Privacy Pass with public metadata — live demo

This demo lets you issue Privacy Pass tokens with public metadata and inspect each step of the issuance protocol, defined in draft-ietf-privacypass-public-metadata-issuance-03.

Each step's output autofills the next section's input for you, so you shouldn't need to copy/paste anything by hand (except for tampering with extensions).

Try it: once you have a token, edit the extensions value in Verify token before clicking Verify, and the verification will fail. That's because the metadata is cryptographically bound to the token, so it can't be tampered with.

Issuer Directory

This issuer's /.well-known/private-token-issuer-directory, advertising the issuer request URI, supported token type, and public key.

Specified in RFC 9578 section 4.


    

Create challenge

Build a TokenChallenge and a ready-to-use WWW-Authenticate header.

Extension set

Advertise the extension types this issuer supports. Optionally, mark some extension types as required.

See draft-ietf-privacypass-auth-scheme-extensions-03 for more info.


    

Inspect challenge

Parse a PrivateToken challenge="...", token-key="..." WWW-Authenticate header, and get a breakdown of the fields it contains.


    

Build extensions

Choose the public metadata to bind to your token (for example, an expiry). The metadata will be structured as extensions, defined in draft-ietf-privacypass-auth-scheme-extensions-03.

A field to create an Expiration extension (defined in draft-ietf-privacypass-expiration-extension-00) is provided, and you can also add one or more custom extensions, each with a type (1–65535) and a value as hex.
The result can be pasted into a token's extensions="..." field in Inspect/Verify to test tampering with metadata.

Custom extensions


    

Validate extensions

Validate a built extensions blob against a challenge's extension-set: every required type must be present, otherwise the Client should expect to be rejected.


    

Send token request

Send a token request and return the token + Authorization header. Supply an extensions blob from Build extensions to cryptographically bind metadata to the token. Behind the scenes, the Issuer derives a brand-new public key just for this exact metadata and signs the blinded token input with that key, making the metadata tamper-proof.


    

Inspect token

Parse a PrivateToken token="...", extensions="..." header and show its fields + bound metadata.


    

Verify token

Check a token against the issuer public key and the provided extensions. To demonstrate tamper resistance, try editing the extensions field before clicking Verify: any change causes verification to fail, since the metadata no longer matches what was signed at issuance.