Aren't these all solved problems that we've worked out decades ago with certificates?
Certificates prove that a website/server (and sometimes the client) are who they say they are.
We force the website to renew their certificate from an issuer every year so that stolen tokens/certificates are less of a problem.
The issuer can protect or hide the identity of the certificate owner, and doesn't get any information about which clients accessed a server.