Swiggy answers a datacenter client with HTTP 202 and nothing in the body. That is the first thing to know about scraping it, and it is not a bug: a 202 with an empty page is what AWS WAF's challenge action returns, a JavaScript interstitial that a real browser solves in a moment and a script never does. On 24 August 2026 our datacenter server got exactly that, and so did every one of the 20 free proxies that managed to connect. The site behind the challenge is India's other delivery giant: more than 2.5 lakh restaurants across 720-plus cities and more than 6 lakh delivery partners per Swiggy's FY25 annual report (Swiggy, annual report FY2024-25), plus Instamart, the quick-commerce arm whose gross order value grew 108 percent year on year in the quarter to 30 September 2025 (Swiggy Q2 FY26 press release).
Everything on Swiggy is per locality: which restaurants deliver, their prices and fees, what Instamart stocks and charges from the nearest dark store, which offers apply. A city is many localities on a schedule, read through a challenge that scores the client.
What fits
Indian residential proxies pinned to the city of the localities you read, driving a real browser, with a session per locality. Any restaurant-partner login needs its own static ISP proxy. Datacenter and free exits get the 202 and nothing else, as the count below shows.
Swiggy as a target
Four surfaces. Restaurant storefronts per locality, with prices set by restaurants and fees set by the platform. Instamart, where prices belong to Swiggy and differ by dark store, which makes it a quick-commerce price target in the same way Instacart is a grocery one. Swiggy One, the membership that changes the fee schedule. And Dineout, the dining-out side, with restaurant deals and bookings.
Behind AWS WAF, swiggy.com is a JavaScript application. Once the challenge is solved, the storefront and the Instamart catalog load through Swiggy's own API calls keyed to the locality in the session.
Jobs a proxy is right for
- Menu and delivery price monitoring. What a restaurant charges on Swiggy versus its own menu, plus fees and estimates, per locality. Chains audit their own listings; price-intelligence firms build the dataset.
- Instamart price and assortment monitoring. Swiggy's own prices per dark store, compared against Blinkit, local supermarkets and other quick-commerce players, city by city.
- Coverage by locality. Which restaurants and which Instamart stores reach a locality and at what estimate, for site selection and competitor mapping.
- Offer and Swiggy One research. Which offers and membership perks show in which cities and when they rotate.
- Swiggy against Zomato. The same restaurant on both platforms at the same locality. The Zomato side, with a very different door, is in proxies for Zomato.
Jobs a proxy is not for
Delivery-partner accounts. Identity and bank verification.
Ratings and reviews. Manipulating them from many addresses is fraud, not research, and we refuse it.
Account farming for credits. Phone, payment and device tie accounts together, and farming credits runs against Swiggy's terms.
The door: HTTP 202 and an empty page
swiggy.com replied to our German datacenter server on 24 August 2026 with HTTP 202, no title, no content, through CloudFront. The 20 elite HTTP proxies from our free proxy list that followed, one call each, split into 15 that never answered and 5 that connected and received the same 202. The site itself never appeared.
A 202 is easy to misread as success, which is the trap. It means "accepted", and here it means the request was accepted into a challenge: AWS WAF hands back a small JavaScript page, the browser solves it, and only then does the real page load. A scraper that treats 202 as a good response will record empty pages all night. Getting past AWS WAF explains the challenge and the token it sets; the practical answer is the same as for any JavaScript challenge, which is a real browser on an address the challenge is served to rarely, and residential Indian addresses are those.
Type by job
| Swiggy job | Proxy type | Why |
|---|---|---|
| Menu and delivery price monitoring | Rotating Indian residential, city-pinned, sticky per locality | Solves the challenge with a real browser; reads as a local |
| Instamart price and assortment monitoring | Rotating Indian residential, sticky per locality | Prices are per dark store, chosen by locality |
| Coverage by locality | Rotating Indian residential, sticky per locality | Each locality is one session |
| Offer and Swiggy One research | Rotating Indian residential, city-pinned | Offers are per city |
| Restaurant-partner login | Indian ISP (static residential) | One fixed, trusted location per account |
| Anything | Datacenter or free | Challenged at the door, 0 of 20 |
For the general split, datacenter vs residential proxies.
Free proxies here
None of twenty, and the Indian free pool is thin to begin with, so even a single manual look is unlikely. Free India proxy describes the pool honestly, and the live count on our free proxy list filtered to India tells you the odds before you try. For a city sweep, our Indian residential proxies start at $0.44/GB, pay as you go, no KYC.
Setup
- Indian residential exit, city-pinned. A Hyderabad locality from a Hyderabad exit. The challenge is served less to addresses that look like customers, and the metering behind it keys on the address.
- A real browser, always. There is no fetch-only route through a JavaScript challenge. Keep the browser's cookies for the session, because the challenge token lives there. The Puppeteer proxy guide shows the launch.
- Check the status code and the body. Treat any 202 with an empty body as "not loaded" and let the browser finish; never record it as data.
- Sticky session per locality. Set the locality, read the storefronts or the Instamart catalog you track, record locality and timestamp, rotate. Sticky vs rotating proxy sessions explains why a mid-session rotation brings the challenge back.
- Pace for a thin pool. Fewer Indian exits means more reuse per exit; read slower and grow the pool. Avoiding IP bans while scraping picks up from there.
Sizing
Instamart price watch, 4 cities, twice weekly:
localities per city 12
pages per locality session ~15 (catalog categories)
sessions per exit per day 3-5
exits in rotation ~20-25 Indian residential, city-pinned
Catalog pages with images blocked are small, and bandwidth is what residential meters, so the locality list sets the bill; nothing on our pricing page expires.
Where it ends
A residential Indian address is what turns the 202 into a page, with a real browser doing the solving; the proxy does nothing for delivery-partner identity, ratings, account links, or Swiggy's terms, which prohibit scraping. Beyond that, a city-pinned residential exit lets a legitimate data job read public storefronts and Instamart catalogs the way customers in each locality see them: one locality per session, human pacing, the challenge rate logged.
The rival with an open door and public restaurant pages is in proxies for Zomato; the same 202-style challenge on a European delivery site appears on Glovo, which we cover next in this cluster.
Sources
- Swiggy Limited, annual report FY2024-25 (more than 2.5 lakh restaurants across 720-plus cities; more than 6 lakh delivery partners): swiggy.com/corporate
- Swiggy Limited, Q2 FY26 press release, 30 October 2025 (Instamart gross order value up 108 percent year on year): swiggy.com/corporate
- HProxy measurement, 24 August 2026: one direct request from a datacenter server (HTTP 202, empty body, CloudFront) and 20 elite HTTP proxies from our free proxy list (15 no connection, 5 challenge, 0 site).