noUA / knowUA

User-Agent is metadata.
It is not identity.

Meme text: 'How do you do, fellow python-requests/*'
Authentication, according to vibes.

What is User-Agent?

A User-Agent header is text supplied by the client making the HTTP request.

The important bit: the client writes it.

That means the client can also change it.

curl https://example.com \
  -H 'User-Agent: Mozilla/5.0 (Definitely A Managed Corporate Browser)'

Congratulations.
You are now a managed corporate browser.

What User-Agent can be useful for

What it does not prove

What User-Agent must not be treated as by itself

Ask the useful question

Instead of asking, What does the User-Agent say?, ask:

What security property proves that this request came from the client we think it did?

Depending on the property you need to establish, use a stronger mechanism such as cryptographic authentication, mTLS, signed requests, workload identity, device attestation, application attestation, token binding / sender-constrained credentials (where available), and server-side authorization based on authenticated identity.

These are not interchangeable controls; choose based on the property you are actually trying to prove.

A User-Agent can be a signal.
A signal is not automatically a control.
A control is not automatically a security boundary.

Tiny demo: what this browser reports

This is intentionally local-only. It is displayed in your browser and not sent anywhere by this site.

JavaScript is disabled, so this demo is hidden. The core point of this site does not depend on JavaScript.

Seeing a User-Agent value does not make it trustworthy.

Privacy

This site does not intentionally collect visitor data, run analytics, fingerprint browsers, or transmit the displayed User-Agent anywhere.

Hosting providers may still generate their own operational logs.