DataDome Bypass API to Bypass DataDome and PerimeterX When Scraping
Send the URL that keeps coming back as a 403 or a slider CAPTCHA and get the real page instead. Each request leaves on a rotating residential address with one consistent browser identity, the DataDome or PerimeterX check runs before the response reaches your code, and you receive raw HTML or the fields you named as typed JSON. Blocked attempts are never billed.
- Status
- ...
- Elapsed
- ... ms
- Exit country
- ...
- Browser used
- ...
This console sends a real request and shows you the real response. Five live fetches per session, and the sample targets run as often as you like.
What a DataDome bypass API does for you
A DataDome bypass API fetches public pages protected by DataDome or PerimeterX and returns the finished HTML or parsed JSON. It sends every request from a residential address, keeps the TLS handshake, headers and browser fingerprint consistent with each other, runs the vendor's JavaScript check, and retries on a fresh identity when a request is refused.
Nobody switches DataDome off. It scores traffic and lets through what looks like a real visitor, so "bypassing" it means arriving as a request it has no reason to stop. That is simple to describe and tiring to maintain, because both vendors retrain their models continuously and a setup that passed in June is back to 403s by August.
The people who buy this already have a scraper. It worked on the target until the site added DataDome or HUMAN, and now the project has a deadline and a data gap. Handing the fetch to an API turns that into a line item instead of a research project.
What DataDome and PerimeterX each check
The two vendors look at the same layers but punish failures differently. Knowing which one sits in front of your target tells you what went wrong before you change anything.
| Layer | DataDome | PerimeterX (HUMAN) |
|---|---|---|
| IP address | Reputation and network type feed a running trust score for the address and session | Residential and mobile addresses score well, datacenter ranges start with a penalty |
| TLS and HTTP | JA3 style handshake fingerprint, HTTP version and header order compared with the claimed browser | The same checks, applied at the edge before any page content is sent |
| Browser check | A JavaScript tag reads canvas, WebGL, plugins, screen, timezone and the webdriver flag, then sets a datadome cookie | A sensor script collects runtime and hardware details and issues the session cookies the site then requires |
| Behavior | Click cadence, scroll, mouse paths and dwell time across the session | Browsing pattern, resource loading and timing, with models trained per customer site |
| What you see when you fail | Usually HTTP 403 with a slider CAPTCHA loaded from captcha-delivery.com, or an outright ban once the trust score drops far enough | HTTP 403 and a page reading "Access to this page has been denied" with a Press and Hold button |
The practical lesson is that the visible challenge is a symptom. Solving the slider or holding the button does not fix the address or fingerprint that triggered it, so the next request is challenged again. The same pattern holds for Cloudflare, covered on the Cloudflare scraping API page.
Who needs to scrape DataDome and PerimeterX sites
-
Retail and marketplace pricing teams
Large US retailers, sneaker and resale marketplaces and ticketing sites are the classic DataDome and HUMAN customers, because scalping and inventory bots cost them real money. If your price monitor covers those sites, you meet these vendors every day. The Amazon scraper API handles the largest storefront the same way.
-
Travel and classifieds aggregators
Fares, listings and availability sit on exactly the pages these vendors defend hardest. Sticky sessions keep one identity through a search and its result pages, which is what the behavior models expect from a real visitor.
-
Recruiting and HR data teams
Several of the big job boards run bot management in front of their listings. Teams feeding a hiring signal product use the job scraping API for the boards and this endpoint for the protected ones.
-
Agencies with client deadlines
When a tracked competitor adds DataDome in the middle of a quarter, the monthly report still has to ship. Moving that one domain to an API is usually faster than rebuilding the crawler.
How a protected page comes back in four steps
-
Step 1
Send the URL
One GET with your key. You do not need to know which vendor protects the page.
-
Step 2
One consistent identity
A residential address, a shipped browser build and a matching TLS and header profile are picked together, so no layer contradicts another.
-
Step 3
The check runs
The vendor's script executes in a real browser and sets its cookie. A refusal is retried on a new identity, and those retries are not billed.
-
Step 4
HTML or JSON back
Raw markup for your parser, or the fields you named, such as price, stock and title, as typed values.
If you write Python, the Python scraping tool quickstart replaces your requests or Selenium call with a single function, so a "datadome bypass python" project stops being a stealth plugin to maintain.
Ways to get past DataDome and PerimeterX, compared honestly
Each approach is right for someone. The difference is who does the maintenance when the vendor ships its next model.
| Approach | Where it wins | Where it costs you |
|---|---|---|
| Stealth plugins (puppeteer-extra, undetected-chromedriver) | Low volume, a site on light settings, an engineer with spare time | Behind within weeks of each vendor update, and still exposed on the address unless you buy proxies too |
| Newer patched browsers (Camoufox, Nodriver and similar) | Better fingerprints than plugins, full control of the session and clicks | You host and scale a browser fleet, and one bad fingerprint burns the residential address it ran on |
| Open source CAPTCHA solvers | Clearing the occasional slider on a session that is otherwise healthy | They treat the symptom. If the trust score is low, a solved CAPTCHA is followed by a ban |
| A managed bypass API | One call, a predictable monthly number, somebody else tracking the detection changes | Per request cost, and your traffic goes through a third party, which a regulated team should review |
What bypassing DataDome costs here
One successful request is one unit. A DataDome storefront, a PerimeterX ticketing page and an unprotected blog cost the same, and a request that ends in a block costs nothing.
| Plan | Per month | Successful requests | Cost per 1,000 pages |
|---|---|---|---|
| Starter | 49 USD | 50,000 | 0.98 USD |
| Growth | 149 USD | 250,000 | 0.60 USD |
| Scale | 499 USD | 1,500,000 | 0.33 USD |
Credit pricing works the other way. ScraperAPI's published rates, checked on 20 September 2026, add 10 credits for a DataDome or PerimeterX bypass on top of the 1 credit base, and another 10 for JavaScript rendering. On their 49 USD plan of 100,000 credits that is about 5.39 USD per 1,000 protected pages, or 10.29 USD with rendering. The full comparison, including the cases where credits come out cheaper, is in ScraperAPI pricing per 1,000 pages.
What this does not do
Public pages only. The API does not sign in, hold accounts or submit credentials, so it is not a tool for account creation, checkout automation, ticket buying or anything else these vendors exist to stop on logged-in flows. It reads the pages any visitor can open.
Concurrency is capped per plan and requests are paced, since a crawler that loads a site hard gets everyone's access tightened. Where the site offers an official feed or API for the data, that will be cheaper and steadier than scraping. The legal picture for public pages is summarized in is web scraping legal. None of this is legal advice.
DataDome and PerimeterX bypass questions
Can DataDome be bypassed?
Not switched off, but passed, yes. DataDome scores every request and blocks only the ones that look automated, so a request that arrives on a clean residential address, with a real browser fingerprint, runs the JavaScript check and paces itself like a person is served the page. Doing that reliably at volume, week after week, is the hard part, and it is what a managed API takes off your plate.
How does DataDome detect bots?
It combines the TLS fingerprint, header order and HTTP version, the reputation and type of the IP address, a JavaScript check that reads canvas, WebGL, plugins and the webdriver flag, and behavior across the session. The results add up to a trust score for the address and session. That is why a scraper can pass ten pages and get banned on the eleventh without anything changing on your side.
How do I bypass PerimeterX?
PerimeterX, now part of HUMAN Security, checks the address, the TLS and header fingerprints, a client side sensor script and behavior. A request passes when every layer looks like one real visitor. You can build that with a patched browser and bought residential proxies, or send the URL to an API that handles the sensor, the Press and Hold challenge and the retries for you.
What does the PerimeterX Press and Hold challenge mean?
It is the interactive challenge HUMAN shows when a request scores as likely automated, usually with an HTTP 403 and a page reading "Access to this page has been denied." Seeing it means an earlier signal already failed, most often the address or the fingerprint. Automating the button alone rarely keeps a session alive, because the next request carries the same weak signals.
Why do I still get blocked with residential proxies?
Because the address is only one of four layers. If the TLS handshake says Python while the user agent says Chrome, or the browser check never runs, the request fails no matter how clean the IP is. Worse, the failed request lowers that address's reputation. Proxies help once the client itself is convincing, which is covered on the web scraping proxy service page.
Does a DataDome captcha bypass solve the slider?
Here the slider is handled inside the request, and an attempt that does not clear is retried on a new identity at no charge. In practice, most requests never see the slider, because the identity was consistent enough that DataDome served the page directly. A setup that has to solve the slider on every page is a setup the trust score is about to ban.
How much does a DataDome bypass API cost?
Here it is 49 USD a month for 50,000 successful requests, which is 0.98 USD per 1,000 pages, falling to 0.33 USD per 1,000 on Scale. A DataDome or PerimeterX page costs the same as a plain one. Credit based providers usually add a multiplier for protected targets, so compare on dollars per 1,000 pages, not on the plan price.
Send the URL that keeps returning a 403
Create your account, paste the page your scraper has been losing to DataDome or PerimeterX, and see the real page come back.
Related endpoints
- Cloudflare scraping API for sites behind Bot Management and Turnstile
- Akamai bypass API for pages behind Akamai Bot Manager
- Imperva Incapsula bypass API for Imperva and Kasada protected pages
- Web scraping proxy service: rotating residential and datacenter addresses
- Screen scraper API that reads the rendered page
- Datacenter proxies versus residential: which one your crawler needs
- Web scraping API pricing and plans