Contents

Web & Networking › HTTP

User-Agent

The header identifying the client software.

Also known as: User-Agent header, UA string, browser string

The User-Agent header is a string in a request that identifies the client software: the browser, the app or the library making the call.

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
User-Agent: curl/8.5.0
User-Agent: python-requests/2.32.0
User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)

Browser strings are famously messy: nearly every one begins with Mozilla/5.0, for historical compatibility reasons.

What it’s used for

  • Logs and analytics: which browsers and devices visit.
  • Identifying bots and crawlers, to allow, throttle or block them (bot protection).
  • Debugging: “which client sent this request?”
  • Courtesy for API providers, who ask API clients to set a descriptive user agent with contact details.

Why not to depend on it

  • It’s trivially faked. Any client can send any string. Never use it for security decisions.
  • Browser sniffing is fragile: new versions and unknown browsers break rules. Prefer feature detection (feature detection).
  • It’s being reduced. Browsers are freezing parts of the string to limit tracking (fingerprinting), and offer client hints (Sec-CH-UA) as a structured, opt-in alternative.
  • It tells you nothing reliable about the person.

Good practice

  • Set a meaningful User-Agent when your code calls other people’s APIs (my-app/1.2 (contact@example.com)), since some services block empty or default ones.
  • Log it for debugging, but don’t use it to gate functionality.
  • Handle bots: crawlers identify themselves, but bad ones lie, so verify (by reverse DNS) if it matters.
  • Mobile vs desktop: use responsive design and media queries, not user-agent checks (responsive design).

See HTTP headers and requests.