You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python请求网站遭遇Cloudflare 403错误的解决咨询

如何绕过Cloudflare保护机制以成功请求目标API(返回403错误)

我正在开发一款网站自动兑码工具,但每次向目标网站发送请求时都会返回403错误,确认是Cloudflare的特殊验证导致无法绕过。我已配置正确的认证请求头与Cookie,尝试过Requests库、cloudscraper及Beautiful Soup 4,但问题仍存在。

以下是测试代码:

from bs4 import BeautifulSoup
import cloudscraper
headers = {
    'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 Safari/537.36'
}
scraper = cloudscraper.create_scraper()
r = scraper.get('https://rblxwild.com/api/promo-code/redeem-code', headers=headers)
print(r) # 输出为403

可行的解决方案

1. 使用undetected-chromedriver模拟真实浏览器

cloudscraper对新版Cloudflare验证的适配可能滞后,undetected-chromedriver会修改Chrome浏览器的指纹特征,规避Cloudflare的检测,更接近真实用户的访问行为。

示例代码:

from undetected_chromedriver import Chrome, ChromeOptions
import time

options = ChromeOptions()
options.add_argument('--headless=new') # 无头模式,若需要可视化可去掉
driver = Chrome(options=options)

# 先访问网站首页,完成Cloudflare验证
driver.get('https://rblxwild.com/')
time.sleep(5) # 等待验证完成,时间可根据实际调整

# 再请求目标API端点
driver.get('https://rblxwild.com/api/promo-code/redeem-code')
print(driver.status_code) # 查看状态码
driver.quit()

2. 模拟完整会话流程

不要直接请求API端点,先完成网站首页的Cloudflare验证流程,再复用会话中的Cookie和请求头访问API。Cloudflare会验证会话的连贯性,直接请求API会被判定为异常请求。

步骤:

  • 先用浏览器或自动化工具访问网站首页,等待Cloudflare验证通过
  • 从会话中提取所有Cookie和请求头(包括CF_Authorization等Cloudflare生成的关键Cookie)
  • 携带这些Cookie和请求头去请求API端点

3. 补充完整真实的请求头

仅设置User-Agent不足以通过验证,需要复制真实浏览器请求的所有关键头,比如Accept、Accept-Language、Referer、Origin、Sec-Fetch-*等。可通过浏览器开发者工具(F12 -> 网络 -> 复制请求头)获取完整内容。

调整后的请求头示例:

headers = {
    'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36',
    'Accept': 'application/json, text/plain, */*',
    'Accept-Language': 'zh-CN,zh;q=0.9',
    'Referer': 'https://rblxwild.com/',
    'Origin': 'https://rblxwild.com',
    'Sec-Fetch-Dest': 'empty',
    'Sec-Fetch-Mode': 'cors',
    'Sec-Fetch-Site': 'same-origin'
}

4. 控制请求频率与使用代理

Cloudflare会根据IP的请求频率触发风控,需:

  • 添加随机延迟(比如每次请求间隔2-5秒),避免连续请求
  • 若频繁请求,使用代理IP轮换,避免单一IP被封禁

内容的提问来源于stack exchange,提问作者SK3

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 15:10:27