For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
LogoLogo
HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
Login
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
  • General
    • About Enforcers
    • Support first-party HUMAN calls
    • Deploy Tool
    • Troubleshoot Enforcer configurations
  • Enforcer frameworks
    • Akamai ESI
    • Apache - C Module
    • ASP.NET
    • Callout Enforcer
    • Envoy Proxy
    • F5 BIGIP
    • Fastly JavaScript Compute@Edge
      • Fastly Rust Compute@Edge changelog
      • Supported Features
      • Installation
      • Configuration
    • Google Cloud Platform (GCP) Callout Enforcer
    • Kong Plugin
    • NGINX - C Module
    • NGINX - LUA Module
    • PHP
    • Python
    • Ruby
    • Salesforce Commerce Cloud Cartridge
  • About Enforcers
  • Support first-party HUMAN calls
  • Deploy Tool
  • Troubleshoot Enforcer configurations
  • Akamai EdgeWorker changelog
  • Installation
  • Manual installation
  • Configuration
  • API
  • Upgrading
  • Supported Features
  • Install the Akamai EdgeWorker Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Akamai ESI
  • Akamai ESI changelog
  • Installation
  • Configuration
  • First Party Configuration
  • Apache - C Module
  • Apache changelog
  • Module Configuration
  • Configuration Options
  • First Party Configuration
  • Apigee Edge changelog
  • Installation
  • Configuration
  • ASP.NET
  • ASP.NET changelog
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • Configuration
  • AWS Lambda@Edge changelog
  • Installation
  • Manual installation
  • API
  • Configuration
  • Upgrading
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Changelog
  • Install the Azure Front Door Enforcer
  • Manually install the Azure Front Door Enforcer
  • API
  • Configuration
  • Callout Enforcer
  • Changelog
  • Supported Features
  • Envoy configuration
  • Enforcer Configuration
  • Advanced Configuration
  • Docker Image
  • Complete Example
  • Cloudflare Worker changelog
  • Installation
  • Installation with Terraform
  • Manual installation
  • Deploy the Cloudflare Enforcer for Shopify applications
  • API
  • Configuration
  • Configuration (v5 and Below)
  • Upgrading to Version 6
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Envoy Proxy
  • Changelog
  • Installation
  • Configuration Options
  • First Party Configuration
  • F5 BIGIP
  • Changelog
  • Installation
  • First Party Integration
  • Configuration
  • Configurational Classes
  • Advanced Customization
  • Troubleshooting
  • Fastly JavaScript Compute@Edge
  • Changelog
  • Installation
  • API
  • Configuration
  • Fastly Rust Compute@Edge changelog
  • Supported Features
  • Installation
  • Configuration
  • Changelog
  • Installation
  • Manual installation
  • Configuration
  • How it works
  • Upgrade to V12
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V11
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V10
  • Installing the Enforcer
  • GraphQL Support
  • Sensitive GraphQL Operations
  • Basic Configuration
  • Customized Subroutines
  • Additional Activity Handler
  • Advanced Blocking Response
  • Creating and Configuring the Edge-Dictionary
  • Custom CSS
  • Custom First Party Sensor Endpoint
  • Custom Logo
  • Custom JS Script
  • Custom Parameters
  • Filter Requests
  • Filter by HTTP Method
  • Filter by Route
  • Filter by Extension
  • Filter by IP
  • Filter by User Agent
  • Data Enrichment
  • First Party
  • First Party Snippet
  • Enforced Routes
  • Login Credentials Extraction
  • Modify First Party Response
  • Module Context Object
  • Module Enabled
  • Module Mode
  • Monitored Routes
  • Returning A Custom Block Page
  • Sensitive Routes
  • Test Block Flow on Monitoring Mode - Bypass Monitor Header
  • Upgrading the Enforcer
  • Changelog
  • Installation
  • API
  • Configuration
  • Installing the Enforcer
  • Supported Features
  • Configuration Options
  • Upgrading the Enforcer
  • Google Cloud Platform (GCP) Callout Enforcer
  • Integrate the GCP Callout Enforcer
  • HAProxy changelog
  • Supported Software Versions
  • Supported Features
  • Installation
  • Configuration
  • Java changelog
  • Installation
  • Configuration
  • Upgrading
  • Kong Plugin
  • Changelog
  • NGINX Gateway Fabric with the HUMAN Enforcer
  • NGINX Gateway Fabric Enforcer configurations
  • Ingress NGINX controller
  • Ingress NGINX Enforcer configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation (Next.js 16)
  • Installation (Next.js 15 and lower)
  • Configuration
  • NGINX - C Module
  • NGINX changelog
  • Supported Features
  • Installation
  • Module Configuration
  • Configuration Options
  • Enrichment
  • First Party Configuration
  • Nginx Docker Image
  • Ingress NGINX Controller with HUMAN Enforcer
  • NGINX - LUA Module
  • Changelog
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • HUMAN Plugin Configuration
  • First Party Configuration
  • Enrichment
  • Changelog
  • Installation
  • API
  • Configuration
  • Configuration Options (7.9.0 and below)
  • Upgrading to Version 8
  • PHP
  • Changelog
  • Upgrading
  • Configuration Options
  • Advanced Configuration
  • Python
  • Changelog
  • Installation
  • Required Configuration
  • Configuration Options
  • Upgrading
  • First Party Configuration
  • Ruby
  • Changelog
  • Installation
  • Configuration
  • Additional Information
  • Salesforce Commerce Cloud Cartridge
  • Changelog
  • Importing the Cartridge
  • Registering the Cartridge
  • Importing Metadata and Services
  • Configuring the Cartridge
  • Using the Cartridge
  • SCAPI Protection Considerations
  • Upgrading
  • Customized Block Page
  • Configuration options
  • First Party
  • Varnish changelog
  • Supported Software Versions
  • Installation
  • Configuration Options
  • Enforcer Configuration
  • Example configuration
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • August 20, 2026
  • 2.2.2
  • August 7, 2026
  • 2.2.1
  • July 30, 2026
  • 2.2.0
  • June 30, 2026
  • 2.1.1
  • June 17, 2026
  • 2.1.0
  • June 16, 2026
  • 2.0.0
  • June 1, 2026
  • v1.2.9
  • May 28, 2026
  • v1.2.8
  • May 7, 2026
  • Version 1.2.7
  • April 30, 2026
  • Version 1.2.6
Enforcer frameworksFastly Rust Compute@Edge

Fastly Rust Compute@Edge changelog

August 20, 2026
August 20, 2026

August 7, 2026
August 7, 2026

July 30, 2026
July 30, 2026

June 30, 2026
June 30, 2026

June 17, 2026
June 17, 2026

June 16, 2026
June 16, 2026

June 1, 2026
June 1, 2026

May 28, 2026
May 28, 2026

May 7, 2026
May 7, 2026

April 30, 2026
April 30, 2026
Older posts
Next
Built with
Login

2.2.2

Fixed

  • Issue with enforced_request logic

2.2.1

Fixed

  • Improved processing of the Bypass Monitor header

2.2.0

Added

  • Added enforced/monitored request callbacks, update example application
  • Added px_pxhd_domain configuration

Fixed

  • Populate custom_params before Risk API call
  • Correctly update SAPI/collector host names

2.1.1

Added

  • Two additional fields to all async activities:
    • s2s_call_reason
    • risk_mode

Changed

  • Updated dependencies

2.1.0

Added

  • [Secret store] Load PX credentials from Fastly Secret Store so deployments can keep required secrets out of ConfigStore/KVStore. Secret values override configured keys when present, while missing secrets fall back to existing config and log errors.

  • add documentation for all public PXContext getters

Changed

  • update fastly dependency to v0.13.0

2.0.0

Added

  • [MCP Protection / Agentic Trust] verify MCP requests and extract JSON-RPC metadata (method, tool name, tool argument keys, session id); config px_agentic_trust_enabled, px_agentic_trust_mcp_endpoint_path
  • [Credentials Intelligence] login credential extraction with breached-credential detection and login-success reporting; config px_login_credentials_extraction_enabled, px_login_credentials_extraction, px_credentials_intelligence_version, px_compromised_credentials_header, px_additional_s2s_activity_*, px_login_successful_*, callbacks px_extract_credentials_fn / px_login_successful_fn
  • [User Identifiers] extract app user id and extra fields from a JWT in a cookie or header; config px_jwt_cookie_* and px_jwt_header_*
  • [_pxhd cookie] set the _pxhd risk cookie on responses; config px_secured_pxhd_enabled to add the Secure attribute
  • [Risk cookie hardening] configurable validation limits: px_user_agent_max_length, px_risk_cookie_max_length, px_risk_cookie_min_iterations, px_risk_cookie_max_iterations
  • [Remote configuration] KV Store backend (kv_store cargo feature) and runtime config updates via update_from_json (initial support, used by e2e testing)
  • [Hard block page] new block_page_hard_block.tmpl template and block/rate-limit template updates
  • [Cookie V2 / Mobile SDK] add V2 cookie validation and mobile SDK token (original-token) support; config px_token_version (V2/V3)
  • [E2E testing harness] new e2e_testing application for testing Enforcer code
  • [CI workflows] auto changelog update, example-compilation check, and cargo-tests workflows
  • [Test suites] new config and credentials-intelligence integration tests

Changed

  • [Split backends/hosts] separate Fastly backend per HUMAN service: human_sapi, human_collector, human_client, human_captcha
  • [Config] large pxconfig refactor: serde-based deserialization, typed PXConfigKey with sensitive/static/local classification, documented px_* fields
  • [Telemetry] improve support for Telemetry command
  • [Client IP extraction] improved real-client-IP resolution from trusted px_ip_headers
  • [Enforcer] enforcement-flow fixes and improvements
  • [Dependencies] add strum/strum_macros, bump regex/uuid, update project metadata
  • renamed px_filter_by_method to px_filter_by_http_method
  • public getters/fields renamed (whitelist_* -> filter_by_*)

v1.2.9

Added

  • support for APQ-style GraphQL queries
  • support for GraphQL keywords extraction
  • new configuration: px_graphql_keywords

v1.2.8

Added

  • support for px_custom_cookie_header configuration (default is “x-px-cookies”)

Changed

  • update fastly dependency to v0.12.1

Version 1.2.7

Changed

  • Fix is_sensitive_request_fn callback overwriting prior sensitivity detection from sensitive_routes configuration and GraphQL inspection. The callback’s result is now OR-ed with the existing value, so it can only escalate (never demote) a request’s sensitivity.

Version 1.2.6

Added

  • px_graphql_body_max_length configuration to set GraphQL max body length
  • Included missing fields in all activities

Fixed

  • Optimized processing of GraphQL requests with large bodies