User-Agent Parser
Read a User-Agent string, with the token behind every claim and the spoofing tells named.
Paste a User-Agent string, or use your own.
How it works
Reads a User-Agent into browser, engine, operating system and device, and shows the exact substring each reading came from. The evidence is not decoration. A User-Agent is a string the client chose to send — not a measurement, not authenticated, and changed in one line of code — so a parser that prints a confident answer with no working is telling you about its own guess rather than about the client.
Why the ordering is the whole algorithm
Every major browser still announces itself as Mozilla/5.0. Chrome ships a Safari/537.36
token, Edge ships both a Chrome and a Safari token, and every Chromium fork ships all of them. The tokens
accumulated because servers gated features on them, so each new engine adopted its predecessors’ names to avoid
being locked out. The only way through is to check the most specific claim first — Edge before Chrome, Chrome
before Safari — which is why this page declares its rules in order rather than pattern-matching loosely.
Frozen values are reported as frozen
Chrome’s minor, build and patch digits are pinned at 0.0.0, AppleWebKit/537.36 has been
constant for over a decade across engines that share nothing, and Chrome on Android reports the fixed placeholder
Android 10; K whatever the device runs. Presenting any of those as a reading would be inventing
precision the string does not contain. The detail they used to carry now lives in the
Sec-CH-UA client-hint headers, which a server has to request.
What this is actually for
In a log, the useful questions are not which browser. They are whether the string is internally consistent, whether it belongs to a tool rather than a person, and whether anything in it is being used to make a decision it should not be. A string naming two operating systems is almost always hand-edited. A crawler identity proves nothing, since announcing Googlebot costs nothing — only a reverse lookup on the source address followed by a forward lookup on the name it returns settles that. And a scanner’s default string is evidence a scan ran, not that it was unauthorised: an approved assessment produces the same line. For extracting the addresses and domains around it, the IOC Extractor takes the whole log line.
The header is an injection vector into your own tooling
User-Agent values get written to logs, dashboards and databases, very often unescaped, which makes the header a standing path into the systems that watch the application rather than into the application. Where this page flags injection-shaped characters it is saying they are present — not that anything succeeded. What matters next is how the value is stored and rendered downstream.
Example
curl/8.11.1 reads as an automation client and nothing else. A Googlebot string that also carries a
Chrome token is classified as a crawler, with the browser claim kept and marked forgeable.
Mozilla/5.0 (Windows NT 10.0; Android 14) Chrome/141.0.0.0 claims two platforms at once, which no
genuine string does.
Frequently asked questions
Why does Chrome report version 141.0.0.0?
The trailing digits are frozen at 0.0.0 as part of User-Agent reduction, so only the major version is real. The detail that used to live there moved to the Sec-CH-UA client-hint headers, which a server has to ask for. Reading 0.0.0 as a patch level would be reading precision the string does not contain.
Why does every browser say Mozilla/5.0?
Historical sniffing. Early servers gated features on the Mozilla token, so every browser adopted it, then each new engine adopted its predecessors’ tokens for the same reason. That is why Chrome ships Safari/537.36 and Edge ships both — and why parsing order, not pattern matching, is what gets the answer right.
Can I trust a string that says Googlebot?
No. Announcing Googlebot costs nothing. The only reliable check is a reverse DNS lookup on the source address followed by a forward lookup on the name it returns. The string itself proves nothing, which is true of every identity claim in this header.
What does it mean when a string names two operating systems?
Usually a hand-edited or generated string. A genuine one names a single platform; Android and ChromeOS carrying a Linux token is the one legitimate overlap, and this tool does not flag it. Anything beyond that is worth treating as unreliable in full, not just in the part that contradicts.
Why flag angle brackets and ${ in a User-Agent?
Because the header gets written to logs, dashboards and databases, often unescaped, which makes it a standing injection vector into the tooling rather than the application. The finding says the characters are present — not that anything succeeded. What matters is how the value is stored and rendered downstream.
Related tools
Email Header Analyzer
Read a raw email header as an ordered delivery path with authentication results.
LocalSecurity Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
LocalIOC Extractor
Pull indicators of compromise out of any block of text, log or report.
LocalSRI Hash Generator
Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.
LocalCSP Generator
Build a Content-Security-Policy header directive by directive, not by editing a string.
LocalPermissions-Policy Builder
Turn on, off or origin-scope a browser feature per directive, then copy the header.
Local