even if some are multi-step and some are not. Click here to review an example of Cloudflare configuration.

Was this page helpful?
Previous

Integrate Credential Intelligence with Auth0 on the Cloudflare Enforcer

Next
Built with
Integrate Credential Intelligence with Auth0 on the Cloudflare Enforcer

Credentials Intelligence: Enforcer Integration Guidelines