...
Tomcat's 'workaround' to add SameSite is potentially less configurable by default, as it globally applies to all cookies a single configured same-site value (including the session cookie). This could be extended by using a custom CookieProcessor, but as there seems no way to access the HttpRequest, it still may not be suitable for conditionally applying the values by user-agent.
Tomcat and Jetty Servlet Specification Support
...