Anatomy of a user agent
A UA string is a semicolon-separated list of product tokens. Mozilla/5.0 is a historical compatibility marker (every modern browser claims it), then come the OS and platform tokens, then the browser product with version: Chrome/126.0.0.0, Firefox/127.0, Version/17.5 Safari/605.1.15. Mobile browsers add Mobile, and iOS UAs include like Mac OS X.
Reading the output
- Browser is detected by its product token; Chrome-based browsers (Edge, Opera, Brave) also contain
Chrome/— the parser checks for the specific token first. - OS comes from platform tokens:
Windows NT 10.0= Windows 10/11,Mac OS X,Android,iPhone,X11; Linux. - Device:
Mobile→ phone,iPad→ tablet, otherwise desktop. - Bots usually advertise themselves:
Googlebot,bingbot,GPTBot,Slurp,DuckDuckBot— the parser flags known crawler names.
Caveats
UA strings are spoofable and increasingly simplified (Chrome is phasing down its UA). Treat this as a heuristic, not a security boundary — for serious bot detection, combine with IP reputation and behavioral signals. Batch mode is handy for scanning your access logs: paste 50 lines, get a compact table.