Skip to main content
Back to the wiki
CAPTCHA & Verification

What Are Private Access Tokens (PATs)?

Last updated on July 21, 2026

Private Access Tokens (PATs) are cryptographic attestations that let a device vouch for its own legitimacy without revealing who its user is. Instead of solving a challenge, the client requests a signed token from an attester — in practice the device vendor, which can verify that the request comes from genuine hardware with a legitimately signed operating system — and presents it to the website. The receiving server learns exactly one bit: this client passed the attester's checks. Apple introduced PAT support across its platforms in 2022, building on the IETF Privacy Pass architecture, with the stated goal of letting trusted devices skip CAPTCHAs entirely.

How the Token Flow Works

The protocol deliberately splits knowledge between parties so no single one sees the whole picture. The website (the origin) issues a token challenge; the client forwards it through the token issuer to the attester, which checks device integrity and signals like a valid account in good standing; the signed token then returns to the origin for verification. Blind signatures ensure the issuer cannot link the token it signed to the site where it is redeemed, and the origin never sees device identifiers — only a valid or invalid token. The design solves a real privacy problem elegantly: proof of trustworthiness without identification, rate-limited so tokens cannot be stockpiled and resold at scale.

Where the Limits Are

PATs attest to the device, and only on platforms whose vendor operates an attester — coverage concentrated in one hardware ecosystem, with everything else falling back to conventional verification. That partial coverage is structural: a website cannot require PATs without excluding a large share of legitimate visitors, so tokens can lower friction for some traffic but never replace the verification layer. The attestation is also narrower than it sounds. A genuine device with a legitimate OS says nothing about what runs on it — automation driving a real browser on real hardware inherits the device's good standing, and a farm of authentic devices passes attestation by definition. Finally, the model concentrates gatekeeping power in the attesting vendors, a governance concern the web-standards community continues to debate.

PATs in a Layered Defense

The sensible reading of PATs is as one strong signal among several rather than a verdict: a valid token justifiably lowers a session's risk score, while its absence — being the normal case on most platforms — proves nothing. Broad protection still requires signals that work everywhere, which is why verification services such as CaptchaFox evaluate environment consistency, behavioral patterns, and proof-of-work results independently of any vendor attestation. The privacy philosophy behind PATs — prove the property, not the identity — points the same direction as cookie-free, identifier-free verification; the token simply covers one slice of clients, and the rest of the defense must hold for everyone else.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is a CAPTCHA?

A CAPTCHA is a challenge designed to tell humans and automated programs apart, protecting logins, forms and checkouts from abuse by bots.

Read more
What Is an Invisible CAPTCHA?

An invisible CAPTCHA verifies that a visitor is human in the background, without a puzzle — a challenge only appears when signals indicate automation.

Read more
What Is Proof of Work?

Proof of work is a cryptographic mechanism that requires solving a computational puzzle before an action is accepted, making abuse expensive at scale.

Read more
What Is a Fake Review?

A fake review is a fabricated customer rating meant to mislead — posted at scale through fake accounts and bots, and increasingly regulated as fraud.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices