A user agent string looks like dense, garbled text at first glance, but it's really just a self-reported label the browser attaches to every request — and understanding why it's shaped the way it is explains some genuinely strange-looking quirks, like Chrome technically claiming to be Safari.

Anatomy of a User Agent String

A typical user agent string is built from several space-separated tokens: a product name and version, a parenthesized block describing the platform and rendering details, and then one or more engine and browser tokens. For example, "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0 Safari/537.36" tells you the operating system (Windows 10, 64-bit), the rendering engine family (WebKit-based, behaving like Gecko), and the actual browser (Chrome). Each token exists because, at some point in history, a website somewhere checked for it.

Why It Always Starts With "Mozilla"

This is a leftover from the mid-1990s browser wars. Early websites checked for the token "Mozilla" to decide whether to serve a page's newer HTML features to Netscape Navigator, which called itself Mozilla internally. When Internet Explorer — and every browser released since — wanted access to those same pages, they started including "Mozilla" in their own user agent string too, and the convention simply never went away. It's a fossil, not a meaningful description of the browser you're using today.

Why Chrome's UA Mentions Safari and Gecko

The same compatibility logic explains the rest of the string. Older sites checked for tokens like "Safari" or "like Gecko" to decide what layout or features to serve, so newer browsers kept including those tokens to avoid being mistakenly treated as an unsupported browser. That's why a real Chrome user agent string can honestly contain the words Mozilla, AppleWebKit, KHTML, and Safari, despite Chrome being none of those things in the way the names imply — it's inherited compatibility baggage, layered on for two decades.

Tip: If you're building a website and tempted to branch logic on the user agent string, check whether a feature-detection approach (testing whether the browser actually supports the API you need, e.g. via "someAPI" in window) would work instead — it's more reliable than guessing capabilities from a string that's inherently unreliable and can be spoofed.

Why You Can't Trust It for Security

The user agent string is just an HTTP header the browser voluntarily sends — there's no verification behind it. It can be changed freely through browser developer tools, a browser extension, or any custom HTTP client, so a server has no real way to confirm it's accurate. That makes it fine for optional, low-stakes uses like analytics dashboards or picking a reasonable default layout, but it should never be relied on as a security control or a way to reliably block or allow specific devices.

User-Agent Client Hints

Partly because of privacy concerns around passive fingerprinting, some browsers now support User-Agent Client Hints as an alternative to exposing full device and version details in every single request by default. Instead of broadcasting a detailed string on every page load, a site has to explicitly request specific details (like the exact OS version) through JavaScript, and the browser can choose whether to share them. Over time this is expected to make the classic user agent string itself less detailed, or "frozen," on major browsers — one more reason not to build critical logic around parsing it.

Parsing a User Agent String Instantly

Paste any user agent string — your own or one from a support ticket or server log — into our free User Agent Parser to break it down into browser, engine, operating system, and device details instantly, entirely in your browser.

FAQ

Why do almost all user agent strings start with the word "Mozilla"? It's a historical leftover from the mid-1990s browser wars. Early websites checked for the token "Mozilla" to decide whether to serve a page's newer HTML features to Netscape Navigator. When Internet Explorer and every browser since wanted access to those same pages, they started including "Mozilla" in their own user agent too — and the convention never went away, even though the browser called Mozilla (as in the organization) barely factors into most of them anymore.

Why does Chrome's user agent string mention Safari and Gecko? For the same compatibility reason — older sites checked for tokens like "Safari" or "like Gecko" to decide what features or layout to serve, so newer browsers kept including those tokens to avoid being mistakenly treated as an unsupported browser. This is why a Chrome user agent string can honestly contain the words Mozilla, AppleWebKit, KHTML, and Safari despite Chrome being none of those things in the way the name implies.

Can a website safely trust the user agent for security decisions? No — the user agent string is just a header the browser voluntarily sends, and it can be changed freely through browser developer tools, extensions, or a custom HTTP client, so it should never be treated as a reliable way to authenticate a device or block malicious traffic. It's useful for optional things like analytics or picking a reasonable default layout, not as a security control.

What are User-Agent Client Hints? They're a newer API that some browsers now use instead of exposing full device and version details in every request by default. Rather than passively broadcasting a detailed string on every single page load, a site has to explicitly request specific details (like the exact OS version) through JavaScript, which the browser can then choose to share — reducing how much passive fingerprinting data is sent by default.

Have a user agent string to decode? Try the free User Agent Parser — paste it in and get browser, engine, OS, and device details instantly, no sign-up.