# Strava Proxies: 117 Words Without a Login

> Strava measured from 3 countries: a segment page returns 117 words without a login; a club page returns 7,284,511 members and 20 posts over plain HTTP.

[Home](https://quanticdata.io/)/[Blog](https://quanticdata.io/blog/)/Strava Proxies: 117 Words Without a Login

# Strava Proxies: 117 Words Without a Login

Social proxiesSep 29, 2026·10 min read·By [Aldo Morese](https://quanticdata.io/about/), founder of QuanticData

What a public Strava page costs to read through a proxy, measured on 28 September 2026: a segment page returns 117 words over plain HTTP in 615,374 bytes and the same sign-in prompt rendered in 1,383,075 bytes, the club page returns 7,284,511 members and twenty posts in 963,234 bytes over plain HTTP, and rendering the club page costs 2,161,313 bytes for the same 1,089 words

On this page [On this keyword, "proxy" means the heatmap](/blog/strava-proxies/#on-this-keyword-proxy-means-the-heatmap) [A segment page is 117 words and a sign-in prompt, from any country](/blog/strava-proxies/#a-segment-page-is-117-words-and-a-sign-in-prompt-from-any-co) [The club page is the one public surface with data in it](/blog/strava-proxies/#the-club-page-is-the-one-public-surface-with-data-in-it) [The API needs OAuth, and it documents its own ceiling](/blog/strava-proxies/#the-api-needs-oauth-and-it-documents-its-own-ceiling) [What robots.txt and the terms say](/blog/strava-proxies/#what-robots-txt-and-the-terms-say) [What a gigabyte buys, and what it does not](/blog/strava-proxies/#what-a-gigabyte-buys-and-what-it-does-not) [The setting that works on Strava](/blog/strava-proxies/#the-setting-that-works-on-strava)

Strava is the largest activity network in sport, and it is the platform in this series that publishes the least to a logged-out client. On 28 September 2026 we fetched it twenty-one times through residential exits in the United States, Germany and Italy. A public segment page returned 117 words: the segment name, sport and location in the title, and a sign-in prompt in the body, the same from every country and with or without a browser. The club page is the one public surface with data: 7,284,511 members and twenty dated posts in 963,234 bytes over plain HTTP. Everything else on Strava is behind OAuth, and the terms say so in one sentence.

## On this keyword, "proxy" means the heatmap

Search for Strava proxies and Google returns code, not vendors. Ranks one and four are GitHub repositories called strava-heatmap-proxy, small servers that stream Global Heatmap tiles into mapping tools that cannot log in; rank three is a mapping forum discussing them, and rank two is a Strava community event literally named "Test Proxy" with 247 participants. Further down: an r/Strava thread on alternatives after the API restrictions, one VPN video and a Strava press release about privacy. The autocomplete box is empty for the head term.

The intent that exists is under "strava api", which completes fifteen ways and reads like a support queue: key, access, cost, changes, "subscriber only", limits. And under "strava scraper", where "strava club scraper" is the first suggestion and "can you export data from strava" is the third. This post answers those with numbers: what the public web hands a proxied client, what the club page carries, what the API allows, and where Strava draws the line.

## A segment page is 117 words and a sign-in prompt, from any country

We audited `strava.com/segments/229781`, Hawk Hill in the Marin Headlands, one of the most ridden climbs on the platform, from three countries, each time as a pure HTTP client and as a full browser.

| Exit | Plain HTTP words | Title | h1 |
| --- | --- | --- | --- |
| United States | 117 | Hawk Hill \| Strava Ride Segment in Marin Headlands (GGNRA), California | Log in to see "Hawk Hill" |
| Germany | 113 | Hawk Hill \| Strava Radfahren Segment in Marin Headlands (GGNRA), Vereinigte Staaten von Amerika | Anmelden, um „Hawk Hill“ zu sehen |
| Italy | 123 | Hawk Hill \| Strava Ciclismo Segmento in Marin Headlands (GGNRA), Stati Uniti d'America | Accedi per vedere "Hawk Hill" |

The plain response is 615,374 bytes and it contains exactly what a search engine needs and nothing else: the segment name, the sport and the place in the title, a `robots: noindex` meta tag, an Organization JSON-LD block for Strava itself, and a body that asks you to log in. Strava localises the title and the h1 off the exit IP alone, with no Accept-Language header sent, which is why the three word counts differ by ten: the German chrome is shorter than the Italian.

Rendering does not open it. From the US the browser returned the same 117 words. From Germany and Italy the audit counted 1,805 and 2,116 words in the rendered DOM, so we looked at what they were: the visible text from Italy was the same sign-in prompt, in 1,383,075 bytes and 6.1 seconds. The extra words are the localised chrome and the consent and menu markup that European visitors get; the leaderboard, the elevation profile and the efforts never appear. The pro athlete page behaves the same way: `/pros/1671` returned 615,442 bytes with the athlete’s name, team and photo in a Person JSON-LD block and a sign-in prompt for a body. A non-existent id, `/athletes/1`, returns Strava’s own 404 page, "Sorry, this one stays red".

## The club page is the one public surface with data in it

`strava.com/clubs/strava`, the platform’s own club, is a different animal. Over plain HTTP from the US it returned 963,234 bytes and 1,089 words with real content: the club name, location (San Francisco, California), website, description, a member count of 7,284,511, and twenty dated posts with their first lines, from January to September 2026, including product announcements and the Strava Metro academic programme. No login, no cookie.

The country matters here for the label and the weight, not the data. From Germany the same page came back as "7.284.511 Mitglieder" in 1,337,550 bytes; from Italy as "7.284.511 membri" in 1,317,053 bytes. The localised bundles are 37% heavier than the US one, and the thousands separator flips to a full stop, which is the parser trap we keep meeting in this series: a naive integer parse of "7.284.511" returns 7. The posts themselves stayed in English from all three exits; only the interface moved.

Rendering the club page is the expense to strike out. The browser moved 2,161,313 bytes in 10.5 seconds and returned the same 1,089 words. That is 2.2 times the bandwidth for nothing, and it is the pattern on both public surfaces: on Strava the plain HTTP view is the maximum a logged-out client gets, and the browser only adds weight.

## The API needs OAuth, and it documents its own ceiling

Every read on the Strava API is authenticated. A call to `/api/v3/segments/229781` with no token answered in 107 bytes of JSON with an Authorization Error naming the `access_token` field. With a token, the rate-limit page states the numbers plainly, and they are per application, not per IP:

```
Overall:     200 requests per 15 minutes, 2,000 per day
Non-upload:  100 requests per 15 minutes, 1,000 per day  (every read endpoint)
Windows reset at :00, :15, :30, :45; the daily limit at midnight UTC
Headers:     X-RateLimit-Limit / X-RateLimit-Usage  (15-minute, daily)
             X-ReadRateLimit-Limit / X-ReadRateLimit-Usage
Over the limit: 429 with a JSON body; short-term overages still count toward the daily total
```

Two more numbers decide what an application can be. A newly created app has an athlete capacity of one, which Strava calls Single Player Mode: it can read its own creator’s data and nobody else’s. The self-service upgrade raises that to ten athletes, with reads at 200 per 15 minutes and 2,000 a day. Anything larger is a request to Strava. And the API Agreement adds the clause that settles most "strava data scraper" projects before they start: data related to other users, even if it is publicly viewable on the platform, may not be displayed or disclosed in your application.

Because the limits are per application and per token rather than per address, a proxy pool does nothing for API throughput on Strava. It changes where a request comes from, not which application made it. That is worth saying because on [Mastodon](https://quanticdata.io/blog/mastodon-proxies/) and [Discord](https://quanticdata.io/blog/discord-proxies/) the limit is per IP and a pool is exactly what buys concurrency; here it is not.

## What robots.txt and the terms say

`strava.com/robots.txt` is 1,510 bytes. Four AI crawlers, ClaudeBot, Google-Extended, GPTBot and Meta-ExternalAgent, are refused everywhere. Everyone else is allowed in with 47 path exclusions, and the list is a map of where the data lives: activity analysis, heart rate, laps, power and pace views, athlete follows, segments, training logs and trophy cases, club members, leaderboards and discussions, segment comparisons, route exports, the API itself and the dashboard. One path is explicitly allowed: `/training-plans/*`. The sitemap index it points to lists 1,889 pro athlete URLs and separate athlete and verified-athlete sitemaps, all regenerated on the day we measured, so the public shells of those pages are meant to be indexed even though their bodies are not public.

The Terms of Service are the line, and it is one sentence in section 19: automated access to or collection of data from the Services, by any means including data mining, robots, screen scraping, scripts, browser extensions and crawlers, is prohibited, and the prohibition applies whether or not you are logged into a Strava account. There is no reading of that clause that permits a crawl of athlete or activity pages, with or without a proxy, and we will not help build one. What the platform does offer is an API with the athlete’s consent for the athlete’s own data, Strava Metro as a free aggregate data service for planners, and a Metro programme for academic researchers.

## What a gigabyte buys, and what it does not

Nothing in twenty-one fetches looked at the address: every public page answered a rotating residential exit with a 200 on the first attempt from three countries. The cost driver is bytes, and the arithmetic below uses [residential proxies](https://quanticdata.io/residential-proxies/) on the Basic line at $0.80/GB, counting a gigabyte as 10^9 bytes.

| Request | Bytes | Requests per GB | Cost per request |
| --- | --- | --- | --- |
| Segment page, plain HTTP (title only) | 615,374 | 1,625 | $0.00049 |
| Segment page, rendered (same prompt) | 1,383,075 | 723 | $0.00111 |
| Club page, plain HTTP, US | 963,234 | 1,038 | $0.00077 |
| Club page, plain HTTP, Germany | 1,337,550 | 748 | $0.00107 |
| Club page, rendered | 2,161,313 | 463 | $0.00173 |
| API call without a token | 107 | 9,345,794 | $0.0000001 |

The only job those rows price is club and brand monitoring: 10,000 club pages a month are 9.6 GB and about $7.71 over plain HTTP from a US exit, $17.29 rendered for the same words. A segment sweep prices at $0.00049 a page and returns the segment’s name and place, which is a lookup table, not a dataset. Budget by what a request yields, and on Strava the yield outside the club page is a title.

## The setting that works on Strava

- **Network:** [residential proxies](https://quanticdata.io/residential-proxies/), Basic line, $0.80/GB, rotating. The public pages met no address-level obstacle from three countries, and the API limits are per application, so the pool buys throughput on club pages and nothing on the API. Mobile at $2.30/GB and ISP at $2.50/IP per month buy nothing we could measure here.

- **Fetch mode:** `engine: tls`, plain HTTP, never rendered. The club page returns 7,284,511 members and twenty posts in 963,234 bytes; the segment and pro pages return the name, sport, place and a Person block in about 615,000 bytes; rendering returns the same words for 2.2 times the bytes.

- **Country:** pin the United States unless you need the localised labels. The club page is 963,234 bytes from the US and 1,337,550 from Germany, and a German exit writes the member count as "7.284.511". Mixing exits inside a job mixes number formats.

- **When the proxy is not enough:** there is no Strava collector in our catalogue, and the only public data surface does not need one. The [web scraping API](https://quanticdata.io/web-scraping-api/) without rendering returns each club page as clean Markdown or JSON from $0.0002 per page, retries and rotation included, and failed requests are never billed. For athlete and activity data, the route is the Strava API with the athlete’s consent, inside its documented limits; for aggregate movement data, Strava Metro.

- **Free tier:** every account gets $2 of free API usage per month, which is 10,000 club pages through the scraping API before you pay anything.

Read club pages over plain HTTP for club and brand monitoring, take segment and pro names from the titles, and stop there: the terms prohibit automated collection of anything else, logged in or not, and no proxy changes that. That is the whole configuration. For the platform in this series where a public profile carried everything in the head, see [Snapchat](https://quanticdata.io/blog/snapchat-proxies/); for the one where a per-IP API limit made the pool the whole point, see [Mastodon](https://quanticdata.io/blog/mastodon-proxies/).

### Sources & further reading

- [strava.com/robots.txt (fetched 28 September 2026)](https://www.strava.com/robots.txt)

- [Strava Developers: Rate Limits](https://developers.strava.com/docs/rate-limits/)

- [Strava API Agreement](https://www.strava.com/legal/api)

- [Strava Terms of Service (section 19, Proprietary Rights)](https://www.strava.com/legal/terms)

- [Strava sitemap index (athletes, pros, verified athletes)](https://sitemap.strava.com/sitemap.xml)

## FAQ

Quick answers on strava proxies.

[Something else? Ask us →](mailto:hello@quanticdata.io)

### Can you scrape Strava segment or athlete pages without logging in?

You get the title and nothing else. On 28 September 2026 a public segment page returned 117 words to a logged-out client from the United States, 113 from Germany and 123 from Italy: the segment name, sport and location in the title and a sign-in prompt in the body, with or without a browser. A pro athlete page returned the name and photo in a Person JSON-LD block and the same prompt. The leaderboard and efforts never appear.

### Which Strava page is public over plain HTTP?

The club page. strava.com/clubs/strava returned 963,234 bytes and 1,089 words over plain HTTP with the club name, location, website, a member count of 7,284,511 and twenty dated posts with their first lines, no login required. Rendering the same page cost 2,161,313 bytes and 10.5 seconds for the same 1,089 words.

### What are the Strava API rate limits?

Per application, not per IP: 200 requests per 15 minutes and 2,000 per day overall, and 100 per 15 minutes and 1,000 per day for every non-upload endpoint, with windows resetting at :00, :15, :30 and :45 and the daily limit at midnight UTC. New apps have an athlete capacity of 1, Single Player Mode; the self-service upgrade allows 10 athletes with reads at 200 per 15 minutes and 2,000 a day. A proxy pool does not change any of these numbers.

### Does the exit country change what Strava returns?

The labels and the weight, not the data. The segment title came back as "Ride Segment" from the United States, "Radfahren Segment" from Germany and "Ciclismo Segmento" from Italy with no Accept-Language header sent. The club page was 963,234 bytes from the US, 1,337,550 from Germany and 1,317,053 from Italy, with the member count written "7.284.511" from both European exits. Pin one country per job.

### Does Strava allow scraping?

No. Section 19 of the Terms of Service prohibits automated access to or collection of data from the Services by any means, including robots, screen scraping, scripts, browser extensions and crawlers, whether or not you are logged in. robots.txt refuses four AI crawlers everywhere and closes 47 paths to everyone else. The API Agreement adds that other users’ data may not be displayed even if it is publicly viewable. Use the API with the athlete’s consent, or Strava Metro for aggregates.

### What does it cost to monitor 10,000 Strava club pages a month?

At 963,234 bytes per club page from a US exit, 10,000 pages are 9.6 GB, about $7.71 on residential Basic at $0.80/GB, counting a gigabyte as 10^9 bytes. Rendered, the same sweep is 21.6 GB and about $17.29 for the same 1,089 words per page; from a German exit the plain page is 1,337,550 bytes, 37% heavier, because the localised bundle is larger.

## Read the club page, leave the rest to the API

Every number here came from one platform: fetch any Strava URL over plain HTTP or rendered, compare the two views, and see what each byte returns. Every account gets $2 of free API usage each month, and failed requests are never billed.

[Start free — $2/month included](https://quanticdata.io/signup/)[Explore Residential Proxies from $0.80/GB](https://quanticdata.io/residential-proxies/)

## Related reading

[Social proxies Letterboxd Proxies: 2,830 Words, No Browser Nineteen fetches of Letterboxd on 28 September 2026 from the United States, the United Kingdom and Germany. A public film page returns 2,830 words to a plain HTTP client, identical from all three countries, with cast, crew and twelve popular reviews. The average rating is not in that HTML: it arrives in a 5,981-byte fragment the page loads separately. Member profiles are the one surface that answers only a real browser, at 1,270,529 bytes and 32.9 seconds. Here is the whole measurement and the line Letterboxd draws around its API. Read →](https://quanticdata.io/blog/letterboxd-proxies/) [Social proxies Nextdoor Proxies: 2,404 Words, No Login Nineteen fetches of Nextdoor on 28 September 2026 from the United States, Canada and the United Kingdom. A public city page returns 2,404 words to a plain HTTP client, identical from all three countries: resident counts, six neighbour conversations, 1,147 groups, marketplace listings with prices and 44 events. Rendering the same URL costs 1,046,614 bytes and returns 322 fewer words. Here is the whole measurement, the two paths robots.txt leaves open, and where Nextdoor’s own Display API takes over. Read →](https://quanticdata.io/blog/nextdoor-proxies/) [Social proxies XING Proxies: 2,514 Words Without a Browser Twenty-two fetches of XING on 28 September 2026 from Germany, Austria and the United States. A public company page returns 2,514 words to a plain HTTP client, byte-identical from Germany and Austria, with follower count, headcount band, news, twelve job ads and named employees. A member profile returns 679 words and a complete Person JSON-LD block with every role and start date. Rendering the company page costs 1,511,542 bytes for 394 extra words of interface. Here is the whole measurement, what robots.txt closes, and the one line about personal data. Read →](https://quanticdata.io/blog/xing-proxies/)

## Also on this site

Quantic**Data**

Residential proxies & web data APIs for AI.

#### Proxies

- [Residential Basic](https://quanticdata.io/residential-proxies/#basic)

- [Residential Premium](https://quanticdata.io/residential-proxies/#plans)

- [Cheap Residential](https://quanticdata.io/cheap-residential-proxies/)

- [Mobile Proxies](https://quanticdata.io/mobile-proxies/)

- [Datacenter Proxies](https://quanticdata.io/datacenter-proxies/)

- [ISP Proxies](https://quanticdata.io/isp-proxies/)

- [Rotating Proxies](https://quanticdata.io/rotating-proxies/)

- [Sneaker Proxies](https://quanticdata.io/sneaker-proxies/)

- [SOCKS5 Proxies](https://quanticdata.io/socks5-proxies/)

- [IPv6 Proxies](https://quanticdata.io/ipv6-proxies/)

- [Proxy locations](https://quanticdata.io/proxies/)

#### Data APIs

- [MCP Server](https://quanticdata.io/mcp-server/)

- [Web Scraper API](https://quanticdata.io/web-scraping-api/)

- [SERP API](https://quanticdata.io/serp-api/)

- [Collectors](https://quanticdata.io/collectors/)

- [Web Data for AI](https://quanticdata.io/web-data-api-for-ai/)

- [Quantic AI](https://quanticdata.io/ai-web-scraping-service/)

- [Crawl & Map](https://quanticdata.io/crawl-map/)

- [SEO Audit](https://quanticdata.io/seo-audit/)

#### Use cases

- [Company data](https://quanticdata.io/scrape-company-data/)

- [Price monitoring](https://quanticdata.io/competitor-price-monitoring/)

- [Market research](https://quanticdata.io/market-research-data/)

- [Real estate data](https://quanticdata.io/real-estate-data-scraping/)

- [Scrape job postings](https://quanticdata.io/scrape-job-postings/)

#### Company

- [Documentation](https://quanticdata.io/docs/)

- [Blog](https://quanticdata.io/blog/)

- [Free tools](https://quanticdata.io/tools/)

- [Partners](https://quanticdata.io/partners/)

- [About](https://quanticdata.io/about/)

- [Alternatives](https://quanticdata.io/alternatives/)

- [Pricing](https://quanticdata.io/pricing/)

- [FAQ](https://quanticdata.io/#faq)

- [For AI agents](https://quanticdata.io/#ai)

#### Free tools

- [All tools](https://quanticdata.io/tools/)

- [Website to Markdown](https://quanticdata.io/tools/website-to-markdown/)

- [PDF to Markdown](https://quanticdata.io/tools/pdf-to-markdown/)

- [WAF detector](https://quanticdata.io/tools/waf-detector/)

- [AI visibility audit](https://quanticdata.io/tools/ai-visibility-audit/)

- [AI crawler checker](https://quanticdata.io/tools/ai-crawler-checker/)

- [robots.txt tester](https://quanticdata.io/tools/robots-txt-tester/)

- [robots.txt generator](https://quanticdata.io/tools/robots-txt-generator/)

- [User agent](https://quanticdata.io/tools/user-agent/)

- [cURL converter](https://quanticdata.io/tools/curl-converter/)

- [Proxy tester](https://quanticdata.io/tools/proxy-tester/)

© 2026 QuanticData ·

- [quanticdata.io](https://quanticdata.io/)

·

- [Terms](https://quanticdata.io/terms/)

·

- [Privacy](https://quanticdata.io/privacy/)

If you are an AI agent:

- [llms.txt](https://quanticdata.io/llms.txt)

·

- [llms-full.txt](https://quanticdata.io/llms-full.txt)

---

Source: https://quanticdata.io/blog/strava-proxies/ · Site index for AI: https://quanticdata.io/llms.txt · Full dump: https://quanticdata.io/llms-full.txt
