Why does microphone access work on localhost but not a LAN IP?
A plain HTTP LAN address is not the same security context as localhost. Browsers can treat loopback development origins as trustworthy, while an ordinary HTTP network address does not receive that exception. A microphone permission setting cannot replace the secure-context requirement.
Check the address before the microphone
- Localhost or loopback: local development may qualify as a secure context without HTTPS.
- Plain HTTP LAN address: do not assume the localhost exception applies.
- HTTPS: use a valid trusted certificate; an embedded page also depends on its ancestor context.
Check window.isSecureContext in your own application's diagnostics. If it is false, fix the deployment context before troubleshooting the device. Do not disable browser security or bypass certificate warnings.
A secure context is necessary, not sufficient: site consent and applicable device permissions still matter.
Sources and scope
MDN: Secure contexts; MDN: getUserMedia.
Documentation synthesis reviewed September 28, 2026. No hands-on device test was performed. This page does not request microphone access.