The operational shift here is blunt: instead of running a headless browser through DataDome’s JavaScript challenges, Hyper Solutions’ scraper mints one DataDome session token via a paid sensor API, then hits Hermès’ own bck.hermes.com product API directly for clean JSON — no HTML, no rendering, no image or script overhead. According to The Web Scraping Club, that dropped the cost of scraping Hermès’ entire US catalog to about $1 in residential-proxy bandwidth and roughly €5 in DataDome “sensor calls,” a fraction of what a browser farm would burn pulling the same 7,690 products.
By turning DataDome’s own cookie into a metered line item — 0.22 sensor calls per product at about €3 per 1,000 — Hyper Solutions has effectively priced the antibot vendor’s defense as a cost of doing business rather than a barrier.
The build-versus-buy math is the real story for data teams. Bright Data’s self-serve dataset estimator starts at $500 for up to 200,000 records, per the source; a catalog Hermès’ size sits at the very bottom of that tier, so a team that already runs request-based infrastructure can reproduce and refresh the data indefinitely for single-digit euros instead of paying for a static snapshot. Projected across Hermès’ 39 markets — roughly 280,000 records by the source’s estimate — the all-in cost is still only about $37 in bandwidth and €190 in sensor calls, according to the same measured ratios.
What this doesn’t change is the legal exposure. DataDome exists precisely to gate access behind an authentication-like token, and minting that token through a third-party paid API to defeat it sits closer to the kind of “circumvention of a technical access barrier” theory that has underpinned CFAA and anti-circumvention claims in past scraping disputes — a materially different posture than the public-page scraping at issue in hiQ v. LinkedIn. Publishing the method as an open-source repository, rather than keeping it as a private capability, raises the stakes further: it’s a reproducible playbook any retailer’s legal or security team can now read, and a template plaintiffs’ counsel can point to in describing intent to bypass a known technical protection measure.
Worth watching next is whether Hermès or DataDome respond with a cease-and-desist, a takedown request against the GitHub repo, or a rate-limiting countermeasure that changes the token-minting economics described here — and whether other luxury retailers running DataDome quietly rotate their session-bootstrap logic in response.
We scraped the entire US Hermès catalog straight off its JSON API, behind DataDome, with zero browsers: 7,690 products at 37 KB each, for a few euros.