Reading a C2PA manifest, field by field
7 min read
The "C2PA manifest" panel on the result page shows the raw data. A file can hold several manifests (one per signing). The common fields are:
active_manifest
The label of the manifest currently in effect (a urn:uuid:…). Other manifests usually belong to ingredients or earlier versions.
manifests → claim_generator / claim_generator_info
The software (and version) that wrote this manifest, e.g. Adobe_Firefly or Adobe Photoshop 26.x.
assertions
c2pa.actions/c2pa.actions.v2: the action history. Each entry has anaction(such asc2pa.created,c2pa.edited),softwareAgent,when, and adigitalSourceType(e.g.trainedAlgorithmicMediafor AI-generated).c2pa.hash.data/c2pa.hash.bmff: hashes of the content, used to detect changes after signing.c2pa.thumbnail.claim.*: the thumbnail captured at signing.stds.schema-org.CreativeWork: author, copyright and similar.c2pa.training-mining: whether AI training and data mining are allowed.cawg.identity: creator identity claims (CAWG standard).
ingredients
Other files this one was made from. relationship parentOf means the previous version, componentOf a component; active_manifest points to that ingredient's own manifest.
signature_info
Signature details: common_name (certificate name), issuer, alg (e.g. Es256, Ps256) and time (signing time from a trusted timestamp).
validation_results and validation_state
Results come in success, informational and failure groups. Common codes: claimSignature.validated (signature valid), assertion.dataHash.match (content unchanged), signingCredential.trusted / signingCredential.untrusted (certificate on / not on a trust list). validation_state summarizes the result as Trusted, Valid or Invalid.