Programa de referidos →
InicioGlosarioUser-Agent
Glosario

User-Agent

Una cabecera HTTP que identifica el navegador, la versión y el sistema operativo que hace la solicitud.

Un User-Agent es la cadena que tu cliente envía en la cabecera HTTP User-Agent para identificarse: su navegador, versión, motor de renderizado y sistema operativo. Un Chrome real en Windows envía algo como "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ... Chrome/120.0". Los servidores lo leen para decidir qué contenido y formato devolver.

Para el scraping, el user-agent es un punto de detección común. Las librerías HTTP por defecto envían user-agents de bot evidentes (p. ej. "python-requests/2.31"), que los sistemas antibot marcan al instante. Enviar un user-agent de navegador realista es un requisito básico para no ser bloqueado de inmediato.

Más allá de establecer un solo valor realista, rotar los user-agents entre solicitudes ayuda a que el tráfico parezca de muchos usuarios distintos. Pero el user-agent debe ser coherente con el resto de la solicitud - afirmar que eres Chrome mientras envías cabeceras o una huella TLS que Chrome nunca enviaría es una señal de alarma que los sistemas sofisticados detectan.

El user-agent es una señal entre muchas. Combina un user-agent realista y rotado con cabeceras Accept y Accept-Language coincidentes, una huella TLS coherente e IPs rotativas. Falsear solo el user-agent, mientras todo lo demás grita "bot", no te llevará lejos frente a las defensas antibot modernas.

A string that has to agree with everything else

The User-Agent header is a self-reported description of your browser and operating system. It is trivially editable, which is why no serious anti-bot system trusts it on its own. What those systems do instead is check whether it agrees with everything they can measure independently.

The list of independent measurements is long. The TLS handshake produces a fingerprint that differs between Chrome, Firefox and a Python library. The order of your HTTP headers differs between real browsers and most automation tools. JavaScript exposes the screen size, the platform, the font list, the number of CPU cores and the graphics renderer. The TCP stack itself has an operating-system flavour.

A request claiming to be Chrome on Windows while presenting a Python TLS fingerprint, sending headers in the wrong order and reporting a Linux platform in JavaScript is not a browser. Sites do not need to guess. The contradiction is arithmetic.

This is why changing the User-Agent alone almost never helps, and occasionally hurts: a mismatched string turns a consistent automated client into an inconsistent one, which is the pattern detection systems are actually built to find.

Where the proxy fits into fingerprint consistency

The address is one signal among many, and it has to agree with the others. On mobile modems you can also align the network stack:

Set the modem fingerprint to match the profile

# Supported values on our mobile modems:
android:1   android:3
ios:1       ios:2
macosx:3    macosx:4
windows:1

# An iPhone profile behind a modem announcing Windows
# contradicts itself before any script runs.
  • Match the proxy country to the profile locale and timezone. A US address with a Warsaw timezone is a contradiction visible in one line of JavaScript.
  • On mobile, set the OS fingerprint when you create the profile and leave it. Changing it later looks like the device was replaced overnight.
  • Let your antidetect browser generate the User-Agent rather than typing one. Hand-written strings drift out of date and stop matching the browser version behind them.
  • A proxy fixes the address. Fingerprint consistency is a separate job, and the two have to be solved together to be worth anything.

What the User-Agent will and will not do

Changing it does not make you a different browser

Everything measurable stays the same, and now it disagrees with your claim.

Mobile User-Agent without a mobile address

Claiming an iPhone from a datacenter range is a contradiction that costs nothing to detect.

A blocked request is rarely about the string

Most blocks are decided on address reputation and TLS fingerprint. The header is the last thing checked, not the first.

Rotating User-Agents per request

Real browsers keep theirs. A session where the browser changes identity every request is more suspicious than one that repeats.

¿Listo para usar user-agent?

SotaProxy te da acceso a proxies residenciales rotativos, móviles, de centro de datos e ISP. Sin compromiso mínimo.

Empezar