**Session Date/Time:** 22 Jul 2026 14:00 # [PRIVACYPASS](../wg/privacypass.html) ## Summary The PRIVACYPASS Working Group meeting focused on document status updates, the formal discontinuation of the Anonymous Rate-Limited Credentials (ARC) drafts, an architectural update and adoption discussion for the Privacy Pass Reverse Flow protocol, and a summary of the recently held side meeting for Moderation of Unlinkable Endorsement (MoLE / formerly PACT). --- ## Key Discussion Points ### Working Group Document Status & Updates The Chairperson presented the [Chair Slides](https://datatracker.ietf.org/meeting/126/materials/slides-126-privacypass-chair-slides-00) and gave status updates on active working group documents: * The "batch token" draft is currently with the IESG awaiting AD review. * `draft-ietf-privacypass-auth-scheme-extensions` (The PrivateToken HTTP Authentication Scheme Extensions Parameter) is ready. * `draft-ietf-privacypass-expiration-extension` (Privacy Pass Token Expiration Extension) is currently in Working Group Last Call (WGLC). * `draft-ietf-privacypass-public-metadata-issuance` (Privacy Pass Issuance Protocols with Public Metadata) is currently designated as Informational. The Chairperson and Christopher Wood agreed that this designation was a mistake and it should be transitioned to the Standards Track. The Chairperson will confirm on the mailing list to ensure no objections before the authors publish an updated Standards Track version. ### Discontinuation of ARC The working group discussed the status of the Anonymous Rate-Limited Credentials (ARC) drafts: * `draft-ietf-privacypass-arc-crypto` (Anonymous Rate-Limited Credentials Cryptography) * `draft-ietf-privacypass-arc-protocol` (Privacy Pass Issuance Protocol for Anonymous Rate-Limited Credentials) The Chairperson noted that these documents have reached their terminal point and there is no intent to continue developing them. Christopher Wood and other participants agreed. There were no objections to releasing these drafts from the working group. ### Privacy Pass Reverse Flow Update Thibault Meunier presented an update on the Reverse Flow architecture using the slides [Privacy Pass Reverse Flow - Update](https://datatracker.ietf.org/meeting/126/materials/slides-126-privacypass-privacy-pass-reverse-flow-update-00). Key updates in the latest draft version (draft-06) include: * Splitting credential finalization from credential presentation to accommodate cryptographic operations where a credential is presented multiple times. * Renaming "token request/challenge" terminology to "credential" to better align with anonymous credential concepts. * Adding security considerations for amplification, replay protection, and consistency. * Splitting the HTTP header definition out of the main architecture document into its own dedicated draft. This ensures the core architecture remains transport-independent, facilitating use cases like Media over QUIC (`draft-ietf-moq-privacy-pass-auth`) or MoLE which do not use HTTP headers. **Discussion on Reverse Flow:** * **State Management:** Tommy Pauly noted that client storage needs to distinguish between a "refund" model (where spent tokens are replaced with equivalent ones) and storing tokens that carry different properties. Sam Schlesinger suggested adding explicit guidance on client and issuer state (e.g., tracking VOPRF transactions to prevent double-minting during retries). Nick Doty raised privacy concerns regarding client state, highlighting the need to clarify how local state interacts with browser clearing mechanisms. * **Deployment Status:** In response to Ben VanderSloot, Thibault Meunier confirmed that reverse-flow systems are deployed today to preserve unlinkability over repeated requests. These deployments are not browser-exclusive and do not use the newly split HTTP header draft. * **Consistency:** Ben VanderSloot questioned referencing the expired consistency draft. Thibault Meunier and Christopher Wood suggested removing the reference to simplify the adoption and progression of the draft. Sam Schlesinger expressed that if there are cross-browser or cross-client deployments, consistency becomes highly relevant and the consistency draft should be revived. The working group held two polls to gauge consensus on the document: * **Poll 1:** Have you read the document? — yes: 13, no: 9, no_opinion: 0 (total: 43) * **Poll 2:** Do you think we should adopt this draft? — yes: 13, no: 1, no_opinion: 0 (total: 43) ### MoLE (Moderation of Unlinkable Endorsement) Update Thibault Meunier presented an update on MoLE (formerly known as PACT - Private Access Control Token) using the slides [MoLE - Update](https://datatracker.ietf.org/meeting/126/materials/slides-126-privacypass-mole-update-00). * **Side Meeting Report:** David Schinazi and Thibault Meunier reported that the side meeting went well, showing a viable architecture and strong community interest in writing and reviewing the drafts. * **Architecture:** MoLE uses three roles: Anchor (provides endorsement to the client), Browser (presents unlinkable proofs of endorsement), and Moderator (verifies proofs without learning which specific Anchor endorsed the client, then issues/queries credentials). * **Registry Coordination:** Tommy Pauly emphasized that MoLE should maintain tight coordination with the Privacy Pass IANA registry and building blocks to allow clean evolution from blind signatures to these newer structures. * **Chartering Strategy:** Deb Cooley (Responsible AD) advised the group on chartering options for the MoLE work. The proponents can either recharter the existing PRIVACYPASS working group (which is often the quickest path and does not require a formal BoF) or propose a new working group (with or without a BoF). Proponents must demonstrate community consensus, implementer interest, and interoperability concerns regardless of the chosen path. --- ## Decisions and Action Items * **Decision:** The working group agreed to discontinue work on the ARC drafts (`draft-ietf-privacypass-arc-crypto` and `draft-ietf-privacypass-arc-protocol`). The Chairs will update the Data Tracker to release these documents. * **Action Item (Chairs):** Confirm on the mailing list that there are no objections to transitioning `draft-ietf-privacypass-public-metadata-issuance` from Informational to Standards Track. * **Action Item (Chairs):** Initiate a formal Working Group Adoption Call on the mailing list for the Privacy Pass Reverse Flow architecture draft based on the strong positive room poll. --- ## Next Steps * **Reverse Flow Draft:** Authors will address feedback on client state management, replay considerations, and determine whether to remove references to the expired consistency draft. * **MoLE Proponents:** David Schinazi, Martin Thompson, and other proponents will regroup to draft a charter and consult with the ADs on whether to recharter PRIVACYPASS or pursue a new working group.