Sec-Fetch-User

Servers need to distinguish clicks and form submissions from automated navigations. The Sec-Fetch-User request header signals whether a user gesture triggered the navigation.

Usage

The Sec-Fetch-User header is part of the Fetch Metadata Request Headers specification. Browsers include this header only on navigation requests where the user directly caused the navigation, such as clicking a link, submitting a form, or pressing a keyboard shortcut to navigate.

The header uses the Structured Fields boolean format. The only value sent is ?1, meaning true. When no user activation triggered the navigation, the browser omits the header entirely rather than sending a false value. Automatic navigations like <meta http-equiv="refresh"> Redirects and JavaScript-initiated navigations without user gestures do not include this header.

Servers use Sec-Fetch-User alongside Sec-Fetch-Site, Sec-Fetch-Mode, and Sec-Fetch-Dest to distinguish legitimate user-initiated navigations from automated or programmatic requests. A server protecting a sensitive endpoint verifies both Sec-Fetch-User: ?1 and Sec-Fetch-Site: same-origin before processing the request, adding an extra layer of defense against cross-site request forgery.

Values

?1

The ?1 value is a Structured Fields boolean indicating true. The navigation was activated by a user gesture: a click, tap, form submission, or keyboard action. No other values exist for this header.

Example

A user clicks a link on the same site. The browser includes all four fetch metadata headers, with Sec-Fetch-User confirming user activation.

Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin

A user submits a form pointing to a same-site action URL. The form submission counts as user activation.

POST /submit HTTP/1.1
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin

An automatic redirect triggered by JavaScript does not include the Sec-Fetch-User header because no user gesture initiated the navigation.

Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin

Crawlers and Sec-Fetch-User

Verified crawler probe

Probe data from verified crawler traffic (September 2026 snapshot) shows which bots send Sec-Fetch-User when requesting pages. Yes marks the header on at least nine of ten sampled requests from the bot, Sometimes marks a smaller share, and No marks absence.

Crawler Sends Sec-Fetch-User
Amazonbot No
Applebot No
Baiduspider No
Bingbot No
ClaudeBot No
DuckDuckBot No
GPTBot No
Googlebot No
Googlebot (smartphone) No
Googlebot-Image No
Meta-ExternalAgent Sometimes
Meta-WebIndexer Sometimes
OAI-SearchBot No
SeznamBot No
YandexBot No
YandexFavicons No

See also

Last updated: September 21, 2026