Skip to main content
QUIETLYTIC
Cybersecurity

User-Agent Parser

Read a User-Agent string, with the token behind every claim and the spoofing tells named.

Local · nothing leaves this browser Waiting for a string
Esc Clear
Reading

Paste a User-Agent string, or use your own.

How it works

Reads a User-Agent into browser, engine, operating system and device, and shows the exact substring each reading came from. The evidence is not decoration. A User-Agent is a string the client chose to send — not a measurement, not authenticated, and changed in one line of code — so a parser that prints a confident answer with no working is telling you about its own guess rather than about the client.

Why the ordering is the whole algorithm

Every major browser still announces itself as Mozilla/5.0. Chrome ships a Safari/537.36 token, Edge ships both a Chrome and a Safari token, and every Chromium fork ships all of them. The tokens accumulated because servers gated features on them, so each new engine adopted its predecessors’ names to avoid being locked out. The only way through is to check the most specific claim first — Edge before Chrome, Chrome before Safari — which is why this page declares its rules in order rather than pattern-matching loosely.

Frozen values are reported as frozen

Chrome’s minor, build and patch digits are pinned at 0.0.0, AppleWebKit/537.36 has been constant for over a decade across engines that share nothing, and Chrome on Android reports the fixed placeholder Android 10; K whatever the device runs. Presenting any of those as a reading would be inventing precision the string does not contain. The detail they used to carry now lives in the Sec-CH-UA client-hint headers, which a server has to request.

What this is actually for

In a log, the useful questions are not which browser. They are whether the string is internally consistent, whether it belongs to a tool rather than a person, and whether anything in it is being used to make a decision it should not be. A string naming two operating systems is almost always hand-edited. A crawler identity proves nothing, since announcing Googlebot costs nothing — only a reverse lookup on the source address followed by a forward lookup on the name it returns settles that. And a scanner’s default string is evidence a scan ran, not that it was unauthorised: an approved assessment produces the same line. For extracting the addresses and domains around it, the IOC Extractor takes the whole log line.

The header is an injection vector into your own tooling

User-Agent values get written to logs, dashboards and databases, very often unescaped, which makes the header a standing path into the systems that watch the application rather than into the application. Where this page flags injection-shaped characters it is saying they are present — not that anything succeeded. What matters next is how the value is stored and rendered downstream.

Example

curl/8.11.1 reads as an automation client and nothing else. A Googlebot string that also carries a Chrome token is classified as a crawler, with the browser claim kept and marked forgeable. Mozilla/5.0 (Windows NT 10.0; Android 14) Chrome/141.0.0.0 claims two platforms at once, which no genuine string does.

Frequently asked questions

Why does Chrome report version 141.0.0.0?

The trailing digits are frozen at 0.0.0 as part of User-Agent reduction, so only the major version is real. The detail that used to live there moved to the Sec-CH-UA client-hint headers, which a server has to ask for. Reading 0.0.0 as a patch level would be reading precision the string does not contain.

Why does every browser say Mozilla/5.0?

Historical sniffing. Early servers gated features on the Mozilla token, so every browser adopted it, then each new engine adopted its predecessors’ tokens for the same reason. That is why Chrome ships Safari/537.36 and Edge ships both — and why parsing order, not pattern matching, is what gets the answer right.

Can I trust a string that says Googlebot?

No. Announcing Googlebot costs nothing. The only reliable check is a reverse DNS lookup on the source address followed by a forward lookup on the name it returns. The string itself proves nothing, which is true of every identity claim in this header.

What does it mean when a string names two operating systems?

Usually a hand-edited or generated string. A genuine one names a single platform; Android and ChromeOS carrying a Linux token is the one legitimate overlap, and this tool does not flag it. Anything beyond that is worth treating as unreliable in full, not just in the part that contradicts.

Why flag angle brackets and ${ in a User-Agent?

Because the header gets written to logs, dashboards and databases, often unescaped, which makes it a standing injection vector into the tooling rather than the application. The finding says the characters are present — not that anything succeeded. What matters is how the value is stored and rendered downstream.

Related tools

From the intelligence desk