01

What a manifest contains

A C2PA manifest can include a signed claim, assertions about actions, a claim generator, ingredients and references to thumbnails. The asset and claim hashes allow a verifier to detect certain changes.

Key points
  • Claim and signature
  • Actions and editing history
  • Ingredients or source assets
  • Digital source type
  • Validation and trust status
02

Verification is not a truth detector

A valid signature shows that the signed data validates under the standard. It does not independently verify the event, the person’s identity beyond the credential context, or every edit that happened before signing.

What this does not prove

A metadata result describes the fields and structures that the supported parser could read. It does not, by itself, prove authenticity, intent, authorship or the truth of the visible scene.

Sources