YouTube shows "Sign in to confirm you're not a bot" when it does not trust a session enough to play a video without an account. The text comes from YouTube, and YouTube publishes no help page for it. In yt-dlp the same text arrives as an ERROR line, with a hint about cookies that yt-dlp adds. For yt-dlp users the first thing to check in 2026 is not the cookies: in our count of 51 bug reports that quote the message, 30 percent of the logs had no JavaScript runtime installed.
Two readers see this message. A viewer in a browser usually meets it on a VPN, a work or school network, or in a private window. A yt-dlp user meets it when a download that worked yesterday stops, often on a server. The causes overlap, and the fixes differ.
| What YouTube weighs | In a browser | In yt-dlp |
|---|---|---|
| Whether the client can run the scripts of YouTube | Allow scripts and cookies | Install a JavaScript runtime (Deno) |
| The session and its cookie history | Sign in, keep your cookies | Export cookies the way the wiki says |
| The address | VPN off, or another network | Not a datacenter server; try --force-ipv4 |
| The rate of requests | Wait | -t sleep, fewer downloads an hour |
What the message says, and who wrote which part
In a browser the player shows "Sign in to confirm you're not a bot. This helps protect our community. Learn more". The yt-dlp code takes that reason from YouTube, removes the last sentence, and appends its own hint. A typical line reads:
ERROR: [youtube] VIDEO_ID: Sign in to confirm you’re not a bot. Use --cookies-from-browser or --cookies for the authentication. See https://github.com/yt-dlp/yt-dlp/wiki/FAQ#how-do-i-pass-cookies-to-yt-dlp for how to manually pass cookies. Also see https://github.com/yt-dlp/yt-dlp/wiki/Extractors#exporting-youtube-cookies for tips on effectively exporting YouTube cookies
So the words "not a bot" come from YouTube, and the advice about cookies comes from yt-dlp. Two neighbouring messages have their own causes. YouTube is requiring a captcha challenge before playback means YouTube put a captcha in the way. This content isn't available, try again later is a rate limit, and yt-dlp adds that the session is limited "for up to an hour".
This is not new or rare. In 2024 a yt-dlp maintainer noted that the sign-in requirement affected almost all apps that access YouTube, the official web app included.
In a browser
Sign in first, since that is the step the message names. If you would rather not use an account, work through these in order.
- Use a normal window with cookies allowed. A private window starts without history, and so does a profile that blocks cookies or scripts for YouTube. A yt-dlp maintainer put it plainly: YouTube uses tracking cookies to judge how trustworthy a session is. For the same reason, do not start by clearing the YouTube cookies, which throws that history away.
- On a site that embeds YouTube, allow its cross-site cookies. HeySummit, which embeds YouTube for its events, says it cannot override the check. Oracle tells the viewers of its help videos to allow cross-site tracking, which most browsers block by default.
- Test the address. Turn off the VPN, or play the video on a phone over mobile data. If it plays there, the address of your first connection is part of the cause. Our guide to turning off a proxy covers proxies you did not set on purpose.
- Wait out a rate limit. An address that sent YouTube too much traffic, from you or from someone else on it, meets the check more often for a while. Our guide to the Google unusual traffic message explains how to find that traffic.
In yt-dlp: check four things, in this order
We read the 51 issues opened on the yt-dlp tracker in the year to 25 September 2026 that quote this message in the title or the report itself, and 33 of them include a verbose log. The order below follows what those logs show, not what is easiest to type.
1. Install a JavaScript runtime
Since version 2025.11.12, yt-dlp needs an external JavaScript runtime to download from YouTube fully. The yt-dlp EJS guide says it must "solve JavaScript challenges presented by YouTube". Deno is recommended and is the only runtime turned on by default. The guide gives Deno 2.3.0 as the minimum; Node works from version 22.0.0 when you add --js-runtimes node.
Look for this warning in your output: No supported JavaScript runtime could be found. In a verbose log (-vU) the same problem shows as [debug] JS runtimes: none. That was the case in 10 of the 33 logs we read. One reporter titled the issue "YouTube seems to have started blocking by IP", and a maintainer answered with "Heed the warning" and a link to that guide.
Update yt-dlp too, but do not expect the update alone to fix it. Of the 21 logs from a stable build, 20 ran the newest release of the day.
2. Export cookies the way the wiki says
In 12 of the 33 logs, cookies were loaded and the error came anyway. A maintainer answered one such report with: "You didn't export the cookies correctly". The yt-dlp wiki explains why: YouTube rotates account cookies frequently in open YouTube tabs, so a file exported from your everyday browser stops working soon. The method in the wiki avoids that:
- Open a new private window and sign in to YouTube.
- In the same tab, open
https://www.youtube.com/robots.txt. It should be the only private tab open. - Export the youtube.com cookies with a cookie export extension, to a Netscape format file.
- Close the private window at once, so the session is never opened again.
- Run
yt-dlp --cookies cookies.txt URL.
Do not export with --cookies-from-browser and --cookies together. The wiki warns that this exports your regular browser cookies and not the private session.
Two warnings from the same page. "By using your account with yt-dlp, you run the risk of it being banned (temporarily or permanently)." And cookies are only necessary for content that requires an account, such as private playlists, age-restricted videos and members-only videos. Logging in with OAuth no longer works with yt-dlp.
3. Check the address
A yt-dlp maintainer wrote that users who stay blocked even with a valid PO Token are likely downloading too fast, or running from a datacenter address, which is "susceptible to being blocked". In our count, 10 of the 51 reports name a server, VPS or cloud machine, 4 a VPN and 5 a proxy.
The plain test is to run the same command from a home connection. If it works there, the server address is part of the cause, and running yt-dlp at home is the fix that costs nothing. A proxy does not settle it on its own: 5 of the 33 logs had one set, and the error came anyway. For a report where every public video failed, a maintainer also suggested --force-ipv4, which makes all connections over IPv4.
4. Slow down
The wiki puts the YouTube rate limit at about 300 videos an hour for a guest session and about 2,000 for an account, and recommends 5 to 10 seconds between downloads. The -t sleep preset sets --sleep-requests 0.75, --sleep-interval 10 and --max-sleep-interval 20, plus a pause before subtitles. If you see This content isn't available, try again later, the rate is the cause, and waiting up to an hour lifts it.
When the log mentions a PO Token
YouTube requires a Proof of Origin token for some of the clients yt-dlp can use. The PO Token guide says that without one, requests may get HTTP Error 403, or the account or address may be blocked. Tokens are now bound to each video, so the guide recommends a PO Token provider plugin instead of copying tokens by hand. This part changes often. Treat the guide as the source, not a blog post, this one included.
What the YouTube terms say
YouTube serves its Terms of Service by country, and the versions differ on one point. All of them forbid downloading content unless the service permits it or YouTube gave written permission. All of them forbid accessing the service "using any automated means (such as robots, botnets or scrapers)", except public search engines that follow YouTube's robots.txt and anyone with YouTube's written permission. The version for the European Economic Area and Switzerland (Google Ireland, effective 5 January 2022) and the one for the United Kingdom (Google LLC, effective 17 March 2025) add a third exception to both rules: "as permitted by applicable law". The US version (Google LLC, effective 15 December 2023) has no such exception.
All three forbid circumventing "security-related features", and the check behind this message is such a feature. None of the steps above changes those rules, and the account risk in the yt-dlp wiki is real.
How we counted

We read every issue opened on the yt-dlp tracker from 26 September 2025 to 25 September 2026 that quotes "not a bot" in its title or in the report itself, 51 in all, through the public GitHub API. A search without that limit also returns issues where only a comment quotes the message, 79 in all, some of them about other sites, so we left those out. For the 33 with a verbose log, we read the [debug] lines, which show the version, the cookies, the JavaScript runtime and any proxy. The quoted error itself contains --cookies, so we removed it before counting what reporters wrote. People who file issues are asked to update first, so the share of current versions is higher than among yt-dlp users in general.
Sources
- yt-dlp source, extractor/youtube/_video.py and common.py, 16 September 2026, read 26 September 2026. They build the error line, the captcha message and the rate limit message.
- yt-dlp wiki, Extractors, last edited 11 June 2025, read 26 September 2026. It covers exporting cookies, "you run the risk of it being banned (temporarily or permanently)", and the rate limits.
- yt-dlp wiki, PO Token Guide and EJS, both last edited 12 July 2026, read 26 September 2026.
- yt-dlp announcement #15012, 12 November 2025. External JavaScript runtime support arrived with version 2025.11.12.
- yt-dlp issue tracker, read 26 September 2026. The maintainers' answers on issues #10128, #15392, #15865, #16410 and #16747.
- yt-dlp README, read 26 September 2026. It documents
--proxy,--force-ipv4,--cookies, the sleep options and the-t sleeppreset. - YouTube Terms of Service in three versions, all read 27 September 2026: European Economic Area and Switzerland, Google Ireland, effective 5 January 2022; United Kingdom, Google LLC, effective 17 March 2025; United States, Google LLC, effective 15 December 2023.
- HeySummit Help Center, 25 July 2026, and Oracle Help Center, 16 April 2026, both read 26 September 2026.
- Measured by HProxy: the count of 51 yt-dlp issues that quote the message, on 27 September 2026. The script and its results are kept with the research for this page.


