# UAParse > Free User-Agent parser and bot detector: browser, OS, device type and engine, plus flags for known bots, search crawlers, AI crawlers and AI agents acting for a user. Public JSON API plus a remote MCP server for AI agents. UAParse runs entirely inside a Cloudflare Worker: ua-parser-js 1.0.41 (MIT) for browser / engine / OS / device / CPU, and a curated list of 151 bots (43 of them AI crawlers, list 2026-10-08) for bot detection. It makes no network lookups per request, so a match is never "verified": anyone can spoof a User-Agent. It does not store User-Agent strings next to IP addresses. `is_ai_agent` is true only for User-Agents that the operator's own docs describe as acting live for an individual user of an AI assistant or agent: 9 names (8 current plus the retired Google-NotebookLM name, still detected). AI agents that browse in a real browser and publish no token (e.g. Meta Muse; Meta publishes no Muse User-Agent) are indistinguishable from people here. UAParse is independent and not affiliated with Meta, OpenAI, Google, Anthropic, Amazon, Perplexity or Mistral AI. ## For AI agents - [MCP server](https://uaparse.mike-tusa.workers.dev/mcp): remote MCP over Streamable HTTP at `https://uaparse.mike-tusa.workers.dev/mcp` (POST only, stateless, JSON responses, no sessions). Protocol versions: 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05 (2026-07-28 per-request `_meta`; older versions use `initialize`). One tool: `parse_user_agent` with `ua` (required, 1–2,048 characters) and `include_raw` (optional). Read-only. Client config (most MCP clients accept this; some use a different format, for example VS Code uses a `servers` key): `{"mcpServers":{"uaparse":{"type":"http","url":"https://uaparse.mike-tusa.workers.dev/mcp"}}}` - [OpenAPI 3.1 spec](https://uaparse.mike-tusa.workers.dev/openapi.json): machine-readable description of the JSON API - [JSON API docs](https://uaparse.mike-tusa.workers.dev/docs): human-readable API reference with examples ## JSON API - `POST https://uaparse.mike-tusa.workers.dev/v1/parse` with `{"ua":"…"}` (recommended; JSON body at most 8,192 bytes) or `GET https://uaparse.mike-tusa.workers.dev/v1/parse?ua=…`. Without `ua` it parses the caller's own User-Agent. Returns `ua`, `browser`, `engine`, `os`, `device` (`type`: desktop, mobile, tablet, smarttv, console, wearable, xr, embedded, bot or unknown), `cpu`, `is_bot`, `is_ai_crawler`, `is_ai_agent`, `is_search_crawler`, `bot` (`category`, `name`, `operator`, `ai_purpose`, `ai_agent_kind`, `robots_token`, `token_only`, `info_url`, `match`, `verified` = false), `list_version`, `parser`. Header `X-Cache: HIT|MISS`. CORS enabled. - `POST https://uaparse.mike-tusa.workers.dev/v1/bulk` with `{"uas":["…", …]}`: API key required; at most 100 User-Agents per call (free keys 10); body at most 65,536 bytes; each UA is one lookup; all-or-nothing. Returns `{"count", "list_version", "results": [...]}`. REST only (not an MCP tool). - `GET https://uaparse.mike-tusa.workers.dev/v1/bots`: the curated bot list (not counted as lookups). - `GET https://uaparse.mike-tusa.workers.dev/v1/meta`: version, list version, counts and limits. - `GET https://uaparse.mike-tusa.workers.dev/health`: `{ "ok": true, "service": "uaparse", "version": "0.3.2", "build": "…" }` - Errors: `{ "error": { "code", "message" } }` with HTTP 400 `empty_ua`/`ua_too_long`/`invalid_body`/`invalid_json`/`empty_batch`/`too_many_uas`/`invalid_ua_item`, 401 `invalid_api_key`/`api_key_required`, 403 `plan_bulk_limit`, 405 `method_not_allowed`, 413 `body_too_large`, 415 `unsupported_media_type`, 429 `rate_limited`/`quota_exceeded`/`daily_capacity_reached`/`too_many_failed_auth` (see `Retry-After`), 503 `keys_unavailable`/`storage_unavailable`/`quota_unavailable`. ## Limits, keys and pricing - Anonymous (no key; web tool, API and MCP): about 20 lookups per minute per IP (IPv6: per /64 prefix); all anonymous users share about 10,000 lookups per UTC day. - Free API key (issued by email request during early access: digitalpromohub.support@gmail.com): 1,000 lookups per UTC day, about 120 requests per minute, bulk up to 10 per call. Send `Authorization: Bearer up_live_…`. - Pro: planned (about $9/month), not on sale yet: 50,000 lookups per UTC day and bulk up to 100 per call. - Everyone: a shared daily capacity of about 15,000 lookups; when it is reached, HTTP 429 `daily_capacity_reached` until 00:00 UTC. - The MCP endpoint uses the same keys and the same counters: each `tools/call` is one lookup (cache hits included, like the API). `initialize`, `tools/list` and other non-lookup messages don't count as lookups, but have a light cap of about 120 per minute per IP (over it: HTTP 429 with `Retry-After`). Over a limit, the tool result has `isError: true` with the reason and `retryAfterSeconds`. An invalid key returns HTTP 401. - MCP request caps: 65,536-byte body, JSON-RPC batches (legacy versions only) of at most 10 messages with at most one `tools/call`. ## Optional - [Homepage and web tool](https://uaparse.mike-tusa.workers.dev/) - [Privacy](https://uaparse.mike-tusa.workers.dev/privacy) - [RobotsGate](https://robotsgate.mike-tusa.workers.dev): sibling tool for robots.txt rules for AI crawlers (UAParse does not build robots.txt) - Contact: digitalpromohub.support@gmail.com