Sec-Private-State-Token header

Experimental: This is an experimental technology
Check the Browser compatibility table carefully before using this in production.

The HTTP Sec-Private-State-Token header exists both as a request and a response header. It is used by the Private State Token API during issuance and redemption requests to transmit request data and response data.

During token issuance, the Sec-Private-State-Token request header contains a collection of unsigned, blinded nonces required to generate a private state token to the issuer server. A successful response should include a Sec-Private-State-Token response header containing blind signatures, which the browser then unblinds and stores along with the original unblinded nonces in a secure token store.

During token redemption, the Sec-Private-State-Token request header contains a single signed, unblinded token along with associated redemption metadata. A successful response should include a Sec-Private-State-Token response header containing a signed redemption record, which is again stored securely by the browser.

Note that a developer wouldn't be expected to generate Sec-Private-State-Token request headers — these are created automatically by the browser when invoking private state token token-request and token-redemption fetch requests.

Header type Fetch Metadata Request Header, Response header
Forbidden request header Yes (Sec- prefix)
CORS-safelisted request header No

Syntax

http
Sec-Private-State-Token: <string>

Servers should ignore this header if it contains any other value.

Directives

<string>

A string containing the required data for private state token issuance and redemption operation requests and responses.

Examples

Sample request header sent during token issuance:

http
Sec-Private-State-Token: AEB9WGWUx398Pdr0SFE7NDo…

Sample response header:

http
Sec-Private-State-Token: AEB9WGWUxj1085Cuk2qmt3y…

Specifications

Specification
Private State Token API
# sec-private-state-token

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Sec-Private-State-Token
Experimental
Chrome – Full support
Chrome 117 (Release date: 2023-09-12)
footnote Full support
Edge – Full support
Edge 117 (Release date: 2023-09-15)
footnote Full support
Firefox – No support
Firefox
footnote No support
Opera – Full support
Opera 103 (Release date: 2023-10-03)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 117 (Release date: 2023-09-12)
footnote Full support
Firefox for Android – No support
Firefox for Android
footnote No support
Opera Android – Full support
Opera Android 78 (Release date: 2023-10-23)
footnote Full support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – Full support
Samsung Internet 24 (Release date: 2024-01-25)
footnote Full support
WebView Android – No support
WebView Android
footnote No support
WebView on iOS – No support
WebView on iOS
footnote No support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support
Experimental. Expect behavior to change in the future.

See also