What it is
The Web Audio API can render sound without playing it. An oscillator pushed through a compressor produces a waveform whose exact sample values depend on the audio engine, the operating system and the CPU’s floating-point behaviour — a fingerprint you cannot hear.
How websites read it
const ctx = new OfflineAudioContext(1, 5000, 44100);
const osc = ctx.createOscillator(); osc.type = 'triangle'; osc.frequency.value = 10000;
osc.connect(ctx.createDynamicsCompressor()).connect(ctx.destination); osc.start();
const buffer = await ctx.startRendering(); // hash(buffer.getChannelData(0))The rendered buffer is summed or hashed. Chrome on one OS gives one famous number (124.04347…), Firefox another; small deviations narrow the hardware down further.
Why it identifies you
The value is stable across sessions and identical across tabs, and it is independent of the graphics signals, so it corroborates them. Because it is computed rather than declared, it cannot be edited like a string.
How risk-control systems use it
Two behaviour tests dominate. A 0 Hz oscillator must render exact zeros: anything else means noise was injected after rendering. And getChannelData and createOscillator must still be native functions. A value that is unique but changes on every render is the signature of a "protection" extension.
Common mistakes
Random noise on every call; noise applied to silence; hooking getChannelData; an audio value that belongs to Firefox in a Chrome profile.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
NoiseSeeded, deterministic noise on the rendered samples; silence stays silent so the "zero test" passes.
Check yours
Jump to this signal in your scan results.