What it is
The User-Agent is a string every browser attaches to every request and exposes to scripts: browser, version, operating system. It is the first thing a server reads and the first thing people try to change.
How websites read it
navigator.userAgent // JavaScript
User-Agent: Mozilla/5.0 (...) // request header — must be identical
navigator.userAgentData?.getHighEntropyValues(['platform', 'uaFullVersion'])The request header and navigator.userAgent should agree. Engines that support User-Agent Client Hints also expose structured identity fields, which should be consistent with the same browser and operating system.
Why it identifies you
On its own the UA is weak — thousands of people share the same string. It matters as an anchor: every other signal on this page is checked against the OS and browser it claims.
How risk-control systems use it
Risk engines compare the header with the JavaScript value, read the JavaScript engine from error-message shapes, and check that Client Hints tell the same story. Modern Chrome also "reduces" its UA (minor versions become 0.0.0), so an unusually precise version is itself a tell.
Common mistakes
Changing the UA with an extension while Client Hints still say the truth; claiming Firefox in a Chromium browser; using a UA whose version the engine features contradict.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
CustomMango supports Chrome / Chromium and Firefox profiles on Windows and macOS. The User-Agent follows the selected engine, version and operating system; Chromium profiles also keep their Client Hints aligned with that identity.
Check yours
Jump to this signal in your scan results.