This demo lets you issue Privacy Pass tokens with public metadata and inspect each step of the issuance protocol, defined in draft-ietf-privacypass-public-metadata-issuance-03.
Each step's output autofills the next section's input for you, so you shouldn't need to copy/paste anything by hand (except for tampering with extensions).
Try it: once you have a token, edit the
extensions value in Verify token before clicking Verify, and the verification will fail.
That's because the metadata is cryptographically bound to the token, so it can't be tampered with.
This issuer's /.well-known/private-token-issuer-directory, advertising the issuer request URI, supported token type, and public key.
Specified in RFC 9578 section 4.
Build a TokenChallenge and a ready-to-use WWW-Authenticate header.
Advertise the extension types this issuer supports. Optionally, mark some extension types as required.
See draft-ietf-privacypass-auth-scheme-extensions-03 for more info.
Parse a PrivateToken challenge="...", token-key="..." WWW-Authenticate header, and get a breakdown of the fields it contains.
Choose the public metadata to bind to your token (for example, an expiry). The metadata will be structured as extensions, defined in draft-ietf-privacypass-auth-scheme-extensions-03.
A field to create an Expiration extension (defined in draft-ietf-privacypass-expiration-extension-00) is provided, and you can also add one or more custom extensions, each with a type (1–65535) and a value as hex.
The result can be pasted into a token's extensions="..." field in Inspect/Verify to test tampering with metadata.
Validate a built extensions blob against a challenge's extension-set: every required type must be present, otherwise the Client should expect to be rejected.
Send a token request and return the token + Authorization header. Supply an extensions blob from Build extensions to cryptographically bind metadata to the token. Behind the scenes, the Issuer derives a brand-new public key just for this exact metadata and signs the blinded token input with that key, making the metadata tamper-proof.
Parse a PrivateToken token="...", extensions="..." header and show its fields + bound metadata.
Check a token against the issuer public key and the provided extensions. To demonstrate tamper resistance, try editing the extensions field before clicking Verify: any change causes verification to fail, since the metadata no longer matches what was signed at issuance.