Audio fingerprinting without a microphone
"Audio fingerprint" sounds like something recorded through a microphone. It is not. It is a number derived from how your machine processes a synthetic sound that is never played, never captured and never leaves the tab.
How it is made
The script creates an OfflineAudioContext, which renders audio into a buffer in memory instead of to speakers. It connects an oscillator, usually a triangle wave at a fixed frequency, through a dynamics compressor to the destination, and starts rendering. When the buffer is ready, it reads a slice of the samples, often a few hundred values, and hashes them. The result is a short string such as d4f50eb9.
The whole operation takes a few tens of milliseconds and requires no permission, because nothing is captured. The OfflineAudioContext is closed when the script is done.
Why it differs between machines
The compressor and oscillator are implemented in floating-point arithmetic inside the browser's audio engine, and the exact output depends on the engine version, the operating system's math library, the CPU's floating-point behaviour, and in some configurations the audio hardware's sample rate. The differences are tiny, a few bits in the last decimal places, but hashing amplifies tiny differences into entirely different strings. Like the canvas hash, it is stable on one machine and varies across machines.
Its diversity is lower than canvas: many machines with the same browser build and operating system produce the same audio hash. It is useful mainly as a confirmation signal and as a way to detect browsers that randomise their output.
What browsers do
Brave adds noise to audio readbacks in the same way it does for canvas. Firefox with resist-fingerprinting disables parts of the Web Audio API or returns constant values. Chromium does not alter the output. A browser that randomises the hash produces a different value on every reload, which a diagnostic makes visible simply by letting you reload and compare.
Privacy, precisely
No sound is recorded. No microphone is opened. The buffer exists in memory for the duration of the computation and is discarded. The only thing that could leave the tab is the hash, and only if the page chooses to send it. A diagnostic that computes the hash locally and shows it to you is reading exactly what a tracker would read, and then doing nothing with it.
Reading the value
Two things are worth checking. First, that the hash exists at all: "Unavailable" means the API is blocked, which some sites treat as its own signal. Second, that it is stable: reload and the value should not change. A hash that changes between loads tells you the browser is injecting noise, which protects against tracking across sites but also marks the browser as one that does so.