Web Unlocker · residential exits · forward proxy and REST
A residential web unlocker sends your request from a residential IP under a real browser TLS fingerprint, retries on a fresh exit when the site refuses it, and opens the page in a real browser when a JavaScript challenge appears. Use it when plain residential proxies still return 403, a security check or "Just a moment".
# forward proxy: any HTTP client, one flag
curl -k \
-x http://unlock.quantumproxies.io:9000 \
-U "unlock-XXXX-country-us:PASSWORD" \
-H "x-qp-session: job42" \
https://www.glassdoor.com/Reviews/Google-Reviews-E9079.htm
# the answer tells you what happened
x-qp-unlocker-attempts: 2
x-qp-unlocker-rendered: 1
x-qp-clearance: minted

A residential proxy changes only the IP address. Modern anti-bot systems also read the TLS handshake of your client and run JavaScript before they serve the page, so a Python or Node.js client on a clean residential IP can still be refused. The residential unlocker keeps the residential IP and fixes the other two layers.
Each request goes out under one of six real browser TLS fingerprints. If the site refuses it, the unlocker retries on a fresh residential exit with another fingerprint, up to three TLS attempts. When the answer is a JavaScript challenge, the same request is replayed in a real headless browser, and the page it gets is checked again before it reaches you.
On 29 September 2026 we fetched the same pages three ways from a US exit: a plain request from a cloud server, a plain request through a residential proxy, and a request through the residential unlocker. The table below lists what each client received. Glassdoor and Indeed refused both plain clients with a security check, and the unlocker returned the real page: Indeed on the first TLS attempt, Glassdoor after switching to the browser.
The same test shows the other side, which saves you money: Zillow and Leboncoin refused the cloud server but served a plain residential proxy, and static sites such as books.toscrape.com served everything. Try a plain request first, and send only the refused ones through the unlocker.
When a page is still a challenge after every attempt, the forward proxy answers with an error status and the header x-qp-unlocker-blocked, and names the reason in x-qp-block-class: js_challenge, captcha, ip_reputation, fingerprint, geo or timeout. The REST endpoint returns the same verdict in JSON, or a 502 when you set failOnBlock.
That matters more than it sounds. A scraper that stores a challenge page as data poisons the dataset for days before anyone notices. Here a refusal is an error your code can count, retry later or route to another tier.
Pin a session with the x-qp-session header to keep one residential exit for 3 to 1440 minutes. When the browser has to clear a challenge, the clearance cookies it earned are kept for that session and reused on the next request to the same site, so the browser does not start again on every page.
Use a new session value per job or per logical user. Reusing one session across unrelated targets gains nothing and concentrates your traffic on one IP.
The forward proxy at unlock.quantumproxies.io:9000 works with any client that accepts an HTTP proxy: curl, Python requests, Node.js, Scrapy or Playwright. HTTPS is re-encrypted by the unlocker, so either install the unlocker CA from the dashboard or disable certificate verification for that client. Targeting goes in the username, for example -country-us.
The REST endpoint POST /api/v1/scraper/unlock takes the request as JSON (url, method, headers, body, country, sessionId) with your API key and returns status, headers, body and the unlocker verdict. It is the simpler option for serverless functions and for AI agents.
The unlocker does not solve interactive captchas: sliders, press-and-hold buttons or image grids. When a site answers with one, the request is reported with block class captcha instead of being retried forever. It also does not log in for you or bypass paywalls; pass your own cookies or headers when you are entitled to the content.
Some sites also refuse residential ranges outright and come back as ip_reputation. For those, the Mobile Web Unlocker sends the same request from 4G/5G carrier IPs.
| Page | Cloud server, plain request | Residential proxy, plain request | Residential Web Unlocker |
|---|---|---|---|
| Glassdoor company reviews | 403, captcha page | 403, "Enable JavaScript and cookies" | 200, real page (browser, 17.2 s) |
| Indeed job search | 403, captcha page | 403, security check | 200, real page (2.6 s) |
| Walmart search | 307 redirect | 307 redirect | 200, real page (4.8 s) |
| Best Buy laptops | no response | no response | 200, real page (6.3 s) |
| Zillow city listings | 403, PerimeterX | 200, real page | 200, real page (2.7 s) |
| Leboncoin search | 403, captcha page | 200, real page | 200, real page (1.4 s) |
| books.toscrape.com | 200 | 200 | 200 |

Start with plain residential proxies and measure. If most pages come back normally, you do not need an unlocker. Use the residential unlocker for the sites that still answer with 403, a security check or a JavaScript challenge; in our 29 September test that was Glassdoor, Indeed, Walmart and Best Buy.
Cloud servers use datacenter IP ranges that anti-bot systems score as automated, while your home connection is a residential IP. In our test Zillow and Leboncoin refused a cloud server and served the same request through a residential proxy. If a residential IP is still refused, the TLS fingerprint or a JavaScript challenge is the next layer.
No. It gets past JavaScript challenges by running a real browser, and past fingerprint and IP checks by rotating fingerprints and exits, but it does not solve interactive captchas such as sliders or press-and-hold. Those requests are reported with block class captcha.
Yes. Send the same x-qp-session value on each request and the unlocker keeps one residential exit for that session, from 3 to 1440 minutes. Browser clearance cookies earned in that session are reused on the next request to the same site.
Yes, with your own headers and body, through the forward proxy or the REST endpoint. A POST is sent exactly once: the unlocker never retries non-GET methods, because a response means the target already received the request.
Every new account can claim a free residential proxy trial to test plain residential access first. Unlocker GB are prepaid per tier in the dashboard, where the live price per GB is shown before you buy.
When a site refuses residential ranges and the unlocker reports ip_reputation. The Mobile Web Unlocker sends the same request from 4G/5G carrier IPs shared by many real phones. It is slower and costs more per GB, so keep residential as the default.
Skip the marketing. QuantumProxies.io publishes a machine-readable site map, Markdown for every page, a free MCP server, and APIs billed from the same balance as your proxies.
Connect in one command: npx -y quantumproxies-mcp