C2PA Content Credentials
Verify a file / Articles

Reading a C2PA manifest, field by field

7 min read

The "C2PA manifest" panel on the result page shows the raw data. A file can hold several manifests (one per signing). The common fields are:

active_manifest

The label of the manifest currently in effect (a urn:uuid:…). Other manifests usually belong to ingredients or earlier versions.

manifests → claim_generator / claim_generator_info

The software (and version) that wrote this manifest, e.g. Adobe_Firefly or Adobe Photoshop 26.x.

assertions

ingredients

Other files this one was made from. relationship parentOf means the previous version, componentOf a component; active_manifest points to that ingredient's own manifest.

signature_info

Signature details: common_name (certificate name), issuer, alg (e.g. Es256, Ps256) and time (signing time from a trusted timestamp).

validation_results and validation_state

Results come in success, informational and failure groups. Common codes: claimSignature.validated (signature valid), assertion.dataHash.match (content unchanged), signingCredential.trusted / signingCredential.untrusted (certificate on / not on a trust list). validation_state summarizes the result as Trusted, Valid or Invalid.

Verify a file →

More articles