Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

User-Agent & Client Hints Dissector

Analyze browser UA strings, frozen platform tokens, search bot signatures, and modern W3C Sec-CH-UA Client Hints.

Detected Browser
--
Operating System
--
Client Type
--

Client Hints (navigator.userAgentData) Status

Shannon Entropy & User-Agent Reduction Formulations

The W3C and Chromium User-Agent Reduction initiative was engineered to systematically compress passive fingerprinting entropy:

1. Shannon Entropy of User-Agent Fingerprint:
  H(X) = -Σi=1n P(xi) · log2 P(xi)
  Legacy UA Strings: H(X) ≈ 35 - 42 bits (identifying 1 in 34 billion users).
  Modern Frozen UA: H(X) ≤ 9.5 bits (identifying at most 1 in 724 users without explicit permission).
2. GREASE Injection Brand Generation:
  Chrome injects arbitrary pseudorandom ASCII brands into navigator.userAgentData.brands to prevent vendor lock-in.

5 Fatal Traps in User-Agent & Client Hints Engineering

1. Inaccurate Windows 11 Detection via Frozen UA Tokens Chromium intentionally frozen the platform token to Windows NT 10.0 on all Windows 11 machines. Codebases using regex like /Windows NT 11/ will never match a single Windows 11 user on Earth. Detecting Windows 11 requires requesting the high-entropy Sec-CH-UA-Platform-Version Client Hint, where a major version ≥ 13 corresponds to Windows 11.
2. Brittle Whitelist Parsers Failing on GREASE Brands Chromium regularly injects randomized GREASE brands (e.g. "Not=A?Brand";v="24") into Sec-CH-UA headers. Parsers that strictly validate brands against rigid static lists or assert that all brands must be recognizable will crash or fail requests for legitimate Chrome users.
3. Naive "Safari" Substring Matching in Chrome UA Chrome's desktop User-Agent string includes the token Safari/537.36 for legacy compatibility. Any naive inspection doing navigator.userAgent.includes('Safari') without checking for Chrome first will falsely categorize every single Google Chrome user as running Apple Safari.
4. Missing Accept-CH Server Headers for High-Entropy Hints Browsers never send detailed client hints (such as Sec-CH-UA-Model or exact device hardware specs) by default. The server must explicitly respond with an Accept-CH: Sec-CH-UA-Model, Sec-CH-UA-Platform-Version header. Furthermore, cross-origin iframes cannot access these hints without an explicit Permissions-Policy delegation.
5. User-Agent Cloaking Triggering Googlebot Cloaking Penalties Serving radically different DOM trees, styling, or link graphs to crawlers based on detecting Googlebot or Bingbot in the User-Agent violates Google Search Essentials guidelines against Cloaking, resulting in immediate algorithmic or manual demotion from search indexes.

Frequently Asked Technical Questions

Why are browsers replacing User-Agent with Client Hints?+
Legacy User-Agent strings were historically bloated with arbitrary tokens and easily exploited for cross-site browser fingerprinting. The W3C Client Hints standard shares device details only on demand via granular Sec-CH-UA headers.
How does this tool detect search bots?+
It matches incoming signatures against official crawler token dictionaries including Googlebot, Bingbot, Applebot, GPTBot, and ClaudeBot.
What does GREASE stand for in Sec-CH-UA brands?+
GREASE stands for Generate Random Extensions And Sustain Extensibility. Chrome injects randomized dummy brands (e.g. "Not A;Brand", "Chromium") to prevent web servers from building brittle hardcoded browser whitelists.
Why does Windows 11 report Windows NT 10.0 in the User-Agent?+
Under the User-Agent Reduction initiative, major browser engines froze the platform token to Windows NT 10.0 for all Windows 10 and Windows 11 devices to eliminate fingerprinting entropy. To detect Windows 11, servers must query the Sec-CH-UA-Platform-Version client hint (where version ≥ 13.0.0 represents Windows 11).
How can my backend server request high-entropy Client Hints?+
The server must send the Accept-CH HTTP response header listing desired hints (e.g. Accept-CH: Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List). Cross-origin iframes additionally require explicit delegation via the Permissions-Policy header.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement