> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging.auth0-mintlify.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Actions で Akamai Supplemental Signals を使用する

> Akamai Account Protector シグナルを使用して、Akamai のエッジネットワークから得られる bot、不正、リスクのスコアでログイン時の判定を強化します。

<Warning>
  Supplemental Signals はエンタープライズのお客様のみご利用いただけます。また、攻撃対策アドオンの申請が必要です。詳しくは [Auth0 Sales](https://auth0.com/get-started?place=header\&type=button\&text=talk%20to%20sales) までお問い合わせください。
</Warning>

<Card title="開始する前に">
  Actions で Akamai Supplemental Signals を使用するには、以下が必要です。

  * [Akamai をリバースプロキシとして設定する](/docs/ja-jp/customize/custom-domains/self-managed-certificates)
  * [Supplemental Signals を送信するように Akamai を設定する](/docs/ja-jp/secure/attack-protection/configure-akamai-supplemental-signals)
</Card>

Akamai で Supplemental Signals を使用するように設定すると、それらのシグナルから提供されるデータを [Auth0 Actions](/docs/ja-jp/customize/actions) で利用できます。

<h2 id="supported-supplemental-signals-by-action-trigger">
  Action トリガー別のサポート対象 Supplemental Signals
</h2>

| トリガー                   | Supplemental Signals オブジェクト                             | イベントオブジェクト                                                                                                                                                                                               |
| :--------------------- | :------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Login                  | <ul><li>`akamaiBot`</li><li>`akamaiUserRisk`</li></ul>  | [`event.authentication.riskAssessment.supplemental.akamai`](/docs/ja-jp/customize/actions/explore-triggers/signup-and-login-triggers/login-trigger/post-login-event-object)                              |
| Pre-User Registration  | <ul><li> `akamaiBot`</li><li>`akamaiUserRisk`</li></ul> | [`event.authentication.riskAssessment.supplemental.akamai`](/docs/ja-jp/customize/actions/explore-triggers/signup-and-login-triggers/pre-user-registration-trigger/pre-user-registration-event-object)   |
| Post-User Registration | <ul><li> `akamaiBot`</li><li>`akamaiUserRisk`</li></ul> | [`event.authentication.riskAssessment.supplemental.akamai`](/docs/ja-jp/customize/actions/explore-triggers/signup-and-login-triggers/post-user-registration-trigger/post-user-registration-event-object) |
| Send Phone Message     | なし                                                      | 該当なし                                                                                                                                                                                                     |
| Post-Challenge         | <ul><li> `akamaiBot`</li><li>`akamaiUserRisk`</li></ul> | [`event.authentication.riskAssessment.supplemental.akamai`](/docs/ja-jp/customize/actions/explore-triggers/password-reset-triggers/post-challenge-trigger/post-challenge-event-object)                   |
| Post-Change Password   | <ul><li> `akamaiBot`</li><li>`akamaiUserRisk`</li></ul> | [`event.authentication.riskAssessment.supplemental.akamai`](/docs/ja-jp/customize/actions/explore-triggers/password-reset-triggers/post-change-password-trigger/post-change-password-event-object)       |
| Credentials Exchange   | なし                                                      | 該当なし                                                                                                                                                                                                     |

<h2 id="supplemental-signal-object-schemas">
  Supplemental Signals オブジェクトのスキーマ
</h2>

`akamaiBot` オブジェクトと `akamaiUserRisk` オブジェクトには、認証フローをカスタマイズするために使用できる複数のプロパティが含まれています。

<ResponseField name="akamaiBot" type="object">
  <Expandable>
    <ResponseField name="action" type="string">
      Akamai Bot Manager の結果におけるアクション。

      Example: `Monitor`
    </ResponseField>

    <ResponseField name="botCategory" type="string[]">
      Akamai Bot Manager の結果におけるボットカテゴリ。

      Example: `["Web Search Engine Bots"]`
    </ResponseField>

    <ResponseField name="botScore" type="number">
      Akamai Bot Manager の結果におけるボットスコア。

      Example: `90`
    </ResponseField>

    <ResponseField name="botScoreResponseSegment" type="string">
      Akamai Bot Manager の結果におけるボットスコアのレスポンスセグメント。

      Example: `aggressive`
    </ResponseField>

    <ResponseField name="botnetId" type="string">
      Akamai Bot Manager の結果におけるボットネット ID。

      Example: `googlebot`
    </ResponseField>

    <ResponseField name="type" type="string">
      Akamai Bot Manager の結果の種類。

      Example: `Akamai-Categorized Bot`
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="akamaiUserRisk" type="object">
  <Expandable>
    <ResponseField name="action" type="string">
      Akamai User Risk Assessment におけるアクション。

      Example: `monitor`
    </ResponseField>

    <ResponseField name="allow" type="number">
      Akamai User Risk Assessment における許可ステータス。

      Example: `0`
    </ResponseField>

    <ResponseField name="emailDomain" type="string">
      ユーザーのメールドメイン。

      Example: `example.com`
    </ResponseField>

    <ResponseField name="general" type="object">
      Akamai User Risk Assessment における一般的なリスク。

      Example: `{ aci: “0”, db: “Chrome 85”, di: “0fc91b5ec42f5a471c16a85e3e388ca57697c1a9”, do: “Mac OS X 10” }`
    </ResponseField>

    <ResponseField name="ouid" type="string">
      ユーザーの OUID。

      Example: `m534264`
    </ResponseField>

    <ResponseField name="requestid" type="string">
      ユーザーのリクエスト ID。

      Example: `19e22e`
    </ResponseField>

    <ResponseField name="risk" type="object">
      Akamai User Risk Assessment におけるリスク。

      Example: `{ ugp: “ie/M”, unp: “432/H” }`
    </ResponseField>

    <ResponseField name="score" type="number">
      Akamai User Risk Assessment におけるスコア。

      Example: `0`
    </ResponseField>

    <ResponseField name="status" type="number">
      Akamai User Risk Assessment におけるステータス。

      Example: `4`
    </ResponseField>

    <ResponseField name="trust" type="object">
      Akamai User Risk Assessment における信頼性。

      Example: `{ udbp: "Chrome85", udfp: "25ba44ec3b391ba4ce5fbbd2979635e254775werwe", udop: "Mac OS X 10", ugp: "FR", unp: "12322", utp: "weekday_3" }`
    </ResponseField>

    <ResponseField name="username" type="string">
      ユーザーのユーザー名。

      Example: `testuser@example.com`
    </ResponseField>

    <ResponseField name="uuid" type="string">
      Akamai User Risk Assessment の UUID。

      Example: `86b37525-8047-4a3c-8d7a-23e99666da05`
    </ResponseField>
  </Expandable>
</ResponseField>

<h2 id="use-cases">
  利用例
</h2>

<AccordionGroup>
  <Accordion title="Akamai Account Protector の結果に基づいてセッションを取り消す">
    `akamaiUserRisk.score` プロパティに基づいてセッションを取り消す方法の例を以下に示します。

    ```javascript theme={null}
    exports.onExecutePostLogin = async (event, api) => {
      const userRiskHeader = event.authentication?.riskAssessment?.supplemental?.akamai?.akamaiUserRisk;
      if (userRiskHeader?.score && userRiskHeader?.score >= 90) {
            console.log('User is deemed high risk.');
            //これによりセッションクッキーが取り消され、ログインが拒否されます。
            api.session.revoke('Session revoked, User risk score is greater than 90.');
        }
    };

    ```

    `api.session.revoke` メソッドを使用すると (`api.access.deny` メソッドとは異なり) 、ユーザーがアプリケーションを再読み込みした場合でも、Akamai Supplemental Signals が認証リクエストとともに送信され、post-login Action フローがトリガーされるようになります。
  </Accordion>

  <Accordion title="Akamai Bot Manager の結果に基づいて多要素認証（MFA）を要求する">
    `akamaiBot.score` プロパティに基づいて MFA を強制する方法の例を以下に示します。

    <h4 id="enforce-mfa">
      MFA を強制する
    </h4>

    この Action は 2 つのタスクを実行します。

    1. **[アプリメタデータ](/docs/ja-jp/manage-users/user-accounts/metadata/metadata-fields-data)を更新する**: score プロパティが指定した値を超えた場合、このセッションで MFA が必要であることを記録します。
    2. **MFA を要求する**: score プロパティが指定した値を超えた場合、またはこのセッションで MFA が必要であることを示す記録がアプリメタデータにある場合に、MFA を強制します。

    ```javascript theme={null}
    exports.onExecutePostLogin = async (event, api) => {
      const userRiskHeader = event.authentication?.riskAssessment?.supplemental?.akamai?.akamaiUserRisk;

      if (userRiskHeader?.score && userRiskHeader?.score >= 90) {
        console.log(`Setting app metadata for session id: ${event.session?.id}`);
        api.user.setAppMetadata(`mfa_required_${event.session?.id}`, true);
      }

      if (userRiskHeader?.score && userRiskHeader?.score >= 90 ||
          event.user.app_metadata[`mfa_required_${event.session?.id}`]) {
            console.log(`Requiring MFA FOR Session id: ${event.session?.id}`);
            api.multifactor.enable('any', {allowRememberBrowser: false});
      }
    };

    ```

    <h4 id="clean-up-app-metadata">
      アプリメタデータをクリーンアップする
    </h4>

    この Action は、ユーザーが MFA を正常に完了した後、アプリメタデータからセッション固有の MFA 情報を削除します。

    ```javascript theme={null}
    exports.onExecutePostLogin = async (event, api) => {
      const mfaMethod = event.authentication?.methods.find((method) => {
        return method.name === 'mfa';
      });

      if (mfaMethod) {
        console.log(`Removing MFA requirement for session id: ${event.session?.id}`);
        api.user.setAppMetadata(`mfa_required_${event.session?.id}`, undefined);
      }
    };
    ```
  </Accordion>
</AccordionGroup>
