Claims versus classification
The client.* rows above are Fastly’s device detection: the User-Agent parsed into browser, OS and hardware class, plus the client.class.* flags that spot bots, checkers, downloaders and clients masquerading as something they are not. Display values of -1 mean the database has no answer for that device.
The newer verdicts: fastly.bot.*
The bottom rows come from the fastly.bot.* family, which goes beyond string-matching the User-Agent: verified bot detection checks whether a claimed crawler really is who it says it is, and the category flags separate search engine crawlers from AI crawlers, AI fetchers, security scanners, monitoring tools and link-preview agents. Watch an AI assistant fetch this page and it lights up rather differently to your browser.
These variables populate when the service has Fastly Bot Management enabled; fastly.bot.analyzed tells you whether the verdict rows are live.
Lie to it, see what happens
The plain-text version lives at /raw. The fun experiment is spoofing: claim to be a phone, or a search engine crawler, and watch which rows believe you and which do not.
The same variables drive edge logic
Everything on this page is a live VCL expression, evaluated on every request before your origin is ever involved. That means each value can conditionalise the request flow — route, block, redirect, rewrite, rate limit, or vary the cache on it. A taste, in this site’s dialect:
The other half is insight: every variable here can be emitted through Fastly’s real-time log streaming from vcl_log — per-request, from every POP, with no JavaScript beacons or client-side analytics. Stream them into your warehouse and you know your audience’s device mix, browsers and bot traffic at whatever depth you like.
One service, three hostnames, zero origins
geoip, tls and device are a single origin-less Fastly VCL service, routed by req.http.host. Every response is a synthetic response: the variables above are captured into request headers in vcl_recv (most are not available in vcl_error, where the page is assembled) and interpolated into the HTML at the POP nearest you. Values echoed from client-controlled input are HTML-escaped in VCL first.
The whole family works this way — see http.alpagot.net and h3.alpagot.net for the other experiments, and Fastly’s VCL variables reference for everything the edge can see.
Richard Alpagot
Senior Cloud Engineer at Fastly, collector of small sites that explain themselves.
- websitewww.alpagot.net
- blogblog.alpagot.net
- linkedin/in/alpagot