The HTTP Sec-Fetch-User fetch metadata request header is sent for requests initiated by user activation, and its value is always ?1.
A server can use this header to identify whether a navigation request from a document, iframe, etc., was originated by the user.Header type Fetch Metadata Request Header Forbidden request header Yes ( Sec- prefix)CORS-safelisted request header No
Sec-Fetch-User: ?1The value will always be ?1. When a request is triggered by something other than a user activation, the spec requires browsers to omit the header completely.
If a user clicks on a page link to another page on the same origin, the resulting request would have the following headers:
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site fetch metadata request headers