Skip to content

Integrate using Google Cloud CDN

Google Cloud CDN is a fully managed service that distributes HTTP(S) traffic across backend services and can inspect and modify traffic at the edge. This allows it to act not only as a global entry point for applications but also as a point of control for injecting or filtering content in transit.

Mosaic provides a native integration with GCP Service Extensions that enables you to inject the Fraud Prevention into HTML responses automatically, without modifying your web application code.

This plugin intercepts HTML responses at the CDN level and injects the required `;

Note (Backend handoff)

Make sure to pass the received actionToken to your backend together with the actual action invocation so that your server can fetch the recommendation in the next step.

Step 6: Fetch recommendation

Backend

From your server, fetch recommendations for the reported action using the Recommendation API.

These APIs are authorized using an OAuth access token. Obtain a token with client credentials (from Step 1).

  const resp = await fetch(
    `https://api.transmitsecurity.io/oidc/token`,
    {
      method: 'POST',
      headers: {
        'Content-Type': 'application/x-www-form-urlencoded'
      },
      body: new URLSearchParams({
        grant_type: 'client_credentials',
        client_id: '[CLIENT_ID]',
        client_secret: '[CLIENT_SECRET]'
      })
    }
  );
  const { access_token } = await resp.json();

From your backend, invoke the Recommendation API. The [ACCESS_TOKEN] is the token you obtained above and [ACTION_TOKEN] is the actionToken received from the SDK in Step 5.

const query = new URLSearchParams({
  action_token: '[ACTION_TOKEN]',
}).toString();

const resp = await fetch(
  `https://api.transmitsecurity.io/risk/v1/recommendation?${query}`,
  {
    method: 'GET',
    headers: {
      Authorization: 'Bearer [ACCESS_TOKEN]',
    },
  }
);
Note (Backend step)

This is a server-side (machine-to-machine) call and is not handled by the CDN plugin or the Web SDK.

Step 7: Set user after a successful login

Client

A user identifier should be reported to Mosaic only after the user is fully authenticated, including any required 2FA. This sets the user for subsequent events in the current browser session.

The Web SDK is automatically injected and initialized by the CDN plugin after Steps 3-4. For successful login and custom login actions, if the code that completes the login still has the original actionToken from Step 5, prefer reportActionResult(). This records the outcome on that login action and sets the user for the current browser session. We recommend passing [USER_ID] as an opaque identifier from your system, not a plain-text personal identifier such as an email address.

await window.tsPlatform.drs.reportActionResult('[ACTION_TOKEN]', 'success', {
  userId: '[USER_ID]'
});
Fallback option

If your application architecture does not preserve the original actionToken through login completion, for example after a redirect, in a different page or component, in a server-side callback, or in an external identity flow, use setAuthenticatedUser() as a fallback in your web application code.

await window.tsPlatform.drs.setAuthenticatedUser('[USER_ID]');
Already authenticated users

If the user is already fully authenticated before the current Fraud Prevention flow, report the action with authContext instead of setting the user in a separate call. See Associate users with risk actions.

Note

Do not include personal user identifiers (e.g., email) in plain text.

Step 8: Clear user

Client

When the user logs out or the session expires, clear the user so future actions aren’t associated with the previous user. Implement this in your web application (e.g., on logout).

const tsClearUserHandler = `

`;