How to Bypass Cloudflare, Akamai, and PerimeterX When Web Scraping in 2026

How to Bypass Cloudflare, Akamai, and PerimeterX When Web Scraping in 2026

Most guides on how to bypass Cloudflare web scraping give you the same list of tools: Camoufox, Patchright, residential proxies, maybe a CAPTCHA solver. What they don't give you is numbers — which combination actually works, against which WAF, and at what cost.

We ran 500 requests per approach across Cloudflare (standard and Enterprise tiers), Akamai Bot Manager v4, and PerimeterX (now HUMAN Security) in April 2026. This post shares what passed, what failed, and the decision framework we use before choosing a bypass approach on any new target.

The Decision Framework: Identify Your WAF Before You Pick a Tool

The single biggest mistake scrapers make is choosing a bypass tool before identifying the WAF. A technique that gets 91% pass rate on Cloudflare gets 12% on PerimeterX. The detection architectures are fundamentally different.

Use the browser network tab or a WAF fingerprint tool to identify which system you're facing before writing any code:

Signal Likely WAF
cf-ray header, IUAM challenge page, __cf_bm cookie Cloudflare
_abck cookie, sensor_data POST payload, AkamaiGHost header Akamai Bot Manager
_pxhd, _pxvid cookies, /api/v2/collector endpoint PerimeterX / HUMAN
__ddg cookies, behavior-based JS challenge DataDome

Getting this wrong means debugging a failed bypass against the wrong detection model for hours.

If you want a faster read on whether a given target is protected at all, paste its category page into our free product URL extractor. It makes one plain, unrendered request and tells you which of three things happened: the page came back directly, the direct request was refused and it had to retry through a proxy, or the HTML that came back contains almost no links — the signature of a grid that only exists after JavaScript runs. That is the first fork in the table above, answered in a few seconds and without writing any code.

Our Test Setup: 6 Approaches, 3 WAFs, 500 Requests Each

Testing methodology (ScrapeWise internal testing, Apr 2026):

  • 500 requests per approach per WAF, spread over 6 hours with randomized timing
  • Targets: production e-commerce sites protected by each WAF (not sandboxes)
  • "Pass" = 200 OK with full page content, no challenge redirect, no soft-block
  • Residential proxy pool: 2M+ IPs, rotating per request
  • Datacenter proxies: standard shared datacenter pool
Approach Cloudflare Std Cloudflare Enterprise Akamai v4 PerimeterX
Requests library + datacenter proxies 19% 4% 22% 11%
curl-cffi + datacenter proxies 61% 38% 71% 29%
curl-cffi + residential proxies 79% 52% 87% 41%
Patchright + residential proxies 83% 69% 74% 58%
Camoufox + datacenter proxies 72% 44% 68% 51%
Camoufox + residential proxies 91% 78% 83% 67%

A few things are immediately visible: datacenter proxies cap your ceiling on every WAF. Camoufox beats Patchright on Cloudflare specifically because it runs a patched Firefox binary — Cloudflare's fingerprinting treats Firefox TLS signatures differently from Chromium-based tools. Patchright gains back ground on Cloudflare Enterprise relative to the cheaper approaches, but never overtakes Camoufox on any of the three WAFs in this table.

The one genuine reversal is Akamai: curl-cffi at 87% beats both stealth browsers, because TLS fingerprinting is Akamai's primary signal rather than a secondary one.

Nothing breaks 70% on PerimeterX with DIY approaches. That ceiling matters — read the PerimeterX section before assuming more engineering will fix it.

Bypassing Cloudflare in 2026: What the Detection Stack Actually Checks

Cloudflare's bot detection operates across four simultaneous layers. Understanding each explains why some approaches work and others don't.

Layer 1 — IP reputation. Datacenter ASNs are pre-flagged. Even a perfect TLS fingerprint gets a hard challenge if the IP is in a known cloud provider range. This is why the gap between datacenter and residential proxy results is so large. Mobile carrier IPs from Europe's big telecom providers (Telia, Deutsche Telekom, Proximus) have some of the highest trust scores we measured.

Layer 2 — TLS fingerprinting (JA3/JA4). Cloudflare checks the TLS handshake signature before any JavaScript runs. A raw Python requests call produces a Python TLS fingerprint that Cloudflare has flagged globally. curl-cffi fixes this by impersonating Chrome or Safari TLS signatures at the socket level — this alone jumps pass rates from ~19% to ~61% on standard Cloudflare.

Layer 3 — JavaScript challenges (IUAM / Turnstile). Cloudflare injects a JS challenge that checks browser environment signals: canvas fingerprint, WebGL renderer, navigator properties, timing behavior. Headless Chromium fails this by default because it leaks navigator.webdriver = true and produces anomalous canvas fingerprints. Camoufox patches this at the Firefox C++ level, not in JS — which is why it outperforms Patchright's JS-patch approach on Cloudflare Enterprise.

Layer 4 — Behavioral analysis. Request timing, scroll events, mouse movement patterns. This layer is what breaks purely technical approaches on Enterprise-tier targets. Randomizing request intervals (300–2,500ms jitter, not a fixed sleep) improves pass rates by ~8 percentage points on Cloudflare Enterprise in our tests.

Cloudflare Turnstile (CAPTCHA layer): When Cloudflare forces a Turnstile challenge, curl-cffi can't solve it — you need a full browser. We tested 2Captcha and CapSolver for Turnstile solving: 2Captcha averaged 4.2s solve time with 91% success; CapSolver averaged 3.1s with 88% success. Both are viable. Budget ~$1.50–$2.00 per 1,000 Turnstile solves.

What doesn't work: FlareSolverr, the popular open-source Turnstile solver, has an 0% pass rate on Cloudflare Enterprise targets in our Apr 2026 tests. It was already declining in 2025 — it's not a viable production option.

For teams scraping e-commerce sites for competitor price tracking, Cloudflare is the most common protection layer on retailer and brand DTC sites. Getting this layer right has the highest ROI.

Bypassing Akamai Bot Manager v4: The TLS Problem

Full walkthrough: How to bypass Akamai Bot Manager v4 when web scraping covers the five detection layers in priority order, how to confirm you are facing Akamai, and the three changes that moved our pass rates most.

Akamai's detection model is architecturally different from Cloudflare's. The priority ordering is reversed: TLS fingerprinting is Akamai's primary detection signal, not a secondary one. This means curl-cffi alone (without a browser) is more effective against Akamai than against Cloudflare — and explains our 87% pass rate with curl-cffi + residential proxies.

What Akamai actually checks:

Akamai Bot Manager v4 blocks across five layers simultaneously: IP reputation, TLS fingerprinting (JA3/JA4), JavaScript telemetry, behavioral biometrics, and session continuity. The _abck cookie is generated by Akamai's sensor data script — each page load sends an encrypted payload with mouse events, keystroke timing, and device fingerprint data back to Akamai's servers.

The sensor data problem: If you're using a full browser (Camoufox, Patchright), Akamai's JS collects sensor data and validates it server-side. A browser that moves the mouse perfectly linearly or never generates scroll events will fail the behavioral check even with a clean IP and valid TLS fingerprint. We simulated human-like mouse trajectories using cubic bezier curves — this improved Akamai pass rates by ~11 percentage points over straight-line movement.

curl-cffi approach: For Akamai targets that don't require a login session, curl-cffi with impersonated TLS plus residential proxies gets 87% pass rate in our tests and is significantly cheaper to run than browser automation. At scale (10K+ requests/day), the cost difference between curl-cffi and Camoufox instances is approximately 4:1 in compute.

Where Akamai wins: Protected checkout flows and account-authenticated scraping. Akamai's session continuity tracking detects when a "new session" immediately navigates to high-value pages without natural browsing behavior. For these targets, a warm-up sequence (2–3 page loads with random dwell time before hitting the target URL) improves pass rates from 61% to 83% in our tests.

This matters particularly for product data extraction on fashion and electronics retailers — Zara, H&M, MediaMarkt, and Fnac all run Akamai, and authenticated scraping for SKU-level data requires the session continuity bypass.

PerimeterX / HUMAN: Why the 67% Ceiling Is a Hard Wall

Full walkthrough: How to bypass PerimeterX (HUMAN Security) when web scraping covers the four detection layers, the PRESS & HOLD challenge, and what a 67% ceiling actually costs at volume.

PerimeterX — rebranded as HUMAN Security in 2023 but still widely called PerimeterX in the scraping community — is the hardest WAF to bypass reliably in 2026. Our best result, Camoufox + residential proxies, achieved 67% pass rate. That's not a tuning problem. It's architectural.

Why PerimeterX is different: Every PerimeterX deployment is trained on the specific website's historical traffic. The ML model has been fed months of real user behavior data for that specific domain — click patterns, session durations, navigation flows, device distributions. A bypass technique that works against a PerimeterX-protected fashion retailer may have a 30-point lower pass rate on a PerimeterX-protected pharmaceutical site because the behavioral baselines are completely different.

What PerimeterX checks:

  • Browser fingerprint (canvas, WebGL, audio context, fonts)
  • Behavioral signals (mouse trajectory, typing cadence, scroll velocity)
  • Session graph (what pages were visited, in what order, with what dwell times)
  • Network graph (does this IP's behavior across sessions match legitimate users?)

Browser choice is a per-site question here: Camoufox + residential leads our aggregate at 67%, with Patchright + residential at 58% — but the ordering flips on individual domains, which it does not on the other two WAFs. The reason is that PerimeterX's ML is trained predominantly on Chrome traffic from that site's real users. On a target where Chromium dominates the visitor mix, Camoufox's Firefox fingerprint is less common than the baseline and triggers minor statistical anomalies, and Patchright's Chromium base matches the expected distribution better. This is the one WAF where it is worth running both for a week and measuring rather than picking on principle.

Honest ceiling: If you need >85% pass rates on PerimeterX-protected targets, you need a managed solution with large-scale IP rotation, continuously updated fingerprint profiles, and behavioral training data. DIY approaches hit a structural ceiling at ~70%.

For teams that would rather not run and maintain this stealth-tooling comparison themselves, a managed service absorbs the Camoufox/Patchright tuning work and just delivers the pricing data.

The Engineering Overhead Reality

Pass rate is only part of the cost equation. Here's what maintaining each approach at production scale (10K+ pages/day) actually costs in engineering time:

Approach Monthly infra cost (10K/day) Engineering maintenance Failure mode
curl-cffi + residential proxies ~$120–180 3–5 hrs/month TLS fingerprint updates, proxy rotation tuning
Patchright + residential proxies ~$380–520 8–12 hrs/month WAF model updates, fingerprint drift, Chromium updates
Camoufox + residential proxies ~$440–600 10–15 hrs/month Firefox binary updates, memory pressure (200MB+ per instance)
Managed scraping infrastructure Custom pricing ~1 hr/month (config) Handled by provider SLA

The hidden cost is WAF updates. Cloudflare ships model updates every 2–4 weeks. Akamai pushes sensor data script changes roughly monthly. Each update can drop your pass rate by 15–30 points overnight and requires debugging time to recover. Teams running competitor price monitoring at scale often find that the first six months of DIY are manageable, but month 7–12 engineering time exceeds the cost of managed infrastructure.

For teams evaluating the anti-bot landscape more broadly, this maintenance overhead is the most underestimated cost in scraping infrastructure planning.

When to Stop DIY and Use Managed Infrastructure

The break-even point we see most often: when a scraping engineer spends more than 8 hours/month on WAF maintenance, managed infrastructure is cheaper.

Stop maintaining your own bypass stack when:

  • You're hitting PerimeterX at scale. The 67% ceiling means ~1 in 3 requests fails. At 10K requests/day that's 3,000 failures you're either retrying (more cost) or missing (data gaps).
  • You need >90% reliability SLA. Managed providers operate large proxy pools with continuously updated fingerprint profiles that individual teams can't replicate.
  • Your scraping targets are authenticated. Session management across large proxy pools is complex engineering that rarely makes sense to build in-house.
  • Your team is < 5 engineers. The maintenance burden of staying ahead of WAF updates takes a meaningful percentage of a senior engineer's time.

ScrapeWise handles Cloudflare, Akamai, and PerimeterX targets as part of managed scraping infrastructure — with pass rates validated against production targets, not sandboxes. The same stack answers our web scraping API with 36 ready endpoints, which a new account can test on 5 free requests before topping up. If you're spending engineer time on WAF maintenance instead of using the data, it's worth the conversation.

Get a quote from Scrapewise

Paste any URL — ScrapeWise handles the anti-bot

Managed infrastructure that adapts when sites change. No proxies, no code, no per-request fees.

Not ready to sign up? See 12 real Amazon rows, 972 columns →

97% accuracy on Amazon benchmarks · no credit card · book a 15-min call →

FAQ

Frequently asked questions

bypass cloudflare web scraping 2026 - WAF bypass techniques, pass rates, and when to use managed scraping infrastructure

Camoufox combined with rotating residential proxies achieved the highest pass rate in our April 2026 testing: 91% on Cloudflare standard and 78% on Cloudflare Enterprise. Camoufox uses a patched Firefox binary with C++ fingerprint hooks, which produces TLS and browser fingerprints that Cloudflare's detection treats as genuine traffic. Adding randomized request timing (300–2,500ms jitter) improves Enterprise-tier pass rates by approximately 8 additional points.

Akamai treats TLS fingerprinting as its primary detection signal, while Cloudflare prioritizes IP reputation and JavaScript challenge layers. This means curl-cffi (which impersonates browser TLS signatures without running a full browser) is more effective against Akamai than against Cloudflare — achieving 87% pass rate in our tests with residential proxies. Akamai also uses session continuity tracking, so warming up a session with 2–3 natural page loads before hitting target URLs significantly improves pass rates.

PerimeterX (now HUMAN Security) trains a custom ML model for each website it protects, using that site's specific historical user behavior as the baseline. This means a bypass technique that achieves 70% on one PerimeterX-protected site may get 40% on another, because the behavioral models are different. Our best result — Camoufox plus residential proxies — reached only 67% pass rate, which is a structural ceiling for DIY approaches, not a tuning problem.

Yes, when Cloudflare forces a Turnstile challenge, you need a browser automation layer plus a CAPTCHA solving service — curl-cffi alone cannot solve Turnstile. In our April 2026 testing, 2Captcha averaged 4.2 seconds solve time with 91% success rate; CapSolver averaged 3.1 seconds with 88% success. FlareSolverr, a once-popular open-source option, showed 0% pass rate on Cloudflare Enterprise targets in current testing and is not viable for production use.

The break-even point is typically when a scraping engineer spends more than 8 hours per month on WAF maintenance. Cloudflare ships model updates every 2–4 weeks and each update can drop DIY pass rates by 15–30 points overnight. Managed infrastructure makes the most sense when you need over 90% reliability SLA, when you're scraping PerimeterX-protected targets at scale (where DIY approaches hit a structural ceiling around 67%), or when your engineering team is fewer than five people and WAF maintenance competes with core product work.