A web unlocker takes an ordinary HTTP request and replays it from a residential IP under a real browser TLS fingerprint, retries on a fresh IP when the target blocks it and switches to a real browser when a JavaScript challenge appears. QuantumProxies.io offers one as a REST endpoint and as a forward proxy, on one prepaid balance.
The identity headers your client sends (User-Agent, Accept, Sec-Fetch-*) are replaced by a set that matches the TLS handshake. Authorization, cookies, content type and custom headers pass through untouched.
A challenge or refusal triggers a retry on a new residential exit under a different fingerprint family: Chrome, Firefox, Brave. Up to three TLS attempts inside a 90-second budget.
When every TLS attempt is challenged, a headless browser fetches the page and answers the JavaScript challenge. When you pass a sticky session id, the clearance cookie it earns is kept and replayed on your next requests to that site in the same session.
Same engine underneath. Pick the interface your code already speaks.
POST /api/v1/scraper/unlock with your API key. No proxy protocol and no certificate: a normal HTTPS call that returns the target's status, headers, body and a blocked flag.
Point any HTTP client at unlock.quantumproxies.io:9000 with a proxy sub-user from the dashboard. Targeting rides in the username: country, state, city, session, TLS profile and tier.
x-qp-url, x-qp-country, x-qp-session, x-qp-render, x-qp-keep-headers, x-qp-success-status and x-qp-timeout steer a single request. The header spellings of the two most common commercial unlockers are accepted too.
The QuantumProxies.io Web Unlocker is built for the pages a plain HTTP client cannot get: the ones where the anti-bot layer scores the TLS handshake and the HTTP/2 settings before it reads a single header. A fetch or requests call carries its runtime's signature whatever User-Agent it sets. The unlocker fixes that at the transport layer and, unlike the Extract API, hands back the origin's raw response: any method, your own headers and body, a login or a cart held on one exit IP.
A rotating residential proxy changes where a request comes from. It does not change what the request looks like: the TLS handshake, the HTTP/2 frame order and the header set still say Python or Node, and modern bot walls score exactly that. A web unlocker rewrites the request into one a real browser would send, retries under a different fingerprint when the origin refuses it, and switches to a real browser when the origin demands JavaScript. You keep the proxy interface; the unlocker adds the judgement.
Every attempt leaves under one of six browser profiles: Chrome, Firefox, Safari, Safari iOS, Edge or Brave, plus a mobile Safari option on the REST endpoint. When you pin none, retries rotate the family, so a site that has burned one handshake meets another. The identity headers are rewritten to match the profile, because a Chrome handshake carrying a Firefox User-Agent is a louder signal than either alone. Authorization, Cookie, Content-Type and custom X-* headers are forwarded verbatim, and keepHeaders sends yours as-is when you replay a captured app request.
A blocked GET is retried on a new residential exit with a rotated fingerprint, up to three TLS attempts within a 90-second budget. If every attempt comes back challenged, the request escalates to a headless browser that answers the JavaScript challenge and returns the rendered page. POST, PUT and DELETE never retry on an HTTP response: a 403 means the origin saw the request, and replaying it could double-submit an order or a form. Set render to html or png to start in the browser, or render to false to stay on the TLS tier.
Every response is classified before it reaches you. The classifier reads the headers and body that bot-defence vendors sign their pages with and names both the vendor (cloudflare, datadome, akamai and others) and the class of block: js_challenge, captcha, ip_reputation, fingerprint, geo or timeout. On the REST endpoint a still-blocked page arrives with blocked set to true and the page itself for inspection. On the forward proxy a challenge served with a 2xx becomes a 502 with the x-qp-unlocker-blocked header, while a genuine origin refusal (403, 429, 503) is relayed intact. Interactive captchas are not solved: they come back labelled captcha.
Pass a country, and optionally a state or city, to exit from that market. Leave it empty and the exit country is chosen from the target's top-level domain, with the United States as the fallback. A sticky session id keeps one exit IP across calls for 3 to 1,440 minutes, so a login, a cart or a paginated listing stays on one identity. The unlocker also remembers, per domain, which tier and fingerprint family passed recently and starts there next time, and it quarantines an exit a site has just refused instead of offering it to that site again.
The Web Unlocker runs on two exit pools: Premium on residential IPs and Mobile on 4G/5G carrier IPs, each with its own prepaid GB balance bought from the dashboard. Usage is measured in bytes moved, including retries and browser renders, and when a balance runs out the proxy answers 402 instead of failing silently. The price per GB of each tier is shown on the Web Unlocker page of the dashboard, next to the buy button. There is no subscription and no minimum term.
The forward proxy accepts the control-header spellings of the two most common commercial unlockers alongside its own x-qp-* headers, so an integration usually migrates by changing the proxy host and the credentials and nothing else. Proxy mode carries targeting in the username the way the residential proxies already do: country, state, city, session, profile and tier. HTTPS through the proxy needs the interception certificate, downloadable from the API with your key. Direct mode with x-qp-url and the REST endpoint need no certificate at all.
Use the Extract API when you want a page as Markdown, HTML or structured JSON and do not care how it was fetched. Use the Web Unlocker when you need the origin's raw response: a JSON API behind a bot wall, a POST that submits a form, a request with your own authorization header, a cookie jar you manage yourself, or an existing scraper that already speaks proxy protocol. Both live on the same account and the same residential network; only the unlocker bills from its own prepaid GB balance.
A web unlocker is a service that takes a normal HTTP request and delivers it to a bot-protected site as a real browser would: from a residential IP, with a browser TLS fingerprint and matching headers, retrying on a fresh IP when blocked and using a real browser for JavaScript challenges. It returns the origin's raw response.
A proxy only changes the source IP. Your client's TLS handshake and header set still reveal an automated tool, and that is what modern bot walls score. The unlocker rewrites the request to match a browser, retries under another fingerprint when refused and escalates to a browser when JavaScript is demanded.
It answers JavaScript challenges with a real browser and, inside a sticky session, keeps the clearance cookie for later requests to the same site. Interactive captchas that require a human are not solved: the response comes back labelled captcha, with the vendor named, so your code can decide what to do next.
Yes. Any HTTP method is forwarded with your body, in text or base64. Authorization, Cookie, Content-Type and custom X-* headers pass through verbatim; only the identity headers are rewritten. A POST is attempted exactly once, because replaying it after a response could double-submit a form or an order.
Per GB, from a prepaid balance you buy in the dashboard for the tier you use: Premium on residential exits or Mobile on carrier exits. All bytes moved count, retries and browser renders included. When the balance is exhausted the proxy answers 402. The current price per GB is shown in the dashboard.
It is never returned as a silent success. The REST endpoint sets blocked to true and includes the block class and vendor next to the page. The forward proxy turns a challenge served with a 2xx into a 502 with an x-qp-unlocker-blocked header, and relays a real 403, 429 or 503 from the origin unchanged.
Yes. Pass a session id, in the request body or in the proxy username, and every call with that id leaves from the same exit IP for 3 to 1,440 minutes. That is how a login, a shopping cart or a paginated listing stays on one identity instead of changing IP on every page.
Only for HTTPS through the classic forward proxy, which terminates TLS to rewrite the request; the interception certificate is downloaded from the API with your key. Direct mode, where the target goes in the x-qp-url header, and the REST endpoint need no certificate at all.
The Premium tier uses the same residential network as the Residential Premium proxies, with country, state and city targeting across 200+ countries. The Mobile tier uses 4G/5G carrier IPs. When you set no country, the exit is chosen from the target's top-level domain, with the United States as the fallback.
Skip the marketing. QuantumProxies.io publishes a machine-readable site map, Markdown for every page, a free MCP server, and APIs billed from the same balance as your proxies.
Connect in one command: npx -y quantumproxies-mcp