Loading network utility...
Loading network utility...
Understand why browser User-Agent strings look strange, how layout engines are identified, and how modern Client Hints protect privacy against fingerprinting.
Run live checks and calculations directly on LotsofNetwork.
Every HTTP request sent by a browser includes a 'User-Agent' header. Because early web servers in the 1990s looked specifically for Netscape Navigator ('Mozilla') to enable advanced capabilities, competitors like Microsoft Internet Explorer spoofed 'Mozilla/4.0 (compatible; MSIE)' to prevent being locked out.
This pattern repeated for decades: Safari claimed compatibility with Mozilla and KHTML, and Chrome claimed compatibility with Safari and Mozilla. Today, every major browser string begins with 'Mozilla/5.0' followed by tokens for WebKit, Chrome, and Safari.
Legacy User-Agent strings exposed precise OS versions, CPU architectures, and device models on every single request, enabling advertisers and trackers to passively fingerprint users across the web without consent.
To combat this, the W3C and Chromium introduced User-Agent Client Hints. Instead of sending detailed hardware specs by default, browsers only send low-entropy hints (major browser version, brand, mobile flag). Servers must explicitly request high-entropy hints (architecture, full OS build, model) via the 'Accept-CH' response header.
| Header Name | Entropy Level | Example Value | Description |
|---|---|---|---|
| Sec-CH-UA | Low | "Chromium";v="128", "Google Chrome";v="128" | Browser brand and major version |
| Sec-CH-UA-Mobile | Low | ?0 (Desktop) or ?1 (Mobile) | Boolean form-factor flag |
| Sec-CH-UA-Platform | Low | "macOS" or "Windows" | Primary operating system name |
| Sec-CH-UA-Arch | High | "arm" or "x86" | CPU architecture instruction set |
| Sec-CH-UA-Model | High | "Pixel 8 Pro" or "SM-S918B" | Precise mobile hardware model |
Modern web applications should avoid brittle regex matching on the User-Agent string whenever possible. Follow these engineering guidelines:
1. Use Feature Detection First: Check for API support (e.g. 'if ("geolocation" in navigator)') rather than sniffing user agent strings.
2. Support Client Hints: Inspect 'Sec-CH-UA' headers on modern requests and keep User-Agent parsing as a fallback for legacy clients.
3. Never Trust UA for Security: UA headers can be forged in seconds using cURL or Postman; never authenticate or authorize users based on browser strings.
Use the LotsofNetwork User Agent Analyzer to inspect your browser's live telemetry, test custom strings, or verify crawler tokens for Googlebot and Bingbot.
Quick answers to common questions on this topic.
High-speed, zero-cost engineering tools built for network diagnostics and developer workflows.
Beautify, minify, validate & inspect JSON tree
Encode & decode text, files, and images
Unix epoch to date & global timezone converter
UUID v4 & UUID v7 generator & timestamp decoder
Convert cURL commands to 7 languages instantly
Calculate octal, symbolic, and special Linux permissions