Create a Privacy Pass
Issues a Privacy Pass token by blind-signing a client-provided blinded token (Blind RSA, RFC 9578). The returned blind signature is unblinded client-side to produce a Privacy Pass token that can later be redeemed anonymously (for example, when generating a Relay claim).
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
Request
The base64url-encoded blinded token to be signed. Produced client-side by blinding a token input with the issuer public key identified by key-id.
The hex-encoded identifier of the issuer signing key to use. Must match the key the blinded-token was blinded against.
Response headers
The maximum number of requests permitted in the current rate limit window. For an API key with its own rate limit, requests count against both the key's limit and the environment's limit, and this header reports whichever is closer to being reached, so it can change between responses. On a 429 response, it reports the limit that rejected the request. For an API key without its own rate limit, it reports the environment's limit. Returned on every authenticated response.
The number of requests remaining in the current rate limit window for the limit reported in RateLimit-Limit. Returned on every authenticated response.
The unique identifier of the API log entry that recorded this request. Starts with req_. Include this value when reaching out to Persona support. Present on every authenticated response, including error responses.
Response
The base64url-encoded blind signature. Unblind this client-side to produce the Privacy Pass token.

