c2pa library

High-level APIs for reading, validating, building, and signing C2PA data.

Classes

ActionActor
A human or system actor associated with a C2PA action.
ActionParameters
Action-specific parameters for the c2pa.actions vocabulary.
ActionRegion
A region or segment affected by an action.
ActionsAssertion
The C2PA c2pa.actions assertion.
ActionSoftwareAgent
Software identity attached to a provenance action.
ActionSoftwareAgentInfo
A software agent represented by structured generator info.
ActionSoftwareAgentName
A software agent represented only by its display name.
AssertionDefinition
A custom assertion encoded deterministically as JSON or CBOR.
BmffHashAssertion
Typed v3 c2pa.hash.bmff hard-binding assertion.
BmffHashDataReplacement
Bytes that must match at an offset before BMFF hash replacement.
BmffHashExclusion
A BMFF box exclusion rule used by the C2PA BMFF hash assertion.
BmffHashSubset
A byte range inside a matched BMFF box that remains hash-covered.
BmffMerkleProof
Per-fragment proof stored in a C2PA merkle UUID box.
BoxHashAssertion
Typed representation of the v1 c2pa.hash.boxes assertion.
BoxHashBox
One physical asset range described by a BoxHash v1 assertion.
BuilderIngredient
An ingredient and, when available, its embedded manifest box.
BuilderIntent
A manifest-builder intent that determines generated action semantics.
C2paAction
One provenance action recorded in a c2pa.actions assertion.
C2paActionNames
Canonical action names for the c2pa.actions assertion.
C2paArchiveLoadOptions
Options used when loading a C2PA builder archive.
C2paArchiveResourceRequest
External resource request from a C2PA builder archive.
C2paAssertionMetadata
CBOR assertion metadata for the c2pa.assertion.metadata.v1 label.
C2paAssetReferenceAssertion
CBOR assertion for the c2pa.asset-ref label.
C2paAssetReferenceEntry
Single absolute URI entry in an asset-reference assertion.
C2paAssetType
Asset type entry inside a c2pa.asset-type.v1 assertion.
C2paAssetTypesAssertion
CBOR assertion for the c2pa.asset-type.v1 label.
C2paBuilder
Builds deterministic, signed v2 manifest stores.
C2paCapabilities
Static feature capabilities for this SDK build.
C2paCertificateStatusAssertion
CBOR assertion for the c2pa.certificate-status label.
C2paCollectionItem
One item supplied by a C2paCollectionSource.
C2paCollectionSource
Source of items for a collection data hard binding.
C2paCompressionCapabilities
Compression support exposed by this SDK build.
C2paContext
Immutable dependencies and policy used by future SDK operations.
C2paCoordinate
Two-dimensional coordinate used by C2PA region shapes.
C2paDataSource
Description of a source that supplied assertion metadata.
C2paDynamicAssertion
An assertion whose final content is produced after the preliminary claim and all reserved assertion references are known.
C2paDynamicAssertionOutput
Output produced by a dynamic assertion callback.
C2paDynamicAssertionRequest
Request sent when resolving a dynamic assertion.
C2paDynamicClaimContext
Preliminary claim data passed to a dynamic assertion callback.
C2paEmbeddedData
Opaque binary assertion data with an explicit label and MIME type.
C2paHttpRemoteResolver
HTTP implementation of C2paRemoteResolver.
C2paHttpResolverCapabilities
Security capabilities exposed by an HTTP resolver implementation.
C2paHttpTimeouts
Timeout configuration for HTTP remote manifest resolution.
C2paJsonOptions
Stable JSON encoding options shared by all reader report projections.
C2paLegacyJsonAssertion
Legacy JSON assertion using historical C2PA or Schema.org labels.
C2paManifestEntry
Parsed manifest entry and validation state from a C2PA manifest store.
C2paMetadataAssertion
JSON metadata assertion for the c2pa.metadata.v1 label.
C2paProgressEvent
A progress notification emitted while reading, validating, or signing.
C2paRawBox
Raw JUMBF box bytes exposed from a C2PA manifest store.
C2paReader
Read-only structural view of an embedded or standalone C2PA manifest store.
C2paRegionOfInterest
Collection of one or more ranges describing an asset region.
C2paRegionRange
Typed range payload within a region of interest.
C2paRegionShape
Spatial shape payload for a C2PA region range.
C2paRemoteRequest
A transport request for a remote C2PA manifest.
C2paRemoteResolver
Caller-injected transport for remote manifests.
C2paRemoteResponse
A transport response containing either manifest bytes or a redirect.
C2paReservedSizeSigner
A signer that explicitly declares the exact signature-space reservation needed by embedded DataHash placeholder workflows.
C2paResolverCapabilities
Interface for resolvers that report runtime capabilities.
C2paResource
Manifest resource bytes decoded from a C2PA data box.
C2paReviewRating
Review rating entry embedded in assertion metadata.
C2paSettings
Conservative limits used while reading and validating C2PA data.
C2paSidecarResult
Bytes produced by sidecar manifest generation.
C2paSigner
Signer used to produce C2PA claim signatures.
C2paSoftBindingAssertion
CBOR assertion for the c2pa.soft-binding label.
C2paSoftBindingBlock
Single scoped value inside a soft-binding assertion.
C2paSoftBindingScope
Scope that limits where a soft-binding block applies.
C2paSoftBindingTimespan
Inclusive media time span used by a soft-binding scope.
C2paStandardAssertion
A standard C2PA assertion value that can be embedded in a claim.
C2paThumbnail
Embedded thumbnail assertion for a claim or ingredient.
C2paTimestampAssertion
CBOR assertion for the c2pa.time-stamp label.
C2paTimestampConfig
Immutable timestamp configuration for a Builder claim signature.
C2paTrustConfiguration
Trust anchors and certificate policy used for signature validation.
C2paVerifier
Verifier used to check C2PA claim signatures.
CallbackC2paSigner
C2paSigner adapter backed by a C2paSignCallback.
CallbackC2paVerifier
C2paVerifier adapter backed by a C2paVerifyCallback.
CawgIcaCredentialHolder
Signing material used to generate ICA identity assertions.
CawgIcaVerifier
Verifier for CAWG identity-claims aggregation credentials.
CawgIdentityAssertion
CAWG identity assertion containing signer payload, signature, and padding.
CawgIdentityClaimsCredential
Identity Claims Aggregation verifiable credential.
CawgIdentityLabels
CAWG assertion labels and helpers for identity assertions.
CawgIdentityProvider
Verified identity provider entry in an ICA credential.
CawgIdentityValidationResult
Result of validating one CAWG identity assertion.
CawgIdentityValidator
Validator for CAWG identity assertions referenced by a claim.
CawgIssuer
Issuer value from a CAWG identity-claims credential.
CawgSignerPayload
Decoded CAWG signer_payload map used as signature input.
CawgStatusCodes
Status code constants emitted by CAWG identity validation.
CawgValidationStatus
Single validation status emitted during CAWG identity checking.
CawgVerifiedIdentity
Verified identity claim embedded in an ICA credential.
CawgX509CoseVerifier
Verifier for cawg.x509.cose identity signatures.
CawgX509CredentialHolder
Signing material used to generate X.509 COSE identity assertions.
CawgX509Verification
Internal-style result returned by CAWG signature verifiers.
Claim
A decoded C2PA claim with common version-independent fields.
ClaimGeneratorInfo
Software identity metadata for the claim generator.
ClaimHashedUri
A C2PA hashed URI reference to a claim assertion or resource.
ClaimV1
A C2PA claim using the version 1 assertions list shape.
ClaimV2
A C2PA claim using the version 2 created/gathered assertion shape.
CollectionDataType
Data type descriptor for a collection-hash entry.
CollectionHashAssertion
Typed v1 c2pa.hash.collection.data hard-binding assertion.
CollectionHashEntry
Hash metadata for one URI in a collection hard binding.
CreateIntent
A builder intent for creating a new asset manifestation.
DataHashAssertion
Typed representation of the v1 c2pa.hash.data assertion.
DataHashBuildStateMachine
Enforces the ordering required by an embedded DataHash build.
DataHashExclusionRange
One excluded byte range in a DataHash v1 assertion.
EditIntent
A builder intent for editing one parent ingredient.
FragmentedBmffBuildResult
Output of a fragmented BMFF signing operation. Signed initialization segment and fragments for fragmented BMFF.
HashedUri
A URI paired with the digest expected for its target bytes.
Ingredient
An ingredient entry describing source provenance for a manifest.
IngredientAssertion
Typed ingredient assertion supporting specification versions 1, 2, and 3.
IngredientAssetType
An asset type attached to an ingredient.
IngredientDeltaValidationResult
Validation delta associated with one ingredient assertion URI.
Manifest
A high-level JSON view of one C2PA manifest.
ManifestAssertion
A decoded manifest assertion with arbitrary JSON-compatible data.
ManifestDefinition
Immutable input used to construct one v2 C2PA manifest.
ManifestResource
Caller-owned bytes placed in the manifest's data-box store.
MemoryByteSink
An in-memory byte sink useful for tests and generated byte buffers.
MemoryByteSource
A fixed random-access byte source backed by an isolated in-memory copy.
MerkleMap
One v3 BMFF Merkle map.
RandomAccessByteSource
An asynchronously readable, fixed-length random-access byte source.
RemoteManifestPolicy
Validation-only policy for future remote manifest fetching.
RemoteManifestResolver
Legacy single-request resolver retained for source compatibility.
ResourceReference
A C2PA resource reference such as a thumbnail or ingredient resource.
ResourceStore
In-memory resource storage that takes ownership by copying byte inputs.
SignatureInfo
Signature metadata extracted from a verified C2PA claim signature.
StatusCodes
Validation issues grouped by success, informational, and failure severity.
UpdateIntent
A builder intent for updating an existing parent manifest in place.
ValidationCode
A known C2PA SDK validation status code.
ValidationIssue
One validation status code emitted while checking a C2PA manifest.
ValidationResults
Validation results for the active manifest and ingredient deltas.
WritableByteSink
An asynchronously writable byte destination with append-only semantics.

Enums

AssertionEncoding
The wire encoding used for a custom assertion payload.
C2paBinaryOutput
Controls how binary values are represented in reader reports.
C2paDynamicAssertionEncoding
Encodings a dynamic assertion callback may produce.
C2paLegacyAssertionKind
Legacy JSON assertion namespace represented by the assertion label.
C2paManifestCompression
Compression state for a C2PA manifest store entry.
C2paParseStage
The reader stage that failed while parsing C2PA data.
C2paProgressPhase
A high-level SDK operation reported through C2paProgressEvent.
C2paRegionRangeType
Kind of region range payload in assertion metadata.
C2paRemoteTransportFailure
Transport-level failure categories for remote manifest fetches.
C2paShapeType
Geometric shape used by a spatial region range.
C2paStandardAssertionEncoding
Wire encoding used for a standard C2PA assertion payload.
C2paThumbnailKind
Thumbnail assertion target represented by a C2PA thumbnail label.
C2paUnitType
Coordinate unit for a region shape.
CawgIcaCompatibility
Selects stable CAWG 1.1 behavior or c2pa-rs 0.90.22 compatibility.
CawgStatusSeverity
Severity level attached to a CAWG validation status.
CawgValidationPolicy
A policy for handling multiple CAWG identity validation failures.
ClaimVersion
C2PA claim version discriminator.
DataHashBuildState
Ordered phases of embedded DataHash manifest construction.
DigitalSourceType
IPTC digital source type values used in C2PA action assertions.
IngredientAssertionVersion
C2PA ingredient assertion version.
Relationship
Ingredient relationship values used in ingredient assertions.
RemoteManifestPolicyViolation
Policy violations that can reject a remote manifest URI or response.
ResourceLimitKind
The resource quota that was exceeded.
ValidationClassification
The severity table used to interpret a validation status code.
ValidationSeverity
How a C2PA validation status affects trust in a manifest.
ValidationState
Overall validation state for an active manifest and its ingredients.

Extensions

C2paReaderReports on C2paReader
Deterministic report projections for a parsed C2paReader.
CawgBuilderExtension on C2paBuilder
Convenience methods for adding CAWG identity assertions to a builder.

Functions

c2paBuilderFromReader({required C2paReader reader, C2paContext? context, String signingAlgorithm = 'es256', Iterable<Uint8List> x5chain = const []}) → Future<C2paBuilder>
Creates an edit-mode C2paBuilder from a parsed reader.
createC2paHttpRemoteResolver({required RemoteManifestPolicy policy, C2paHttpTimeouts timeouts = const C2paHttpTimeouts(), C2paHttpCancellationCallback? isCancelled, C2paHostResolver? hostResolver}) → C2paHttpRemoteResolver
Creates an opt-in HTTP resolver for the current platform.
decodeClaim({required String label, required Uint8List bytes, required int maxNestingDepth, required Object? decoder(List<int>, {int maxNestingDepth})}) → Claim
Decodes a C2PA claim from CBOR bytes.
encodeC2paBuilderArchive(C2paBuilder builder) → Uint8List
Encodes builder as a deterministic C2PA JUMBF working archive.
loadC2paBuilderArchive({required List<int> bytes, required C2paContext context, C2paArchiveLoadOptions options = const C2paArchiveLoadOptions()}) → Future<C2paBuilder>
Loads a C2paBuilder from JUMBF or legacy ZIP archive bytes.
normalizeCollectionUri(String value) → String
Normalizes a collection URI to a safe relative path.
resolveRemoteManifest({required Uri uri, required RemoteManifestPolicy policy, required Duration timeout, C2paRemoteResolver? resolver, RemoteManifestResolver? legacyResolver, FutureOr<bool> isCancelled()?, Set<String> acceptedContentTypes = const {}}) → Future<Uint8List>
Resolves and validates remote C2PA manifest bytes.
unknownFieldsOf(Map<String, Object?> map, Set<String> known) → Map<String, Object?>
Collects entries whose keys are not part of the known field set.

Typedefs

C2paArchiveResourceResolver = FutureOr<Uint8List?> Function(C2paArchiveResourceRequest request)
Callback that resolves external resources while loading an archive.
C2paCancellationCallback = FutureOr<bool> Function()
Reports whether the current operation should be cancelled.
C2paDynamicAssertionCallback = Future<C2paDynamicAssertionOutput> Function(C2paDynamicAssertionRequest request)
Callback that produces dynamic assertion content after claim planning.
C2paHostResolver = Future<List<String>> Function(String host)
Resolver that maps a host name to IP address strings.
C2paHttpCancellationCallback = FutureOr<bool> Function()
Callback polled to cancel in-flight HTTP work.
C2paOcspTransport = Future<Uint8List> Function(Uri endpoint, Uint8List requestDer)
Sends an OCSP request to endpoint and returns a DER response.
C2paProgressCallback = FutureOr<void> Function(C2paProgressEvent event)
Receives progress events and may complete asynchronously.
C2paSignCallback = Future<Uint8List> Function(Uint8List data)
Callback that signs canonical claim bytes.
C2paTimestampCallback = Future<Uint8List> Function(Uint8List requestDer)
Callback that exchanges a timestamp request for a timestamp token.
C2paTrustConfig = C2paTrustConfiguration
Backwards-compatible alias for C2paTrustConfiguration.
C2paVerifyCallback = Future<bool> Function({required String algorithm, required Uint8List data, required Uint8List publicKey, required Uint8List signature})
Callback that verifies a signature over canonical claim bytes.
CawgIcaCredentialFactory = CawgIdentityClaimsCredential Function(CawgSignerPayload signerPayload)
Factory that creates an ICA credential from the signer payload.
CawgTimestampCallback = Future<Uint8List> Function(Uint8List counterSignatureBytes)
Callback that timestamps CAWG COSE counter-signature bytes.
DidResolver = C2paRemoteResolver
Resolver alias for DID-style remote identity documents.

Exceptions / Errors

C2paAmbiguousResourceException
Exception thrown when a resource lookup matches multiple resources.
C2paArchiveException
Exception thrown when a C2PA working archive cannot be processed.
C2paArchiveResourceException
Exception thrown when an archive resource cannot be read or written.
C2paDuplicateResourceException
Exception thrown when adding a resource URI that already exists.
C2paException
Base exception for failures reported by the C2PA SDK.
C2paFormatException
Exception thrown when C2PA bytes or metadata are structurally invalid.
C2paMalformedArchiveException
Exception thrown when a C2PA working archive is structurally invalid.
C2paNetworkException
Exception thrown when remote network resolution fails or is disallowed.
C2paParseException
Exception thrown when reading a source fails at a known parse stage.
C2paRemoteTransportException
Exception thrown when a remote manifest transport fails.
C2paResourceException
Exception thrown when manifest resources cannot be used.
C2paResourceLimitException
Exception thrown when resource storage exceeds configured limits.
C2paResourceNotFoundException
Exception thrown when a normalized resource URI has no stored bytes.
C2paResourceUriException
Exception thrown when a resource URI cannot be normalized safely.
C2paSigningException
Exception thrown when building or signing a manifest fails.
C2paTimestampException
Exception thrown when timestamp token creation or validation fails.
C2paTimestampLimitException
Exception thrown when a timestamp token exceeds its reserved byte range.
C2paUnsafeArchivePathException
Exception thrown when an archive entry path is unsafe to materialize.
C2paUnsupportedException
Exception thrown when an asset format or operation is not supported.
C2paUriPolicyException
Exception thrown when remote manifest policy rejects a URI or response.
C2paValidationException
Exception thrown when C2PA validation rules are not satisfied.
C2paVerificationException
Exception thrown when signature verification cannot be completed.