# Sec-Fetch-User Header: ?1 and User Activation

> Sec-Fetch-User is always ?1 and appears only on user-activated navigations, like a link click. When it is absent and why Safari does not send it.

Source: https://howhttpworks.com/headers/sec-fetch-user
Last reviewed: 2026-10-04

> **TL;DR:** `Sec-Fetch-User: ?1` is sent only on navigation requests the user caused with a click, keypress or similar activation. It is absent otherwise, never `?0`. Safari does not send it, so use it as a soft signal, never a requirement.

## What it looks like

```http
GET /dashboard HTTP/1.1
Host: example.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-Dest: document
Sec-Fetch-User: ?1
```

The value comes from structured-field booleans: `?1` is true. The Fetch Metadata spec (section 2.4) says the header is set only when a request is a navigation and its user-activation flag is true; in every other case the browser omits it. It is a forbidden request header, so scripts cannot add it.

## When you will see it

| Action | Sent |
| --- | --- |
| Click a link | Yes |
| Submit a form with a click or Enter | Yes |
| Type a URL or use a bookmark | Yes, with `Sec-Fetch-Site: none` |
| Page script sets `location.href` with no gesture | No |
| `<img>`, `fetch()`, `<script>`, iframe subresources | No |

The spec scopes it to navigation requests, which is why it is of limited use on its own. It matters when you want to separate "user clicked through to my page" from "a page redirected the browser to mine automatically".

## Uses

- **Logging and analytics.** Tell real clicks from auto-redirects and prefetch-like navigations in access logs. Log it with `Sec-Fetch-Site`.
- **Tightening a cross-site navigation rule.** The standard resource isolation policy allows any cross-site `GET` navigation. If you want stricter, require `Sec-Fetch-User: ?1` for cross-site navigations to sensitive pages and send others to a landing page. Accept that Safari users, who do not send the header, will always take the landing page, so this is only suitable where that is acceptable.
- **Clickjacking and drive-by navigation hints.** A navigation to your sensitive URL without user activation, from another site, is suspicious. It is a signal, not a defence. `frame-ancestors` in [Content-Security-Policy](https://howhttpworks.com/headers/content-security-policy) is the defence.

## Browser support

Chrome and Edge 76, Firefox 90. Safari: no support in MDN's compatibility data, with WebKit bug 247697 open for it. This differs from `Sec-Fetch-Site`, `Sec-Fetch-Mode` and `Sec-Fetch-Dest`, which Safari has sent since 16.4. Sent only on requests to potentially trustworthy URLs (HTTPS, `localhost`).

## Related

- [Sec-Fetch-Site](https://howhttpworks.com/headers/sec-fetch-site) for the resource isolation policy, [Sec-Fetch-Mode](https://howhttpworks.com/headers/sec-fetch-mode), [Sec-Fetch-Dest](https://howhttpworks.com/headers/sec-fetch-dest)
