Sticky or Rotating: What Actually Changes in Your Request?
The rotating proxy vs sticky choice comes down to one variable: how long a single exit IP stays attached to your session. Sticky pins one address for a set window, usually 10 to 30 minutes, so a login, a cart and a checkout all look like one visitor. Rotating hands each request or timer tick a new address, which spreads load across the pool. Most providers sell both as session modes on the same residential plan, so you change a credential rather than a subscription.
📌 TL;DR Executive Summary
- Core Takeaway: Sticky and rotating are session modes, not separate products. Sticky holds one exit IP for a window — 10 to 30 minutes is the common default — while rotating issues a new IP per request or timer tick. One residential plan usually covers both.
- Key Risk/Challenge: Random rotation from a pool concentrated in a few subnets still looks correlated, and a sticky session that outlives its task invites re-authentication flags. Neither mode fixes a browser fingerprint that contradicts the IP.
- Recommended Solution: Rotate for discovery and bulk reads, run two-to-five-request sticky bursts for logged-in flows, cap requests per IP and per subnet, and quarantine blocked addresses instead of retrying them.
What a Sticky Proxy Session Really Is
A sticky proxy assigns you one IP address and keeps it for a defined session length. Every request sent with the same session identifier exits through that address. In a checkout flow, the site sees one visitor moving through three pages instead of three visitors sharing one cart.
How the session token works
Most residential gateways encode the session in the proxy username, so credentials look like user-session-abc123. Change that token and the next connection leaves through a different IP. Because the control lives in a string, you can give each worker thread its own identity without touching gateway configuration.
That design explains why providers rarely sell separate “sticky plans” — the mode is a parameter. Some vendors do market a “rotating proxy plan” as a product name, so read the terms before assuming you can switch modes on the same credentials.
How long a sticky IP can actually hold
The practical default is 10 to 30 minutes, which covers logins, carts, checkouts and deep pagination. Published ceilings stretch further: Oxylabs documents up to 24 hours, IPRoyal claims up to 7 days, and Decodo advertises anything from minutes to days. Those are documented session lengths supplied by vendors, not independently benchmarked figures.
What Rotating Proxies Actually Do
A rotating proxy spreads requests across many addresses. A job of 1,000 requests can exit through 1,000 different IPs, so no single address ever looks busy. That is the whole argument for rotation on bulk reads: no one IP accumulates enough request density to trip a rate heuristic.
The trade-off appears the moment your workflow needs continuity. Rotate mid-checkout and the new address arrives without the session cookie, the CSRF token or the cart contents. You rebuild state on every hop, and the site sees a new visitor landing on a deep URL.
If you are wiring rotation into a scraper for the first time, the rotating proxy setup guide covers credential formats and rotation intervals before you design sessions.
What rotation does not fix
Pool size is a marketing number. Proxyway’s 2026 research puts the median advertised residential pool at 54M IPs, and a pool advertised at 20M may have only 2–3M addresses online on a given day. Those addresses are also unevenly spread across subnets.
Rotate randomly from a pool concentrated in a handful of ranges and thirty addresses inside the same /24 firing in lockstep is a correlated pattern, not camouflage. Google scores request density per IP and per subnet over rolling windows: ten queries an hour from one residential address is unremarkable, four hundred is not.
Sticky vs Rotating, Feature by Feature
Sticky and rotating differ on the things that decide whether a target blocks you: how many addresses you touch, how often you re-authenticate, how state survives, and where the detection surface sits. The rotating proxy vs sticky comparison below puts both modes on the same rows.
| Feature | Sticky | Rotating |
|---|---|---|
| IPs used | One, held for the window | Many, per request or timer |
| Re-authentication | Rare inside the window | Constant across hops |
| Billing unit | Per GB, or per IP/month for ISP static | Per GB of traffic |
| Detection surface | Request density on one address | Subnet correlation across many |
| State handling | Cookies, carts and tokens survive | State lost unless re-injected |
| Failure mode | Session dies when the device drops | New IP may already be flagged |
| Best fit | Logged-in, multi-step flows | Discovery and bulk reads |
IP stability and re-authentication
Sticky sessions exist because anti-fraud systems watch for account teleporting. An account that logs in from Frankfurt, refreshes from Dallas and confirms an order from Singapore looks stolen, even when all three addresses are genuine residential IPs. Holding one exit IP across a session removes that signal.
Detection surface: request density per IP and per subnet
Rotating only helps when the addresses you rotate through are genuinely independent. Random selection from a narrow pool concentrates traffic inside a few ranges, and detection systems map subnets rather than single IPs. Enforce a per-subnet cap and widen the geography when the target throttles whole ranges.
Sticky has the mirror-image problem. One address firing 400 requests an hour looks like an unattended script, however clean the IP was when you started. Providers advertise gigabytes, not address health, so the caps are your job.
Cookie, fingerprint and timezone continuity
Proxy mode is one layer of the identity. Even a perfect sticky session leaks if the browser behind it reports a different timezone than the exit IP, renders a canvas that collides with another profile, or carries a font stack the operating system cannot produce.
That is the layer Send.win covers: each profile runs as its own patched-Chromium instance with canvas, WebGL, audio, fonts and hardware spoofed at the engine level and kept coherent, and timezone, locale, WebRTC and geolocation follow the proxy’s exit IP automatically. If you are still choosing between address types, start with residential vs datacenter proxies before you tune session windows.
Sticky, Rotating and Static Are Three Different Things
2026 tightened the vocabulary. “Static” in a session context now means holding one IP for the duration of a session — which is exactly what sticky does. ISP/static residential is a separate product: you rent a specific address per month instead of borrowing one from a shared pool for twenty minutes.
Pricing follows that structure. Rotating and sticky residential bill per gigabyte of traffic. ISP/static residential bills per IP per month. Both can be correct for the same team on different workflows.
The distinction matters most for long-running account work. A sticky window that resets every 30 minutes will eventually place your logged-in account on a new address without asking you. An ISP proxy will not. Hex Proxies, for example, ships rotating as the default mode, offers sticky windows up to 30 minutes on residential, and points account work at ISP proxies for permanent dedicated addresses.
Which Mode Wins for Each Job
SERP scraping and discovery
Mature SERP pipelines stopped rotating randomly and moved to a hybrid: run a sticky session for two to five requests, then rotate. That keeps related queries on one address while preventing any single IP from carrying a whole keyword list.
Cap requests per IP and per subnet, and jitter your intervals. Fixed gaps between requests are themselves a robotic signal. Google publishes no fixed request quota before a 429 — the threshold moves with request rate, fingerprint quality and IP reputation — so pacing choices matter more than any headline limit.
One August 2026 case shows how fast this breaks: a crawler running 40,000 queries a day had roughly a third of its requests blocked within 48 hours after keyword volume doubled on the same proxy configuration.
E-commerce price checks and checkout flows
Use rotating for catalog and listing pages where each fetch stands alone. Switch to sticky the moment a session involves a cart, a coupon field, a payment step or paginated results you must walk in order. A 10 to 30 minute window comfortably covers a normal checkout, so there is no reason to request a longer one.
Social media, ad and marketplace accounts
Account platforms treat IP churn as a risk signal. Logging the same profile in from a new address every few minutes reads as compromise, so sticky windows or ISP statics win here — and pair each account with one profile per account so the cookie jar, fingerprint and IP move together.
The Hybrid Pattern: Sticky Bursts, Then Rotation
The most reliable setup is not a choice between the two modes. It is a scheduler that decides per step: discovery pages rotate, login and checkout pages pin an address for a short burst, and any address that returns a hard block goes into quarantine. If your stack is Playwright, Puppeteer or Selenium, keep that decision in configuration so you can flip modes per run.
Cap requests per IP and per subnet
Track two counters in your scheduler — requests per address and requests per subnet — and reset both on a rolling window. When either hits its ceiling, retire the session token and start a new sticky burst on a different subnet. This one change removes most of the correlation that random rotation creates.
Classify errors before you retry
Split responses into four buckets: clean, soft block, hard CAPTCHA, and transport failure. A soft block deserves a slower retry on the same address. A hard CAPTCHA should quarantine that IP for hours and flag its neighbouring addresses in the subnet for inspection. Retrying a CAPTCHA on the same IP deepens the block — the repeat reads as confirmation, not persistence.
Code: sticky burst in Playwright and Puppeteer
Both frameworks accept the proxy at launch, and the session token lives in the credentials, so switching modes is a string change.
from playwright.sync_api import sync_playwright
# One session token = one sticky IP. Change the token to get a new exit.
SESSION_NAME = "burst-a7f3c1" # retire this after 2-5 requests
PROXY = {
"server": "http://gate.provider.example:8000",
"username": f"user-session-{SESSION_NAME}",
"password": "PROXY_PASSWORD",
}
with sync_playwright() as p:
browser = p.chromium.launch(proxy=PROXY, headless=True)
page = browser.new_page()
page.goto("https://example.com/account/orders", wait_until="domcontentloaded")
# keep this context for the burst, then build a new SESSION_NAME
browser.close()
const puppeteer = require('puppeteer');
(async () => {
const session = 's1-' + Math.random().toString(36).slice(2, 8); // new token, new IP
const browser = await puppeteer.launch({
args: ['--proxy-server=http://gate.provider.example:8000'],
});
const page = await browser.newPage();
await page.authenticate({
username: `user-session-${session}`,
password: 'PROXY_PASSWORD',
});
await page.goto('https://example.com/checkout', { waitUntil: 'domcontentloaded' });
await browser.close();
})();
When the browser is a Send.win profile instead of a bare Chromium, attach to the running profile rather than launching your own. The profile already carries the fingerprint, timezone and cookies, so your script inherits a consistent identity and the proxy decision stays upstream. The browser automation proxy rotation walkthrough covers the local Automation API on Team.
from playwright.sync_api import sync_playwright
CDP_URL = "http://127.0.0.1:PORT" # copy it from the profile's automation settings
with sync_playwright() as p:
browser = p.chromium.connect_over_cdp(CDP_URL)
page = browser.contexts[0].pages[0] # the profile's existing tab
page.goto("https://example.com/account", wait_until="domcontentloaded")
print(page.title())
Sticky vs Rotating Proxy Pricing in 2026
The rotating proxy vs sticky question does not change your bill: on residential plans you pay per gigabyte either way, and the mode is free to switch. The number that moves is the rate, and headline rates are volume-gated.
| Provider | Sticky hold (vendor claim) | Entry price | Volume price | Notes |
|---|---|---|---|---|
| Oxylabs | Up to 24 hours | $30/mo for a 5 GB tier ($6.00/GB) | $2.50/GB at 1 TB | Trial on request |
| IPRoyal | Up to 7 days | $7.00–$7.35/GB at 1 GB | $5.15/GB at 50 GB | No standard free trial |
| Decodo | Minutes to days | $4.00/GB pay-as-you-go, $3.75/GB committed | $2.00/GB at 1,000 GB | 3-day trial or 14-day refund, not both |
| Bright Data | Not documented in the 2026 audits | $4.00/GB pay-as-you-go | $3.50/GB at ~141 GB | Company verification required |
| SOAX | Not documented | $5.00/GB Sandbox | $3.00/GB committed, $0.85/GB Enterprise | 155M+ IPs claimed across 195 geos |
| DataImpulse | Not documented | $1.00/GB flat, $5 intro block | — | $50 minimum top-up; blocks government and payment sites |
| Send.win | Not a browser setting — the mode belongs to the proxy you attach | Trial 1 GB, Pro 5 GB, Team 20 GB included | Extra bandwidth $6/GB | Timezone, locale, WebRTC and geolocation follow the exit IP; BYO HTTP/SOCKS5 supported |
Across six vendors audited in August 2026, 1 GB entry prices ran from $3.49 to $7.00 per GB, and the same vendors reached $2.30–$2.75/GB past 100 GB. Broader published residential pricing spans $1.00–$7.35/GB with entry tiers clustering near $4.00/GB, and a 5,000 GB prepaid package has reached $0.65/GB. Read the volume column carefully: Decodo’s $2.00/GB needs a 1,000 GB purchase, and IPRoyal’s lowest headline rate only appears at 10,000 GB. After declines of up to 75% between 2023 and 2025, rates stabilized in 2026, and grey-market entry pricing under $0.50/GB is treated as a red flag.
Do the arithmetic before you commit. At the $4.00/GB entry tier, 20 GB of rotating traffic costs about $80 a month; at a $2.50/GB volume floor, the same 20 GB is roughly $50. Send.win Pro is $19/mo — $6.99/mo billed annually at $83.88/yr — and bundles 5 GB with extra bandwidth at $6/GB, so the value sits in the profile layer rather than in the cheapest gigabyte. Team is $49/mo, or $20.99/mo billed annually at $251.88/yr, and includes 20 GB plus the local Automation API.
Common Mistakes That Get Sticky Sessions Blocked
- Reusing one token across parallel workers. Two threads with the same session string share one address and double its request density silently.
- Holding a window longer than the task. A checkout finishes in minutes; a 24-hour session keeps an address open for hours of nothing.
- Retrying a hard CAPTCHA in place. The repeat confirms the block. Quarantine the IP and re-check its subnet neighbours.
- Rotating on a fixed timer. Regular intervals are a pattern. Jitter around a sane baseline instead.
- Ignoring the browser layer. A clean IP with a mismatched timezone, WebGL renderer or font list still reads as a fake machine.
How Send.win Helps With Rotating Proxy Vs Sticky
Send.win is an antidetect browser built for exactly this kind of work — every profile is a clean, isolated identity:
- Isolated profiles – unique fingerprint, separate cookies and storage per profile
- Stealth engine – canvas, WebGL, fonts, and audio spoofed at the engine level
- Desktop app + cloud sessions – native app for Windows, macOS, and Linux, or run profiles in the cloud with no install
- Built-in residential proxies – with automatic timezone, locale, and WebRTC matching
- Team features – share logged-in profiles with teammates without sharing passwords
Try the instant cloud browser demo — no install, no signup — or download the desktop app. The 30-day free trial needs no credit card, and paid plans start at $6.99/month billed annually (see pricing).
Rotating vs Sticky: What to Choose
Treat the rotating proxy vs sticky decision as per-step, not per-project. Rotating wins when each request stands alone: discovery pages, catalog listings, keyword expansion, price sweeps. Sticky wins whenever request two depends on request one: logins, carts, checkouts, dashboards and anything carrying a CSRF token.
If your work is account-based rather than page-based, a timed sticky window is a stopgap. Long-lived accounts on social, marketplace or ad platforms want an address that does not move — ISP/static residential or a dedicated IP. Send.win fits the other half of that equation: share a profile with a paid teammate and it opens already signed in, so the login is not recreated from a different machine and a different IP.
🏆 Send.win Verdict
Session mode is a proxy decision, but it only pays off when the browser agrees with it. Send.win runs each profile as its own patched-Chromium instance with canvas, WebGL, audio, fonts and hardware spoofed at the engine level and kept coherent, and timezone, locale, WebRTC and geolocation follow the proxy’s exit IP. Residential proxies ship on every plan — 1 GB on the trial, 5 GB on Pro, 20 GB on Team — and you can point a profile at your own HTTP/SOCKS5 gateway. It will not rescue bad proxy hygiene: hammer one address and it still gets blocked.
Try Send.win free today — 30 days free, $0 today, cancel anytime, with the local Automation API on Team and a 7-day money-back guarantee.
Frequently Asked Questions
What is the difference between a rotating proxy and a sticky proxy?
A sticky proxy holds one exit IP for a defined session length, usually 10 to 30 minutes. A rotating proxy issues a new IP per request or on a timer. At most providers both are session modes on the same residential plan, so you change a credential string rather than buying a different product.
Which proxy type is best for web scraping?
It depends on whether requests are independent. Bulk discovery and listing pages work well with rotation. Logged-in flows, carts and paginated sequences need a sticky window so state survives. Mature pipelines do both: a sticky burst of two to five requests, then rotation.
Can I switch between rotating and sticky in one workflow?
Yes — the rotating proxy vs sticky choice is configuration, and mixing them is the common pattern in 2026. The session token sits in the proxy username, so your scheduler can pin an address for the checkout step, then drop the token and rotate again for the next discovery pass. Keep that choice in configuration rather than in client code.
How long do sticky proxy sessions last?
The practical default is 10 to 30 minutes, with some providers offering up to two hours. Vendor-published ceilings go further: Oxylabs documents 24 hours and IPRoyal claims up to 7 days. Treat all of them as vendor claims, because the underlying residential device can go offline and end the session early.
Do sticky sessions cost more than rotating?
No. On residential plans both modes bill per gigabyte of traffic and the mode is free to switch. The price difference appears between product types: rotating and sticky residential bill per GB, while ISP/static residential bills per IP per month.
Are sticky proxies and static ISP proxies the same thing?
No, though the wording overlaps. Sticky means holding one pool IP for a session window. ISP/static residential means renting a specific address per month that does not come from a shared pool. Account work that must not change IP over weeks belongs in the second category.
Why does my scraper get blocked even with sticky sessions?
Usually because the window outlived the task or one token is shared across parallel workers, which doubles request density on a single address. Retrying a hard CAPTCHA on the same IP makes it worse. Retire the token, quarantine the address for hours and check its subnet neighbours.
How many requests can one IP make before Google blocks it?
There is no fixed quota. The threshold moves with request rate, client fingerprint and IP reputation, and Google scores density per IP and per subnet over rolling windows. Ten queries an hour from one residential address is unremarkable; four hundred is not. Cap both counters and jitter your intervals.