Start here

↑ ↓ to choose · Enter to open · Esc to close

PRIVATE TOKENS / FROM YOUR WALLET

Private tokens,
kept on your device.

Pay from your own wallet and end up holding blind tokens in this browser. No account, and no long-lived key: a one-time key is made here, receives your payment, buys the tokens and is thrown away. Everything runs in your browser, and below is a plain account of what stays linkable to you and what does not.

Reading what this router offers…

  1. 1One-time key
  2. 2Pay
  3. 3Credit
  4. 4Buy tokens
  5. 5Keep them
  6. 6Discard the key

1 · Make a one-time key and pick how you pay

The key is made here, needs no account, and lives only in this tab. It receives your payment, the page turns the credit into blind tokens, and then the key is switched off and wiped.

Your tokens

None yet. Tokens you buy here are kept in this browser and can be saved as a token file.

Can be linked to you

  • Your payment. Sending USDG or $ANYR is a public transaction on the chain, and the router reads it from there. Anyone, the router included, can see that your wallet paid, how much, and to which one-time key (USDG) or to the escrow address ($ANYR).
  • The purchase. The router records that the one-time key spent an amount on tokens: how many, and of which sizes. For $ANYR the credit sits on your wallet’s account, so the purchase is recorded against that wallet. Put together, “this wallet bought N tokens” is on record.
  • Your network address, and when. Buying over the clearnet shows the router your address, and buying right before you spend links the two by time. This page also works at the router’s onion address, where the router sees no address; the USDG route lets you pay from any wallet app, so the rest can run in Tor Browser.

Cannot be linked to you

  • Which prompts the tokens paid for. The router signs each token blind: it never sees the token it signs. When you spend one, the router can check that it is genuine and unspent, but it cannot tell which purchase or wallet it came from. A call paid with a token is recorded against a hash of the token, with no key, account or wallet, and its receipt says the same.

What tokens do not hide

  • The text of a request. On every lane the router reads a request in memory to route it, and that includes a call paid with a token. Tokens hide who is paying, not what is sent.
  • Your address while you spend, unless you use Tor. Spend tokens through the router’s onion address to keep your network address from it. Calls on one Tor circuit can be linked to each other.
  • Nothing is refunded. A token pays for one call, up to its value, and the unused part is not returned. Tokens stop working after the date shown with them, and the router keeps no record of who holds them, so a lost token cannot be replaced.

Spending them

This router does not serve the unlinkable lane right now, so tokens cannot be spent here yet. A token goes in the Authorization header as PrivateToken token=<token>, with the lane named in X-Anyroute-Lane: unlinkable. The token file format and a worked example are in the developer documentation.