Sec-Private-State-Token-Lifetime header

Experimental: This is an experimental technology
Check the Browser compatibility table carefully before using this in production.

The HTTP Sec-Private-State-Token-Lifetime Response Header is used by the Private State Token API during token redemption. It is sent by the redeemer server to indicate to the browser how long (in seconds) a redemption record should be cached for. The redemption record itself is sent in a Sec-Private-State-Token response header.

If the Sec-Private-State-Token-Lifetime header is omitted, the lifetime of the redemption record will be tied to the lifetime of the token verification key that confirmed the redeemed token's issuance.

Header typeResponse Header
CORS-safelisted request headerNo

Syntax

http
Sec-Private-State-Token-Lifetime: <integer>

Servers should ignore this header if it contains any other value.

Directives

<integer>

An integer specifying the lifetime of the sent redemption record in seconds.

Examples

http
Sec-Private-State-Token-Lifetime: 604800

Specifications

See also