⏱️ Reading time: 17 min
You paste the link of a news article blocked by a paywall into wallhop.io, and within seconds, the full text appears on screen, no account creation, no paying a cent. There’s no magic to it: it’s the same pattern 12ft.io used for years, until media outlets learned to recognize and block it site by site.
📑 En este artículo
- TL;DR
- What Is a Paywall Bypass Tool?
- Why It Matters to Bet on the Technique, Not the Tool
- A Brief History of Paywall Bypassing
- How to Bypass a Paywall: Proxies, Caches, and Fake User-Agents
- Practical Examples with WallHop
- How to Start Using a Paywall Bypass
- Real-World Use Cases
- Common Mistakes and Best Practices
- Comparison with Alternatives
- Going Deeper: The Race Between Detection and Evasion
- Frequently Asked Questions
- References
WallHop offers three ways to use it (adding a slash before the link, a bookmarklet, and an iPhone shortcut) and two endpoints for automation, /raw and /api. What matters isn’t whether WallHop works today, but how it works under the hood: proxies, caches, and spoofed headers, the logic that survives even if the tool of the moment disappears.
TL;DR
- WallHop lets you paste the link of a paywalled article and read it in full without paying.
- A proxy requests the page on your behalf; a cache serves a copy that a search engine already indexed.
- User-agent spoofing makes the server believe the request comes from a bot, not a human.
- 12ft.io lost traction once media outlets started blocking its traffic by IP and headers.
- Combining a proxy, a cache, and spoofing is more reliable than depending on a single tool like WallHop.
What Is a Paywall Bypass Tool?
A paywall bypass tool is a web service that lets you get around a news article’s paywall by reconstructing its public version, using proxies, search engine caches, or spoofed HTTP headers, without creating an account, without paying the original outlet, and without revealing the reader’s real IP address.
WallHop, just like its predecessor 12ft.io, doesn’t invent content or break any encryption: it asks the outlet’s server for the same page a search engine would see, which almost always gets through the paywall because the outlet needs Google to read the full article in order to index it. The tool just automates that request and hands you the result.
That’s why none of these tools need to exploit anything: the outlet’s server already decides, case by case, to show the full content to certain visitors. The whole trick consists of qualifying as one of those visitors.
Why It Matters to Bet on the Technique, Not the Tool
The case of 12ft.io is the cautionary tale. For years it was the simplest way to bypass a paywall: you pasted the link and the site showed an overlay window with the article, no payment required. It started as a universal trick and ended up as an ever-growing list of exceptions, because every outlet that detected its traffic (by User-Agent, by Referer, or directly by its servers’ IP) blocked it individually. Today 12ft.io no longer works reliably with a good portion of the major sites.
WallHop solves the same problem with a different implementation: a new domain, /raw and /api endpoints designed to integrate into scripts, and a bookmarklet that avoids typing the full URL by hand. But the underlying logic (proxying the request, pretending to be a different client) is the same one 12ft.io used. If WallHop grows enough for media outlets to notice its traffic, the outcome could repeat itself: site-by-site blocks until the success rate drops.
⚠️ Heads up: WallHop’s own page warns about this: “Paywalls pay for journalism. If there’s a paper or news site you read every day, please subscribe to it.” The tool is meant for the one-off article someone sent you in a chat, not to replace a subscription that sustains a newsroom.
A Brief History of Paywall Bypassing
The trick didn’t start with WallHop or 12ft.io. For years, Google had a cache: search operator that showed its own indexed copy of any page, including many paywalled ones, until it removed it from results in 2024. While it existed, it was the simplest way to get around a paywall without even touching the original site.
After that came a generation of sites that directly reformatted the article, stripping the paywall with an overlay reading layer, the same concept that made 12ft.io popular starting in 2019. They worked well until media outlets started filtering that specific traffic, first with manual per-domain rules and later with third-party anti-bot protection services.
In parallel, archive.today (also known as archive.ph) took a different path: instead of proxying in real time, it stores permanent copies of pages that anyone can request to have archived, just once. That copy stays public forever, without depending on the service actively dodging blocks.
WallHop is the latest turn of that cycle: the same proxy pattern as 12ft.io, with a domain that has no history of blocks yet. The question worth asking isn’t whether WallHop will last, but which specific technique it uses, because that’s what you’ll need when WallHop, sooner or later, faces the same wear and tear.
How to Bypass a Paywall: Proxies, Caches, and Fake User-Agents
Behind any paywall bypass there are, generally, three families of techniques. None of them exploits a vulnerability: all of them take advantage of the fact that the outlet’s server decides what to show based on who appears to be asking.
Proxies: Requesting the Page on Someone Else’s Behalf
A proxy is an intermediary that makes the HTTP request instead of the reader’s browser. WallHop works this way when you use the / prefix in front of any URL: it’s WallHop’s server that actually contacts the outlet, not your browser. To the outlet, the visit appears to come from WallHop’s infrastructure, with its own IP and its own headers, not the reader’s residential IP.
This matters because many “soft” paywalls (the kind that count free articles per month with a cookie) only block by IP or browser history. A proxy that has never visited the site before starts that counter at zero every time, even if the actual reader has already used up their quota.
Caches: Reading the Copy That Already Exists
A cache doesn’t ask the outlet for anything in the moment: it serves a copy that someone else (a search engine, an archiver, another reader) already saved earlier. archive.today is the best-known example: anyone can archive a URL just once, and from then on, that copy stays public forever, even if the outlet later blocks all direct access or takes down the original article.
A cache’s advantage over a proxy is permanence: it doesn’t matter whether WallHop is still online next year, the archived copy doesn’t depend on any active service. The downside is that someone has to have created it beforehand; if nobody archived that URL, there’s nothing to read.
User-Agent Spoofing: Pretending to Be a Different Client
Every HTTP request carries a User-Agent header that states, in theory, which browser or program is asking. Many paywalls check that header (and sometimes the Referer) to decide whether the visitor is an indexing bot, which should be shown everything, or a person, who should be charged. Changing that header to look like Googlebot instead of a regular browser is what’s known as user-agent spoofing.
import requests
headers = {
"User-Agent": "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
}
resp = requests.get("https://www.unperiodico.com/articulo-con-paywall", headers=headers)
print(resp.status_code, len(resp.text))
This script requests the page while pretending to be Google’s indexing bot (replace the URL with the real article you want to test). If the outlet follows the common practice of showing everything to Googlebot to avoid losing search rankings, the response carries the article’s full HTML; if the outlet also filters by IP, the request returns the same block any reader without a subscription would see.
flowchart TD
A["The reader pastes the article link"] --> B["The tool chooses the method"]
B --> C["Proxy: requests the page on the reader's behalf"]
B --> D["Cache: serves an already-indexed copy"]
B --> E["Fake User-Agent: pretends to be a bot"]
C --> F["The outlet delivers the full HTML"]
D --> F
E --> F
F --> G["The reader reads the article without the paywall"]
Practical Examples with WallHop
WallHop exposes the same proxy logic in three different ways, designed for different needs.
The simplest one is the prefix: adding a / slash before any full URL. Pasting https://wallhop.io/https://www.unperiodico.com/articulo-con-paywall into the address bar makes WallHop request that page and hand you back the result inside its own interface, with its buttons and header on top.
The two endpoints designed to integrate into another program are /raw and /api. The first one returns the article’s HTML directly, without WallHop’s interface on top:
curl "https://wallhop.io/raw/https://www.unperiodico.com/articulo-con-paywall"
The expected result is the article’s complete HTML document (the <article> tags, the body text, the images), just as if you had opened the page with an active subscription. The second endpoint, /api, follows the same pattern but is designed to return the content already extracted instead of raw HTML, useful if you’re going to display the text in another application instead of a browser.
There’s also a bookmarklet and an iPhone shortcut that do the same thing with a single click: they take the URL you’re looking at and forward it to WallHop with the corresponding prefix. An equivalent bookmarklet, following the same pattern, is as simple as this:
javascript:location.href='https://wallhop.io//'+location.href;
Clicking that bookmark while on the blocked page makes the browser replace the current URL with the WallHop version of that same address. It’s the same prefix trick, just automated so you don’t have to copy and paste anything.
💡 Tip: if you need to check several URLs in a row, the/rawendpoint is more convenient than the web interface because you can drop it straight into acurlcommand or the Python script from the previous section, chaining one request per link.
How to Start Using a Paywall Bypass
You don’t need to install anything to bypass a paywall: everything runs in the browser or in a single terminal line.
- Copy the full URL of the blocked article, including
https://. - Paste it after
https://wallhop.io/in the address bar (a single slash separates the URL that follows). - If you prefer the terminal, run
curl "https://wallhop.io/https://www.unperiodico.com/articulo-con-paywall", swapping that last URL for the real article you want to read. - If the article is still blocked, try searching for that same URL on archive.today: someone may have already archived it.
Real-World Use Cases
The case WallHop itself describes on its page is specific: someone sends you the link to a story from a paper you’ll never subscribe to, and you want to bypass the paywall to read it just once. In that case, a one-off proxy makes sense, while setting up a trial account or paying for a full month to read a single article doesn’t.
Another typical case is a researcher or journalist who needs to review dozens of articles from different outlets for a one-off report, without the budget to subscribe to each one. There, the /api endpoint or a script with user-agent spoofing handles the volume better than opening tab after tab.
The third case is archiving: when a source important to an investigation might disappear or move, running the URL through archive.today before that happens preserves the evidence even if the original outlet deletes it or later moves it behind a stricter paywall.
The fourth case is the fact-checker or lawyer who needs to confirm the exact wording of a story quoted in another outlet, without that implying regular consumption of that outlet or justifying a full subscription for a single one-off check.
Common Mistakes and Best Practices
- Assuming a paywall bypass tool will work forever. Media outlets adjust their blocking rules frequently; what gets through without a problem today could be blocked next week.
- Depending on a single route. If WallHop fails with a particular site, trying archive.today or a custom script with a different header usually solves the same case.
- Using it for the outlet you read every day. An anti-paywall tool is meant for the one-off article, not to replace a subscription you pay for because you read that outlet regularly: doing so directly cuts off income from the newsroom that wrote the story.
- Ignoring that some paywalls are “hard.” A paywall that never delivers the full HTML to the server, because the content loads only after validating the reader’s session, can’t be bypassed with any proxy or cache: there’s nothing to extract there.
- Confusing a block with an error. An HTTP 403 or 451 status code when using a proxy almost always means the outlet detected the proxy’s IP or User-Agent, not that the article doesn’t exist.
Comparison with Alternatives
None of these options is superior in every case; each one fails in a different way, so it’s worth choosing based on the specific situation.
| Option | When to Use It | Advantage | Limitation |
|---|---|---|---|
| WallHop (URL-prefix proxy) | A one-off article you won’t read again | Requires no installation | Depends on the outlet not blocking its IP or User-Agent |
| archive.today | When someone has already archived that URL | Permanent copy, doesn’t depend on WallHop staying online | If nobody archived it before, the copy doesn’t exist |
| Custom script with a fake User-Agent | Automating many URLs at once | Full control over headers and retries | Needs ongoing maintenance since every outlet changes its detection |
| Browser reader mode | Soft paywalls that only hide content with CSS or JavaScript | Stays in the browser, no extra request | Doesn’t work if the server never delivers the full HTML |
Going Deeper: The Race Between Detection and Evasion
On the outlet’s side, blocking a proxy like WallHop isn’t as simple as banning an IP. Modern proxies rotate addresses, so many paywalls combine several signals at once: the User-Agent header, the Referer header (where the click came from), the absence of previous cookies typical of a real browser, and in some cases, TLS connection fingerprints that reveal whether the request comes from a library like Python’s requests instead of a real browser.
This explains why the user-agent spoofing script from the previous section doesn’t always work: changing a single header fools a simple paywall, but not one that cross-references several signals at once. That’s where a proxy like WallHop has an edge over a homemade script, because it operates at a larger scale and can adjust its entire infrastructure (rotating IPs, varying full headers) faster than an individual developer maintaining their own script.
Third-party anti-bot protection services also exist, which major outlets hire specifically to filter this kind of traffic, evaluating behavioral patterns beyond isolated headers: how many pages the same client requests per minute, in what order, with what pauses between one request and the next. A proxy serving thousands of different users generates traffic patterns very different from those of a human reader, and that difference is exactly what these services look for.
On the other side, paywall bypass tools tend to rely on a structural asymmetry: it’s in the outlet’s interest for Google to index the full article, because a large share of its search traffic comes from there. As long as that indexing need exists, a complete version of every article will keep being served to some kind of automated client, and that, fundamentally, is the crack that any attempt to get around a paywall exploits. Closing it entirely would mean the outlet stops showing up in search engines, something almost no editor is willing to accept.
sequenceDiagram
participant L as Reader
participant W as WallHop
participant M as News outlet
L->>W: pastes the article URL
W->>M: requests the page with a different header
M-->>W: responds with the full HTML
W-->>L: shows the article without the paywall
Note over L,W: the reader's session never touches the original outlet
Your next step: try WallHop’s /raw endpoint with a real article you have blocked right now and compare the result with pasting that same URL into archive.today.
Frequently Asked Questions
Is WallHop Legal?
It depends on the jurisdiction and the outlet’s terms of use, which usually explicitly prohibit bypassing the paywall. WallHop doesn’t publish someone else’s content: it forwards an HTTP request, something technically similar to what any search engine does. That doesn’t eliminate the conflict with the outlet’s terms of service, which may well consider it a contractual violation even if it isn’t a crime.
Why Could a Paywall Evader Like WallHop End Up Blocked Just Like 12ft.io?
Because the simplest defense for an outlet is the same in both cases: identify the proxy’s traffic (by IP, User-Agent, or request patterns) and deny it the full response. The more readers use the same tool, the easier it is for the outlet to recognize its fingerprint and block it.
What’s the Difference Between a Proxy and a Cache in a Paywall Bypass?
The proxy requests the page from the outlet in real time, every time someone uses it; the cache serves a copy that was already saved earlier, without touching the outlet again. That’s why a cache like archive.today keeps working even if the outlet later blocks every known proxy.
Does User-Agent Spoofing Work With Any Outlet?
No. It works with paywalls that only check that header to decide whether the visitor is an indexing bot. Outlets that combine the User-Agent with the IP, cookie history, or more advanced connection fingerprints can’t be bypassed by changing a single header.
Is There a Legal Alternative to a Paywall Bypass?
Yes: most outlets offer digital subscription plans, and many public libraries provide free access to press databases with a library card. For occasional use, those routes completely avoid the legal gray area of a paywall evader.
References
- WallHop: the service’s official page, with the /raw, /api endpoints and the bookmarklet described in this article.
- archive.today: a public archiving service that stores permanent copies of pages, many of them paywalled.
- Wikipedia: Paywall: definition and historical context of the subscription model in digital media.
- MDN: User-Agent header: official documentation of the HTTP header that identifies the client to the server.
📱 Enjoy this content? Follow @programacion on Telegram for daily tech content in Spanish: quick summaries, fresh content every day.
Featured image: Foto de Gene Gallin en Unsplash
Did it work for you? Got a different error? Say so below: questions get answered and help the next reader.
Leave a comment
0 Comments