Skip to content
Guides

Proxies for AI Agents: Sessions, Sizing and What Gets Browsing Agents Blocked

An AI agent that browses the web inherits every problem a scraper has, plus some of its own: it keeps state across many steps, loads full pages in a real browser, and often acts inside logged-in accounts. That makes session design more important than pool size. The working pattern is one sticky residential or ISP identity per task, held for the whole task, released when it ends — and never used for the agent's calls to its own model API, which are limited by key rather than by IP.

seamless Team12 min readSeptember 28, 2026
  • ai agents
  • browser automation
  • sticky sessions
  • residential proxies
A faceted core hovering above the grid with thin lines anchored to separate page panels, one line and its panel held in crimson
51%
of all web traffic was automated in 2024 (Imperva)
37%
of traffic classified as bad bots — the population agents get compared to
~2.5 MB
median page weight a real browser downloads (HTTP Archive)

Automated traffic now outweighs human traffic, and bot defences have scaled to match. An agent built on Playwright or a browser-use framework shows up in that picture looking a lot like the automation sites are trying to stop, which is why the first run usually works and the fiftieth does not.

Why agents get blocked differently from scrapers

BehaviourScraperAgentWhat it means for the proxy
StateMostly stateless fetchesCookies, logins, multi-step flowsNeeds a sticky exit per task
PaceFast and regularSlow and bursty — waits on the modelLong sessions; set TTLs generously
ClientOften plain HTTPFull headless browserHeavier bandwidth per page
TargetsOne site, many pagesMany sites, few pages eachBroad, clean pool; country targeting
Failure costRetry the URLRestart the whole taskReliability beats raw price

The last row is the one people underestimate. A scraper that hits a block loses one request. An agent that hits a block on step nine of twelve loses the whole task and the model tokens spent getting there, so the proxy's job is less about volume and more about not failing mid-flow.

Which proxy type fits which agent

Agent jobProxy typeSession
Research and browsing across many public sitesRotating residentialSticky per task, 10–30 minutes
Acting inside a logged-in accountISP proxyStatic — the same IP every time for that account
Social platforms and app-first servicesMobileSticky per task
Tolerant sites, docs, internal toolsDatacenterAny
Checking what users in a region seeGeo-targeted residentialSticky, country or city set per task

Many large sites now block known hosting ranges for anything that looks automated, and Cloudflare offers site owners a switch to block AI crawlers outright. Datacenter exits are still the cheapest option — test them first — but expect to need residential for the broad web.

Session design: one task, one identity

Anti-bot systems correlate the IP with the cookie jar, the TLS fingerprint and the browser profile. Keeping those four aligned is what makes a session look like one person. The simplest way to guarantee it is to create all of them together when a task starts and throw them away together when it ends.

python
import uuid
from playwright.async_api import async_playwright

async def run_task(task):
    session = uuid.uuid4().hex[:10]
    proxy = {
        "server": "http://PROXY_HOST:PROXY_PORT",
        "username": f"USERNAME-country-{task.country}-session-{session}",
        "password": "PASSWORD",
    }
    async with async_playwright() as p:
        browser = await p.chromium.launch()
        context = await browser.new_context(proxy=proxy, locale=task.locale)
        page = await context.new_page()
        try:
            return await task.agent.run(page)   # every step reuses this exit
        finally:
            await context.close()               # identity ends with the task
            await browser.close()
The session tag pins the exit; the context holds the cookies. Both live and die with the task.
  • Match locale and timezone to the exit country. A German IP with an en-US browser in a Pacific timezone is an easy inconsistency to catch.
  • Set the sticky TTL longer than your slowest task. Agents pause for the model; an exit that rotates during a pause breaks the flow.
  • On failure, rotate the whole identity — new session tag, new context — rather than retrying the same step on a new IP with old cookies.
  • Never share one identity across concurrent tasks. Two agents interleaving on one IP look like one very erratic user.

The mechanics of sticky versus rotating exits are in rotating vs sticky sessions, and the Playwright specifics in Playwright proxies.

Sticky sessions set in the username

Residential from €1.20/GB with country targeting and sticky sessions; the Omni plan adds city and ASN targeting and custom session TTL. Data never expires.

See residential proxies

What not to route through the proxy

The agent's calls to its model endpoint — OpenAI, Anthropic, Google or a self-hosted model — should go direct. Those APIs rate-limit by key and account, not by address, so rotating IPs does nothing for a 429 from the model, and routing that traffic through a residential proxy only spends bandwidth and adds latency to every step. Proxy the browser; leave the model client alone.

Sizing bandwidth for agents

Agents run real browsers, so they pay for everything a page loads. The median page is around 2.5 MB, and most of that is images, video and fonts the model never reads. Blocking those types is the largest cost lever available.

python
BLOCK = {"image", "media", "font"}

async def slim(route):
    if route.request.resource_type in BLOCK:
        await route.abort()
    else:
        await route.continue_()

await context.route("**/*", slim)
Keep images if the agent uses screenshots for vision; block them if it reads the DOM or accessibility tree.
WorkloadPages per taskPer pagePer 1,000 tasksCost at €1.20/GB
Research agent, assets blocked15~0.6 MB~9 GB~€11
Research agent, full pages15~2.5 MB~37 GB~€45
Shopping or booking flow, screenshots25~3 MB~75 GB~€90

These are planning figures, not guarantees — measure a hundred real tasks and scale from that. The general method is in how many proxies do I need.

Being a good citizen, and staying unblocked

The web is moving toward identifying agents rather than guessing at them. Site owners can now block or charge AI crawlers at the edge, and proposals such as Web Bot Auth let well-behaved agents sign their requests so sites can recognise them. Whatever the mechanism, the practices that keep an agent welcome are the same ones that keep it unblocked:

  • Respect robots.txt and terms of service for the sites your agent visits, and stay away from anything behind a login you are not authorised to use.
  • Pace like a person. One agent per identity, human-scale delays, no parallel hammering of one domain.
  • Prefer official APIs where they exist; they are faster, cheaper and stable across redesigns.
  • Keep personal data out of scope unless you have a lawful basis to process it. See are proxies legal for the wider picture.

When the agent gets blocked anyway

Treat the response code as a diagnosis, not a retry signal. A 403 or Cloudflare 1020 means a rule matched something about the identity — change the whole identity, not just the IP. A 429 or 1015 means the agent is too fast for that site; slow it down. A CAPTCHA mid-flow usually means the session changed underneath the agent, which points back at session design.

Sources

Frequently asked questions

Do AI agents need proxies?

Agents that browse the open web at any volume usually do. Running every task from one server IP quickly trips rate limits and hosting-range blocks. Agents that only call APIs or visit a handful of tolerant sites may not need one.

Which proxy type is best for AI browsing agents?

Rotating residential proxies with sticky sessions fit general browsing across many sites. ISP proxies suit agents that act inside a specific logged-in account, because the account keeps the same IP. Datacenter proxies are fine for tolerant targets and are much cheaper.

Should an AI agent rotate its IP on every request?

No. Agents perform multi-step flows with cookies and logins, and an IP change mid-flow looks like session hijacking. Keep one sticky exit for the whole task and rotate the complete identity — IP, cookies and browser context — between tasks.

Will a proxy fix rate limits from the OpenAI or Anthropic API?

No. Model APIs limit requests per API key and organisation, not per IP address. Route model calls directly and only send the agent's website traffic through the proxy.

How much bandwidth does an AI agent use?

A real browser downloads around 2.5 MB for a median page. A research task visiting 15 pages uses roughly 37 MB with full pages, or about a quarter of that with images, media and fonts blocked. Measure your own tasks and scale from there.

Is it legal to use proxies for AI agents?

Using a proxy is legal in most jurisdictions. What the agent does still has to comply with each site's terms, copyright and data-protection law, and it must not access accounts or areas it is not authorised to use.

SE
seamless Team
Proxy infrastructure

The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.

Ready to try seamless proxies?

Residential, ISP and datacenter proxies with no data expiry.

Browse Plans