Defend against a key shenanigans attack by the server
The privacy features of challenge-bypass-ristretto are not guaranteed if the client cannot hide in a crowd of other users. The size of the crowd is defined by the number of clients which redeem vouchers from a server using a particular signing key. If a server offers a different signing key to each user, no user has a crowd and there are no privacy features.
Outside of the cryptographic protocol, the client must take steps to be sure it is not being attacked this way. These steps must somehow convince the client that the server is signing a large number of tokens with the same key.