Toolkit
All tools
String workbench · Free

User Agent Parser

Paste a user agent and get the browser, engine, operating system, and device, or read your own with one click. Then read the string token by token, because most of what a browser says about itself has been false since 1994 and this page tells you which parts.

Parsed in your browser · Nothing uploaded

User agent workspace

Chrome 131.0.0.0 on Windows 10 or 11, rendering with Blink 131.0.0.0. Device type Desktop or laptop. 6 tokens read.

The string

Paste a user agent, or read your own

Everything below recalculates on every keystroke, in this tab. The string is never sent anywhere.

111 / 2,048 characters · 6 tokens

Example loaded: Chrome on Windows. The baseline. Four of the five tokens are historical padding.

What is sending this
Chrome 131.0.0.0

Windows 10 or 11 · Blink 131.0.0.0 · Desktop or laptop

4 carrying information4 historical padding
Browser
Chrome 131.0.0.0
Chrome/131.0.0.0
Engine
Blink 131.0.0.0
AppleWebKit/537.36
Operating system
Windows 10 or 11
Windows NT 10.0
Device type
Desktop or laptop
Windows NT
Vendor and model
Not stated
CPU
x86, 64-bit
Win64; x64
Token by token

Which parts are information, and which are theatre

Products are separated by spaces, platform detail sits inside brackets and is separated by semicolons. Each piece is labelled with what it really says.

  1. Mozilla/5.0Legacy

    Netscape compatibility prefix

    Every mainstream browser still opens with this and none of them are Mozilla. Netscape called itself Mozilla in 1994; Internet Explorer copied the prefix so that servers written for Netscape would serve it the good page; everything since has copied Internet Explorer. The 5.0 has not moved since 1998.

  2. (Windows NT 10.0; Win64; x64)Comment

    Comment block

    Platform detail. Everything a string says about the operating system, the architecture, and the device sits inside brackets like this, separated by semicolons.

    • Windows NT 10.0Real

      Windows kernel version

      Windows 10 and Windows 11 send the same NT 10.0. Nothing in the user agent separates them, which is why Microsoft points at Client Hints platformVersion instead.

    • Win64Real

      Process architecture

      The bitness of the browser build, not of the machine.

    • x64Real

      Process architecture

      The bitness of the browser build, not of the machine.

  3. AppleWebKit/537.36Legacy

    Frozen WebKit build

    Chromium forked WebKit in 2013 and has shipped Blink ever since. 537.36 is the build number at the moment of the fork, kept because sites sniffed for it, and no Chrome release in over a decade has contained that code.

  4. (KHTML, like Gecko)Comment

    Comment block

    Platform detail. Everything a string says about the operating system, the architecture, and the device sits inside brackets like this, separated by semicolons.

    • KHTML, like GeckoLegacy

      Two claims, both false

      WebKit began as a fork of KDE's KHTML, so the first half was a lineage note that stopped being true twenty years ago. The second half was added so that scripts sniffing for Gecko would take the modern path. Chromium is neither, and still sends both.

  5. Chrome/131.0.0.0Real

    Chromium version, reduced

    The major version is genuine. Everything after it was zeroed by UA reduction: Chrome stopped publishing its minor, build, and patch numbers so the string could not be used as a fingerprint. Ask Client Hints for uaFullVersionList if you truly need the rest.

  6. Safari/537.36Legacy

    Safari compatibility claim

    Chrome, Edge, Opera, and every other Chromium browser append this so that server side sniffing written for Safari keeps working. The number matches the frozen AppleWebKit build rather than any Safari that has ever shipped.

Reading

What the rules concluded, and from what

Each row shows the substring it was read from. Anything the string does not state is reported as not stated rather than filled in.

Browser
Chrome/131.0.0.0
Chrome 131.0.0.0
Brave, Arc, and most other Chromium browsers ship this token unchanged and add nothing of their own, deliberately. A Chrome reading therefore means Chrome or something identical to it by design, and no parser can separate them from the string alone.
Layout engine
AppleWebKit/537.36
Blink 131.0.0.0
Chromium forked WebKit in 2013 and the engine has been Blink ever since, so the AppleWebKit number is a fossil. 537.36 has not moved in over a decade and every Chromium browser sends exactly it.
Operating system
Windows NT 10.0
Windows 10 or 11
Windows 10 and Windows 11 both report NT 10.0. Nothing in the user agent separates them. Only the Client Hints platformVersion does, where 13 or higher means Windows 11.
Device
Windows NT
Desktop or laptop
Desktop is the default reading: no phone, tablet, console, or television marker is present. No desktop string states a manufacturer or a model.
Vendor
Not stated
Only Android has ever published a vendor, and only through the model string. Nothing else does.
Model
Not stated
CPU architecture
Win64; x64
x86, 64-bit
Worth knowing

Where this string is lying, frozen, or ambiguous

Every field above is self-reported

A user agent is a string the client chose to send. Changing it takes one setting in developer tools, one flag on curl, or one line in any HTTP library. Nothing here is verified, nothing here is authenticated, and none of it may be used to make a security decision.

Brave, Arc, and most Chromium forks are unidentifiable here

They send the Chrome token unchanged and add nothing of their own. Brave does it deliberately, to shrink the fingerprint surface. Reporting a guess would be worse than reporting Chrome, so Chrome is what this says.

Your browser

What this tab is sending right now

Read from navigator after the page loaded. It is not sent anywhere, and it is not in the page source.

Reading your own user agent needs JavaScript, so it fills in a moment after the page loads. If it stays empty, scripts are blocked in this tab.

navigator.userAgentData

User-Agent Client Hints are the replacement for the string above: structured fields, asked for by name, with the sensitive ones behind an explicit request. Chromium browsers implement it. Safari and Firefox have both declined to.

Checking for support.

Copyable result

The parse as JSON

The shape you would paste into a bug report, with every field the rules filled in and null where they refused to guess.

{
  "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36",
  "browser": {
    "name": "Chrome",
    "version": "131.0.0.0"
  },
  "engine": {
    "name": "Blink",
    "version": "131.0.0.0"
  },
  "os": {
    "name": "Windows",
    "version": "10 or 11"
  },
  "device": {
    "type": "desktop",
    "vendor": null,
    "model": null
  },
  "cpu": {
    "architecture": "x86, 64-bit"
  },
  "agentKind": "browser",
  "bot": null,
  "tokens": [
    {
      "raw": "Mozilla/5.0",
      "kind": "product",
      "truth": "legacy",
      "label": "Netscape compatibility prefix"
    },
    {
      "raw": "(Windows NT 10.0; Win64; x64)",
      "kind": "comment",
      "truth": "real",
      "label": "Comment block"
    },
    {
      "raw": "AppleWebKit/537.36",
      "kind": "product",
      "truth": "legacy",
      "label": "Frozen WebKit build"
    },
    {
      "raw": "(KHTML, like Gecko)",
      "kind": "comment",
      "truth": "legacy",
      "label": "Comment block"
    },
    {
      "raw": "Chrome/131.0.0.0",
      "kind": "product",
      "truth": "real",
      "label": "Chromium version, reduced"
    },
    {
      "raw": "Safari/537.36",
      "kind": "product",
      "truth": "legacy",
      "label": "Safari compatibility claim"
    }
  ]
}
Example library

Real strings, each carrying a different trap

These are the strings that break naive parsers. Load one and watch which token decides the answer.

Desktop browsers

Five strings that are nearly identical, and the small differences that decide the answer.

Phones and tablets

Where the traps live: iOS engines, Android reduction, and an iPad that says Macintosh.

Not a browser at all

Crawlers, a console, and the shortest honest user agent there is.

Never use this for security

A user agent is a string the client chose to send, changed with one setting in developer tools or one flag on curl. It cannot authenticate anything, it cannot gate anything, and it cannot be trusted to tell you a device is what it says.

Do not use it for features either

Ask the browser whether the thing works instead of asking what it is called. CSS.supports, a property check on the object, and @supports all answer the real question, and they keep answering it correctly in browsers that did not exist when the code was written.

The format is being retired

Chrome has already frozen the minor version, the macOS version, and the Android model. Client Hints replaces the string with named fields you request. Anything you build on the old string is building on a number that is being turned off.

Every reading on this page is produced in your browser by a rule table shipped with the page: no string is uploaded, no lookup service is called, and nothing is stored. The guard is stated rather than implied: up to 2,048 characters are read, after which the rest is ignored and the page says so. Where a token matches no rule it is reported as not recognised and shown exactly as it arrived, because a confident wrong vendor is worse than an honest gap.

How it works

A format that has been lying since 1994, read carefully enough to be useful anyway.

A user agent is a stack of compatibility claims left by thirty years of browsers trying to be served the same pages as whoever was winning. Netscape called itself Mozilla; Internet Explorer copied it to get frames; Safari added KHTML and like Gecko; Chrome added AppleWebKit and Safari to be served WebKit pages; Edge, Opera, and Samsung Internet added their own tokens on top of all of Chrome's. Nothing was ever removed, because removing anything broke a server somewhere. This page reads the string with ordered rule tables, so the last claim wins where it should and the first one does not: Edge is not Chrome, Opera is not Chrome, Chrome is not Safari, Chrome on iPhone is WebKit, and Googlebot is not an Android phone. Then it annotates every token, so the two or three pieces that carry information are visible next to the ten that do not. All of it is a rule table shipped with the page and run in your tab: no dependency, no lookup service, and no request.

  1. 01

    Paste a string, or read the one this tab is sending

    Any user agent works: one copied out of a server log, one from a bug report, or your own, which the button reads from navigator after the page has loaded. Fifteen real examples are one click away, chosen because each of them breaks a parser that was written from memory.

  2. 02

    Read the tokens, not only the verdict

    The panel names the browser, engine, operating system, device type, vendor, model, and architecture. The list below it goes through the string piece by piece and says what each one means, which matters because most of a modern user agent means nothing at all.

  3. 03

    Check what the string refused to say before you act on it

    A field marked not stated is a field the string never carried, and a token marked not recognised is one no rule here claims. Both are answers. Where Client Hints can fill the gap, the panel beside your own string shows what they return in this browser.

Built for the cases that break parsers

Ordering, frozen values, and the honest refusal to name a vendor that was never stated.

Ordered rules, because ordering is the whole problem

Edge sends the complete Chrome token and appends Edg at the end. Opera appends OPR. Samsung Internet puts its token before Chrome rather than after. Chrome sends Safari. Every rule table here is read top to bottom and the first match wins, so Edge is Edge, Opera is Opera, and Chrome stops being reported as Safari.

Every token annotated as information or as padding

This is the part other parsers skip, and it is the reason the format is so confusing. Mozilla/5.0 is a Netscape compatibility claim from 1994. AppleWebKit/537.36 is frozen at the moment Chromium forked. KHTML, like Gecko is two claims that are both false. Safari/537.36 on Chrome is a request not to be served the bad page. Each one is labelled where it sits.

The traps handled by name, not by guesswork

Chrome on iPhone is CriOS and is WebKit underneath. Firefox on iPhone is FxiOS and is also WebKit. An iPad in its default mode reports as a Mac. Googlebot's smartphone string contains a whole Chrome user agent. Chrome on Android now reports Android 10 and a model of K from every device on earth. All of them are read correctly and explained where they appear.

Not recognised is a real answer here

Brave and Arc send the Chrome token unchanged and add nothing, deliberately, so they are reported as Chrome with a note rather than guessed at. A token that matches no rule is shown exactly as it arrived. A vendor invented to fill a column is worse than an empty column.

Your own string with Client Hints beside it

One button reads navigator.userAgent, and the panel next to it reads navigator.userAgentData: brands, mobile, platform, and the high entropy values behind them. That is where the real Chrome version, the real Android model, and the Windows build that separates 11 from 10 actually live.

Built in the repository, with no parsing dependency

No ua-parser-js and no lookup service. The tokeniser is one forward pass with no regular expression in it, versions are read by scanning characters from a fixed index, and every rule is a literal string search, so no input can make it backtrack. Input is capped at 2,048 characters and the page says so when it trims.

User agent questions

Why every browser says Mozilla, what Edg means, and why your iPad claims to be a Mac.

What is my user agent?+

It is the line your browser puts in the User-Agent header of every request it makes, describing itself to the server. Press the button in the workspace above and this page reads it out of navigator.userAgent, then breaks it apart. Nothing is uploaded to do that; the reading happens in the tab. A typical one looks like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36, and of those six pieces only two, the platform comment and the Chrome version, tell you anything true. The rest is compatibility sediment that no browser dares remove.

Why does every browser still say Mozilla/5.0?+

Because of one decision in 1994 and thirty years of nobody being able to undo it. Netscape's internal codename was Mozilla and it sent Mozilla/2.0 as its identity. Servers started checking for it before serving frames, which Netscape supported and the competition did not. When Internet Explorer 2 gained frames it could not get the good page, so it sent Mozilla/2.0 (compatible; MSIE 2.0) and was served correctly. Every browser since has copied whoever was winning: Safari added Mozilla and KHTML, Chrome added Mozilla and Safari, Edge added Mozilla and Chrome and Safari. The prefix now means only that the sender is a web browser, and the 5.0 has not moved since 1998. Anyone who drops it finds some server somewhere serving them a 1999 page.

Why does Chrome claim to be Safari?+

For the same reason Internet Explorer claimed to be Netscape. When Chrome launched in 2008 it used WebKit, the engine behind Safari, and a large amount of server side sniffing code was written as if WebKit meant Safari. Sending AppleWebKit and Safari tokens got Chrome the same pages Safari got, so it sent them. In 2013 Chromium forked WebKit into Blink, and it kept sending both tokens anyway, because by then removing them would have broken sites. So AppleWebKit/537.36 is a build number from the moment of the fork and no Chrome release in over a decade has contained that code, while Safari/537.36 is not a Safari that has ever existed. The practical consequence is that a parser must test for Chrome before Safari, or every Chrome user is counted as a Safari user.

What does Edg mean, and why not Edge?+

Edg is Microsoft Edge built on Chromium, which is every Edge since 2020. It is spelled with three letters on purpose. The old Edge sent Edge/18.19041 and a large amount of feature detection code had been written to match the string Edge and treat it as the EdgeHTML browser with its own set of bugs. Shipping a Chromium browser that matched those checks would have handed it EdgeHTML workarounds it did not need, so Microsoft picked a token nothing was already matching. Edge on Android is EdgA and Edge on iOS is EdgiOS, which is a common gap in hand written parsers. In all three cases the token sits after a complete Chrome token, so a parser reading left to right and stopping at the first browser it recognises reports Edge as Chrome.

Why does my iPad say Macintosh?+

Because Apple decided in iPadOS 13 that an iPad should get desktop websites by default, and the way to make that happen was to send the desktop string. Safari on iPad now sends Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) with no iPad token in it, byte for byte identical to Safari on a Mac. There is no way to separate the two from the string, and that is deliberate. If you must know, the tell is in the page rather than the header: navigator.maxTouchPoints returns a number above zero on an iPad claiming to be a Mac, and zero on almost every real Mac. The iPad token only reappears when the user has chosen Request Mobile Website for that site.

Can I trust what a user agent says?+

No, and this is not a caveat, it is the defining property of the format. The string is chosen by the client. Changing it takes one field in the network conditions panel of any browser's developer tools, one -A flag on curl, or one line in any HTTP library. Nothing signs it, nothing verifies it, and nothing about the header travels with any guarantee. It is fine for analytics, where a small share of nonsense does not change the shape of the data, and for choosing a download link, where the worst outcome is the wrong installer. It is never acceptable as an access control, a licence check, a bot defence, or any other security decision. If you need to know that a request really is Googlebot, Google publishes reverse DNS ranges and a JSON list of its addresses for exactly that reason, and verifying against them is the only honest way to treat the claim.

What are User-Agent Client Hints?+

They are the replacement for the whole format. Instead of one string carrying everything whether the site wants it or not, the browser sends three low entropy fields on every request (the brand list, whether it is mobile, and the platform name) and keeps everything else back until a site asks for it by name through the Accept-CH response header or through navigator.userAgentData.getHighEntropyValues in JavaScript. The high entropy values are the useful ones: the full browser version, the platform version, the architecture, the bitness, and the device model. Two details are worth knowing. The brand list deliberately includes one made up brand whose name changes every release, so that code has to parse the list properly rather than matching a single hardcoded name, which is precisely the mistake that made the old string impossible to fix. And support is not universal: Chromium browsers implement it, while Safari and Firefox have both declined to, which is why the old string is still what every browser sends.

What is user agent reduction, and what has it already removed?+

It is Google's staged programme, largely complete since Chrome 110 in 2023, of freezing the parts of the string that made it a fingerprinting surface. Chrome now reports its minor, build, and patch numbers as 0.0.0, so the whole version reads 131.0.0.0 and only the major number is real. On desktop the platform version is pinned to a fixed value. On Android every device reports Android 10 and a model of K, whatever it actually is. Apple got there earlier and by a different route: macOS has reported 10.15.7 since Big Sur because so much sniffing code compared the version numerically and broke on 11, and the word Intel is still sent on Apple Silicon. The effect is that the string is now a much weaker signal than the code reading it usually assumes, and anything that needs the real values has to ask for them through Client Hints.

How do I change or spoof my user agent?+

In Chrome and Edge, open developer tools, use the three dot menu to show More tools then Network conditions, untick Use browser default, and pick or type a string. Firefox exposes general.useragent.override in about:config. Safari has a Develop menu with a User Agent submenu. On the command line it is curl -A on curl and --user-agent on wget, and every HTTP library has an equivalent one line option. The legitimate uses are real: testing that your own site serves the right thing to an old browser, reproducing a bug that only a particular client sees, and checking what a crawler receives. What matters is the inverse. Since changing it is that easy for you, it is exactly that easy for everyone else, so no check you write on the server can assume the string is honest. Spoofing to evade a paywall or a rate limit is a terms of service problem rather than a technical one, and it usually fails anyway because serious systems stopped trusting the header years ago.

Chrome on my iPhone reports as CriOS. Is that really Chrome?+

It is really Chrome's interface, its sync, and its address bar, and it is not Chrome's engine. Apple requires every browser on iOS and iPadOS to render with the system WebKit, so Chrome for iOS, Firefox for iOS, Edge for iOS, and Opera for iOS are all Safari underneath with different shells on top. The tokens are CriOS, FxiOS, EdgiOS, and OPiOS respectively, and each of them sits in a string that also carries AppleWebKit and a Safari build number, which are genuine in this case rather than decorative. The practical consequence for testing is the useful part: a rendering bug reported in Chrome on an iPhone is a WebKit bug, it will reproduce in Safari on the same device, and it will not reproduce in Chrome on any other platform. The European Union's Digital Markets Act has begun to loosen this, but outside that context the rule still holds.

More focused tools, ready when you are.

Explore the growing collection for calculations, documents, writing, and everyday work.

Browse all tools