Generate a Relay claim
Returns a relay’s claim.
Authentication
Privacy Pass token per RFC 9577. Provide as Authorization: PrivateToken token=<privacyPassToken>.
Path parameters
The public Relay token returned by POST /relays.
Headers
The relay-secret value returned at Relay creation. Required for every read of the claim payload; an incorrect secret returns 404.
Response headers
The maximum number of requests permitted in the current rate limit window. For an API key with its own rate limit, requests count against both the key's limit and the environment's limit, and this header reports whichever is closer to being reached, so it can change between responses. On a 429 response, it reports the limit that rejected the request. For an API key without its own rate limit, it reports the environment's limit. Returned on every authenticated response.
The number of requests remaining in the current rate limit window for the limit reported in RateLimit-Limit. Returned on every authenticated response.
The unique identifier of the API log entry that recorded this request. Starts with req_. Include this value when reaching out to Persona support. Present on every authenticated response, including error responses.
Response
The claim payload. If an encryption-key-pem was provided at Relay creation, this
is a base64-encoded RSA OAEP ciphertext that must be decrypted client-side.
Otherwise, this is a JSON string containing claim_type, claim_result, and an
optional methodology array.
true if the Privacy Pass token was consumed by this request. false if the underlying claim did not pass and the token was refunded to the client.

