Proxies for AI Agents: Sessions, Sizing and What Gets Browsing Agents Blocked
An AI agent that browses the web inherits every problem a scraper has, plus some of its own: it keeps state across many steps, loads full pages in a real browser, and often acts inside logged-in accounts. That makes session design more important than pool size. The working pattern is one sticky residential or ISP identity per task, held for the whole task, released when it ends — and never used for the agent's calls to its own model API, which are limited by key rather than by IP.
- ai agents
- browser automation
- sticky sessions
- residential proxies

Table of contents
Automated traffic now outweighs human traffic, and bot defences have scaled to match. An agent built on Playwright or a browser-use framework shows up in that picture looking a lot like the automation sites are trying to stop, which is why the first run usually works and the fiftieth does not.
Why agents get blocked differently from scrapers
| Behaviour | Scraper | Agent | What it means for the proxy |
|---|---|---|---|
| State | Mostly stateless fetches | Cookies, logins, multi-step flows | Needs a sticky exit per task |
| Pace | Fast and regular | Slow and bursty — waits on the model | Long sessions; set TTLs generously |
| Client | Often plain HTTP | Full headless browser | Heavier bandwidth per page |
| Targets | One site, many pages | Many sites, few pages each | Broad, clean pool; country targeting |
| Failure cost | Retry the URL | Restart the whole task | Reliability beats raw price |
The last row is the one people underestimate. A scraper that hits a block loses one request. An agent that hits a block on step nine of twelve loses the whole task and the model tokens spent getting there, so the proxy's job is less about volume and more about not failing mid-flow.
Which proxy type fits which agent
| Agent job | Proxy type | Session |
|---|---|---|
| Research and browsing across many public sites | Rotating residential | Sticky per task, 10–30 minutes |
| Acting inside a logged-in account | ISP proxy | Static — the same IP every time for that account |
| Social platforms and app-first services | Mobile | Sticky per task |
| Tolerant sites, docs, internal tools | Datacenter | Any |
| Checking what users in a region see | Geo-targeted residential | Sticky, country or city set per task |
Many large sites now block known hosting ranges for anything that looks automated, and Cloudflare offers site owners a switch to block AI crawlers outright. Datacenter exits are still the cheapest option — test them first — but expect to need residential for the broad web.
Session design: one task, one identity
Anti-bot systems correlate the IP with the cookie jar, the TLS fingerprint and the browser profile. Keeping those four aligned is what makes a session look like one person. The simplest way to guarantee it is to create all of them together when a task starts and throw them away together when it ends.
import uuid
from playwright.async_api import async_playwright
async def run_task(task):
session = uuid.uuid4().hex[:10]
proxy = {
"server": "http://PROXY_HOST:PROXY_PORT",
"username": f"USERNAME-country-{task.country}-session-{session}",
"password": "PASSWORD",
}
async with async_playwright() as p:
browser = await p.chromium.launch()
context = await browser.new_context(proxy=proxy, locale=task.locale)
page = await context.new_page()
try:
return await task.agent.run(page) # every step reuses this exit
finally:
await context.close() # identity ends with the task
await browser.close()- Match locale and timezone to the exit country. A German IP with an
en-USbrowser in a Pacific timezone is an easy inconsistency to catch. - Set the sticky TTL longer than your slowest task. Agents pause for the model; an exit that rotates during a pause breaks the flow.
- On failure, rotate the whole identity — new session tag, new context — rather than retrying the same step on a new IP with old cookies.
- Never share one identity across concurrent tasks. Two agents interleaving on one IP look like one very erratic user.
The mechanics of sticky versus rotating exits are in rotating vs sticky sessions, and the Playwright specifics in Playwright proxies.
Sticky sessions set in the username
Residential from €1.20/GB with country targeting and sticky sessions; the Omni plan adds city and ASN targeting and custom session TTL. Data never expires.
What not to route through the proxy
The agent's calls to its model endpoint — OpenAI, Anthropic, Google or a self-hosted model — should go direct. Those APIs rate-limit by key and account, not by address, so rotating IPs does nothing for a 429 from the model, and routing that traffic through a residential proxy only spends bandwidth and adds latency to every step. Proxy the browser; leave the model client alone.
Sizing bandwidth for agents
Agents run real browsers, so they pay for everything a page loads. The median page is around 2.5 MB, and most of that is images, video and fonts the model never reads. Blocking those types is the largest cost lever available.
BLOCK = {"image", "media", "font"}
async def slim(route):
if route.request.resource_type in BLOCK:
await route.abort()
else:
await route.continue_()
await context.route("**/*", slim)| Workload | Pages per task | Per page | Per 1,000 tasks | Cost at €1.20/GB |
|---|---|---|---|---|
| Research agent, assets blocked | 15 | ~0.6 MB | ~9 GB | ~€11 |
| Research agent, full pages | 15 | ~2.5 MB | ~37 GB | ~€45 |
| Shopping or booking flow, screenshots | 25 | ~3 MB | ~75 GB | ~€90 |
These are planning figures, not guarantees — measure a hundred real tasks and scale from that. The general method is in how many proxies do I need.
Being a good citizen, and staying unblocked
The web is moving toward identifying agents rather than guessing at them. Site owners can now block or charge AI crawlers at the edge, and proposals such as Web Bot Auth let well-behaved agents sign their requests so sites can recognise them. Whatever the mechanism, the practices that keep an agent welcome are the same ones that keep it unblocked:
- Respect robots.txt and terms of service for the sites your agent visits, and stay away from anything behind a login you are not authorised to use.
- Pace like a person. One agent per identity, human-scale delays, no parallel hammering of one domain.
- Prefer official APIs where they exist; they are faster, cheaper and stable across redesigns.
- Keep personal data out of scope unless you have a lawful basis to process it. See are proxies legal for the wider picture.
When the agent gets blocked anyway
Treat the response code as a diagnosis, not a retry signal. A 403 or Cloudflare 1020 means a rule matched something about the identity — change the whole identity, not just the IP. A 429 or 1015 means the agent is too fast for that site; slow it down. A CAPTCHA mid-flow usually means the session changed underneath the agent, which points back at session design.
Sources
Frequently asked questions
Do AI agents need proxies?
Agents that browse the open web at any volume usually do. Running every task from one server IP quickly trips rate limits and hosting-range blocks. Agents that only call APIs or visit a handful of tolerant sites may not need one.
Which proxy type is best for AI browsing agents?
Rotating residential proxies with sticky sessions fit general browsing across many sites. ISP proxies suit agents that act inside a specific logged-in account, because the account keeps the same IP. Datacenter proxies are fine for tolerant targets and are much cheaper.
Should an AI agent rotate its IP on every request?
No. Agents perform multi-step flows with cookies and logins, and an IP change mid-flow looks like session hijacking. Keep one sticky exit for the whole task and rotate the complete identity — IP, cookies and browser context — between tasks.
Will a proxy fix rate limits from the OpenAI or Anthropic API?
No. Model APIs limit requests per API key and organisation, not per IP address. Route model calls directly and only send the agent's website traffic through the proxy.
How much bandwidth does an AI agent use?
A real browser downloads around 2.5 MB for a median page. A research task visiting 15 pages uses roughly 37 MB with full pages, or about a quarter of that with images, media and fonts blocked. Measure your own tasks and scale from there.
Is it legal to use proxies for AI agents?
Using a proxy is legal in most jurisdictions. What the agent does still has to comply with each site's terms, copyright and data-protection law, and it must not access accounts or areas it is not authorised to use.
The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.
Ready to try seamless proxies?
Residential, ISP and datacenter proxies with no data expiry.
Browse PlansKeep reading
Rotating vs Sticky Proxy Sessions Explained
When to rotate IPs on every request and when to hold one — with a decision rule, session-length guidance and the bugs each choice causes.
AutomationPlaywright Proxies: Authentication, Per-Context Rotation and Real Geo Testing
One browser, many identities: set the proxy per context, keep locale and timezone honest, and stop leaking the fact that your headless Chrome is headless.
GuidesHow to Avoid Getting Blocked When Web Scraping
The six layers a modern anti-bot system checks, in the order it checks them — and what to change at each one to stay unblocked.
