For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
LogoLogo
HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
Login
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
  • General
    • About Enforcers
    • Support first-party HUMAN calls
    • Deploy Tool
    • Troubleshoot Enforcer configurations
  • Enforcer frameworks
    • Akamai ESI
    • Apache - C Module
    • ASP.NET
    • Callout Enforcer
    • Envoy Proxy
    • F5 BIGIP
    • Fastly JavaScript Compute@Edge
    • Google Cloud Platform (GCP) Callout Enforcer
    • Kong Plugin
      • Changelog
      • Installation (Next.js 16)
      • Installation (Next.js 15 and lower)
      • Configuration
    • NGINX - C Module
    • NGINX - LUA Module
    • PHP
    • Python
    • Ruby
    • Salesforce Commerce Cloud Cartridge
  • About Enforcers
  • Support first-party HUMAN calls
  • Deploy Tool
  • Troubleshoot Enforcer configurations
  • Akamai EdgeWorker changelog
  • Installation
  • Manual installation
  • Configuration
  • API
  • Upgrading
  • Supported Features
  • Install the Akamai EdgeWorker Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Akamai ESI
  • Akamai ESI changelog
  • Installation
  • Configuration
  • First Party Configuration
  • Apache - C Module
  • Apache changelog
  • Module Configuration
  • Configuration Options
  • First Party Configuration
  • Apigee Edge changelog
  • Installation
  • Configuration
  • ASP.NET
  • ASP.NET changelog
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • Configuration
  • AWS Lambda@Edge changelog
  • Installation
  • Manual installation
  • API
  • Configuration
  • Upgrading
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Changelog
  • Install the Azure Front Door Enforcer
  • Manually install the Azure Front Door Enforcer
  • API
  • Configuration
  • Callout Enforcer
  • Changelog
  • Supported Features
  • Envoy configuration
  • Enforcer Configuration
  • Advanced Configuration
  • Docker Image
  • Complete Example
  • Cloudflare Worker changelog
  • Installation
  • Installation with Terraform
  • Manual installation
  • Deploy the Cloudflare Enforcer for Shopify applications
  • API
  • Configuration
  • Configuration (v5 and Below)
  • Upgrading to Version 6
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Envoy Proxy
  • Changelog
  • Installation
  • Configuration Options
  • First Party Configuration
  • F5 BIGIP
  • Changelog
  • Installation
  • First Party Integration
  • Configuration
  • Configurational Classes
  • Advanced Customization
  • Troubleshooting
  • Fastly JavaScript Compute@Edge
  • Changelog
  • Installation
  • API
  • Configuration
  • Fastly Rust Compute@Edge changelog
  • Supported Features
  • Installation
  • Configuration
  • Changelog
  • Installation
  • Manual installation
  • Configuration
  • How it works
  • Upgrade to V12
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V11
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V10
  • Installing the Enforcer
  • GraphQL Support
  • Sensitive GraphQL Operations
  • Basic Configuration
  • Customized Subroutines
  • Additional Activity Handler
  • Advanced Blocking Response
  • Creating and Configuring the Edge-Dictionary
  • Custom CSS
  • Custom First Party Sensor Endpoint
  • Custom Logo
  • Custom JS Script
  • Custom Parameters
  • Filter Requests
  • Filter by HTTP Method
  • Filter by Route
  • Filter by Extension
  • Filter by IP
  • Filter by User Agent
  • Data Enrichment
  • First Party
  • First Party Snippet
  • Enforced Routes
  • Login Credentials Extraction
  • Modify First Party Response
  • Module Context Object
  • Module Enabled
  • Module Mode
  • Monitored Routes
  • Returning A Custom Block Page
  • Sensitive Routes
  • Test Block Flow on Monitoring Mode - Bypass Monitor Header
  • Upgrading the Enforcer
  • Changelog
  • Installation
  • API
  • Configuration
  • Installing the Enforcer
  • Supported Features
  • Configuration Options
  • Upgrading the Enforcer
  • Google Cloud Platform (GCP) Callout Enforcer
  • Integrate the GCP Callout Enforcer
  • HAProxy changelog
  • Supported Software Versions
  • Supported Features
  • Installation
  • Configuration
  • Java changelog
  • Installation
  • Configuration
  • Upgrading
  • Kong Plugin
  • Changelog
  • NGINX Gateway Fabric with the HUMAN Enforcer
  • NGINX Gateway Fabric Enforcer configurations
  • Ingress NGINX controller
  • Ingress NGINX Enforcer configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation (Next.js 16)
  • Installation (Next.js 15 and lower)
  • Configuration
  • NGINX - C Module
  • NGINX changelog
  • Supported Features
  • Installation
  • Module Configuration
  • Configuration Options
  • Enrichment
  • First Party Configuration
  • Nginx Docker Image
  • Ingress NGINX Controller with HUMAN Enforcer
  • NGINX - LUA Module
  • Changelog
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • HUMAN Plugin Configuration
  • First Party Configuration
  • Enrichment
  • Changelog
  • Installation
  • API
  • Configuration
  • Configuration Options (7.9.0 and below)
  • Upgrading to Version 8
  • PHP
  • Changelog
  • Upgrading
  • Configuration Options
  • Advanced Configuration
  • Python
  • Changelog
  • Installation
  • Required Configuration
  • Configuration Options
  • Upgrading
  • First Party Configuration
  • Ruby
  • Changelog
  • Installation
  • Configuration
  • Additional Information
  • Salesforce Commerce Cloud Cartridge
  • Changelog
  • Importing the Cartridge
  • Registering the Cartridge
  • Importing Metadata and Services
  • Configuring the Cartridge
  • Using the Cartridge
  • SCAPI Protection Considerations
  • Upgrading
  • Customized Block Page
  • Configuration options
  • First Party
  • Varnish changelog
  • Supported Software Versions
  • Installation
  • Configuration Options
  • Enforcer Configuration
  • Example configuration
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • June 21, 2026
  • Version 0.3.2
  • May 4, 2026
  • Version 0.3.1
  • February 10, 2026
  • Version 0.3.0
  • December 4, 2025
  • Version 0.2.3
  • February 24, 2025
  • Version 0.2.2
  • August 28, 2024
  • Version 0.2.1
  • August 7, 2024
  • Version 0.2.0
  • May 31, 2023
  • Version 0.1.6
  • May 24, 2023
  • Version 0.1.5
  • May 18, 2023
  • Version 0.1.4
Enforcer frameworksNextJS

Changelog

June 21, 2026
June 21, 2026

May 4, 2026
May 4, 2026

February 10, 2026
February 10, 2026

December 4, 2025
December 4, 2025

February 24, 2025
February 24, 2025

August 28, 2024
August 28, 2024

August 7, 2024
August 7, 2024

May 31, 2023
May 31, 2023

May 24, 2023
May 24, 2023

May 18, 2023
May 18, 2023
Older posts
Next
Built with
Login

Version 0.3.2

Added

  • Custom block on error message: New px_custom_block_on_error_message configuration to display a custom message on block pages served due to an error

Fixed

  • URL host replacement in NextJSIncomingRequest now preserves the raw URL path without normalization (fixes raw URL tracking for paths containing dots or extra slashes)
  • Form URL-encoded body parsing now clones the request before reading to allow the body stream to be consumed multiple times

Version 0.3.1

Added

  • MCP Protection support: New configurations px_agentic_trust_enabled and px_agentic_trust_mcp_endpoint_path to protect MCP server endpoints
  • Proxy support: New px_proxy_url configuration to route outbound requests through an HTTP proxy
  • Added Hardblock support
  • Response custom parameters 11–20: px_enrich_response_custom_parameters can now populate custom parameters 11 through 20, extracted from the origin response
  • Data enrichment header: New px_data_enrichment_header_name configuration to specify the header used for data enrichment
  • Async timeout: New px_async_timeout configuration that applies to async activities, telemetry, remote logger, and remote configuration requests
  • Regex-formatted route strings: Route configurations (e.g. px_sensitive_routes, px_enforced_routes, px_filter_by_route, etc.) now accept strings in regex format (e.g. "/^\/api\/.*$/i") in addition to plain strings and RegExp objects

Version 0.3.0

Added

  • Support for Next.js ^16.0.0. Use proxy.ts and export const proxy = perimeterx(pxConfig) (or export default) on Next.js 16+; middleware.ts remains supported but is deprecated there.

Version 0.2.3

Fixed

  • onResponse signature updated for accuracy (changed response parameter to be type NextResponse)
  • Fixed Next.js critical vulnerability by bumping version to 15.5.7

Version 0.2.2

Changed

  • Upgraded JS Core to v0.24.2
  • Updated to support NextJS versions ^14.2.7 || ^15.0.0
  • Changed NextJS to be a peer dependency

Version 0.2.1

Changed

  • Using CryptoJS to read _px3
  • Supporting NextJS

Version 0.2.0

Changed

  • Upgraded to js-core 0.21.4
  • Added ci e2e tests
  • Upgraded next js to 13.4.4

Version 0.1.6

Fixed

  • Fixed context overriding between two different requests.

Version 0.1.5

Fixed

  • Using host header to construct url, the default implementation (by Next.js) does not do that.

Version 0.1.4

Changed

  • js-core version