All articles Advanced signals

User-Agent Client Hints (UA-CH): What Replaces the User-Agent String

The user-agent string is being dismantled, and User-Agent Client Hints are taking its place. If your fraud or analytics stack still parses the legacy string, it is reading a signal that Chromium deliberately freezes and that spoofers rewrite in seconds.

Why Client Hints exist

The classic user agent grew into a bloated, everything-string that leaked more than necessary and was still trivial to forge. Chromium’s answer is UA-CH: a system where the browser sends a minimal set of hints by default and reveals detailed ones only when a site asks. This reduces passive fingerprinting while giving legitimate sites a structured, harder-to-fake way to learn about the client.

The frozen legacy string still exists for compatibility, but its meaningful details are increasingly parked in Client Hints.

Low-entropy versus high-entropy hints

UA-CH splits data by sensitivity. Low-entropy hints are sent automatically because they leak little:

  • Sec-CH-UA (brand and major version list)
  • Sec-CH-UA-Mobile (a boolean)
  • Sec-CH-UA-Platform (operating system name)

High-entropy hints must be requested explicitly, either by responding with an Accept-CH header or by calling navigator.userAgentData.getHighEntropyValues():

  • platformVersion
  • architecture and bitness
  • model (device model on mobile)
  • fullVersionList (exact browser versions)
  • uaFullVersion

Requesting only what you need is the privacy-conscious default, and Prynt requests high-entropy values judiciously rather than vacuuming everything.

GREASE and why odd brands appear

If you inspect Sec-CH-UA, you will see a nonsense brand such as Not.A/Brand alongside the real ones. This is GREASE, a deliberate anti-ossification trick. By injecting a random, meaningless brand, Chromium forces servers to parse the list flexibly instead of hard-coding assumptions. A parser that chokes on the fake brand is a broken parser.

For detection, GREASE is also a subtle authenticity check. The exact format and rotation of these tokens follow Chromium’s implementation. A crude spoof that omits GREASE or formats it wrong reveals itself.

Detecting spoofed browsers with UA-CH

The strongest use of Client Hints is cross-surface consistency. The same facts now appear in three places: the frozen user-agent string, the Sec-CH-UA headers, and the JavaScript userAgentData object. On a genuine browser they agree. On a spoofed one they often do not.

Prynt checks that:

  • The legacy user agent’s browser and platform match Sec-CH-UA and Sec-CH-UA-Platform.
  • Sec-CH-UA-Mobile agrees with the platform and with touch and screen signals.
  • The high-entropy platformVersion and architecture are plausible for the claimed OS.
  • GREASE tokens are present and well formed.

An automation stack that patches navigator.userAgent but forgets userAgentData, or sets a desktop platform while Sec-CH-UA-Mobile says ?1, gets caught by the contradiction. Because Prynt reasons across the header and the JavaScript API together on the server, patching one surface is not enough for an attacker to pass. Our documentation covers how to forward these headers correctly through your CDN so the hints reach our API intact.

A migration note

Two practical gotchas trip teams up. First, high-entropy hints require an explicit round trip: the first request will not carry them unless you send Accept-CH. Second, non-Chromium browsers implement UA-CH differently or not at all, so absence of userAgentData is itself informative rather than an error. Firefox and Safari still lean on the traditional string, and Prynt treats that difference as a signal rather than a gap.

Analytics and detection both benefit

The migration to UA-CH is not only a detection story; it also cleans up analytics. Because high-entropy hints deliver structured fields like exact browser version and platform version, you no longer parse a brittle string with regular expressions that break on each release. That structure makes version-based routing, feature gating, and compatibility decisions more reliable. For fraud teams the same structure pays off differently: a well-formed set of hints that all agree is a small positive signal, while a request that supplies a rich legacy user agent but a suspiciously bare userAgentData object suggests a tool that populated one surface and neglected the other. Prynt reads both the analytics value and the authenticity value from the same hints, so a single collection path serves product and risk teams at once.

Recommendations

  • Stop trusting the legacy user-agent string as a primary source; treat it as one surface among three.
  • Request only the high-entropy hints you actually need.
  • Validate GREASE tokens and cross-check every hint against screen, touch, and platform signals.
  • Ensure your CDN and proxies forward Sec-CH-UA headers so server-side checks see the full picture.

User-Agent Client Hints are not a privacy silver bullet, but they do change the game: spoofing now means keeping several structured surfaces consistent, and inconsistency is exactly what good device intelligence is built to find.

Start free and let Prynt validate Client Hints for you. Compare tiers on the pricing page.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading