AI News
05 Oct 2026
Read 9 min
How to fix 403 Forbidden error when web scraping instantly
how to fix 403 Forbidden error when web scraping to restore access using header rotation and retries.
How to fix 403 Forbidden error when web scraping
Step 1: Confirm the cause fast
- Open the URL in a normal browser. If it loads there, your script looks suspicious.
- Compare the browser’s request headers with your script. Note User-Agent, Accept, Accept-Language, Referer, and cookies.
- Check if only certain paths (like /api or /cart) fail. Those often need auth, CSRF, or special headers.
- Look for geo blocks. Try a proxy from the site’s main country.
Step 2: Imitate a real browser
- Set a modern User-Agent string (Chrome, Edge, or Firefox). Avoid default library IDs.
- Send common headers: Accept, Accept-Language, Referer, Accept-Encoding, and Connection.
- Keep a cookie jar. Reuse cookies across requests so your session persists.
- Use HTTPS and HTTP/2 if the site does. Match TLS where possible by using a headless browser or a HTTP client that supports modern fingerprints.
Step 3: Control speed and patterns
- Slow down. Add small random delays (e.g., 500–1500 ms) between requests.
- Cap concurrency. Start with 1–3 parallel requests, then raise gently.
- Follow crawl-delay hints if listed. Avoid hammering single endpoints.
- Cache and deduplicate. Do not fetch the same page again and again.
Step 4: Manage IP and location
- Rotate IPs if your volume is high. Use a reputable proxy pool.
- Use sticky sessions for login flows so the same IP keeps the same cookies.
- Prefer residential or mobile proxies for tough sites. Many datacenter IPs are flagged.
- Match the site’s target region. Some content needs a local IP.
Step 5: Handle authentication and CSRF
- Log in with a real session when needed. Save the cookies and reuse them.
- Scrape the page to extract CSRF tokens, then include them in POSTs.
- Send Origin and Referer headers if the site checks them.
- Use the correct HTTP method. Some endpoints block GET and allow POST only, or vice versa.
Step 6: Beat simple bot checks
- Avoid repeating the same header order or exact timing. Randomize slightly.
- Rotate between a few realistic User-Agents, not hundreds.
- Load critical resources (like CSS or a key API) in the same pattern a browser would, if the site expects it.
- If JavaScript must run to build tokens, switch to a headless browser (Playwright/Puppeteer) with stealth settings.
Step 7: Respect site rules
- Read robots.txt and the site’s terms. Do not scrape disallowed or sensitive parts.
- Throttle during busy hours. Avoid actions that look like attacks.
- Identify yourself in a polite User-Agent if allowed, and provide contact info.
Instant checklist: quick wins before you dig deeper
- Copy your browser’s headers (User-Agent, Accept, Accept-Language, Referer) into your script.
- Save and send cookies from a real session.
- Add 1-second random delay; limit to 2–3 concurrent requests.
- Switch to a residential proxy in the target country.
- Include CSRF, Origin, and Referer for forms and APIs.
- Try a headless browser for pages that build tokens with JavaScript.
Common 403 patterns and fast fixes
403 only on API endpoints
- Likely needs auth, CSRF, or custom headers (Origin, Referer).
- Fix: Visit the page first, copy auth headers and CSRF, then call the API with the same session.
403 after a few minutes of scraping
- Likely rate or behavior based.
- Fix: Slow down, add jitter, rotate IPs, and reuse cookies across requests.
403 on first request from a new IP
- Likely IP reputation or geo restriction.
- Fix: Use a residential proxy from the right country; warm the IP with a few light page views.
403 only with libraries but not a browser
- Likely header or TLS fingerprint mismatch.
- Fix: Use a browser engine (Playwright/Puppeteer) or a client that mimics modern TLS and header order.
Tools that make this easier
- Headless browsers: Playwright or Puppeteer with stealth plugins to pass simple bot checks.
- Session managers: Keep cookies and local storage between runs.
- Proxy managers: Rotate IPs, pick sticky sessions, and target regions.
- Traffic shapers: Implement rate limits and randomized delays.
For more news: Click Here
FAQ
Contents