Content Credentials
What the manifest records, who signs it — and what it does not contain.
Content Credentials are the machine-readable provenance details inside the file — signed to the open C2PA standard. verstag embeds them into every output file while rendering.
The signed-in product speaks German, so its labels are quoted in German throughout, with the English rendering in italics.
What the manifest records
The producer. Always verstag, with the software version.
Creator and rights — only if you enter them. Settings → Content Credentials holds three fields: creator, copyright notice and credit line. What you leave empty is not in the manifest. verstag puts nothing there on its own — who owns a picture is something only you know.
The editing history. A list of actions in the order they happened.
The source material. The uploaded file is carried as an ingredient, titled "Source image" or "Source video" depending on the container.
A small thumbnail of its own. That is what a third-party verification tool shows as "this is what was signed".
Your workspace's usage statement — what the content may be used for. It sits together with the rights fields under Usage and rights.
What it does not contain
Nothing about you, your workspace or your customers. Neither your name nor a workspace or user identifier reaches the manifest.
Not what the source material was made with.
The editing history
The manifest always begins with c2pa.opened: verstag does not produce the
pixels, it opens the delivered material as an ingredient.
After that, each editing step gets its own action:
| What you do | What the manifest records | How the app displays it |
|---|---|---|
| Crop | c2pa.cropped | „Zugeschnitten“ (Cropped) |
| Scale to a format | c2pa.resized | „Skaliert“ (Resized) |
| Burn in the label | c2pa.addedText | „Text eingefügt“ (Text added) |
Steps that are switched off do not appear. A disabled label, a crop set to none and a resize set to none are skipped.
Each of these actions carries the source type „Von Menschen bearbeitet“ (edited by humans). That is a statement about the editing step, not about the origin of the picture. The asset's own origin is recorded separately and only ever taken over from the source material: where it is unknown, the field is absent entirely.
Foreign manifests are preserved
If the uploaded file already carried Content Credentials from elsewhere, they are preserved and carried forward as an ingredient. Only a previous verstag manifest is removed, and even that only where no foreign provenance sits beneath it.
For video no previous manifest is removed at all.
Who signs
There is no workspace-specific signing identity. Signing always happens with verstag's identity.
Where signing is not possible, no output is produced. An unsigned file is never served; the signed file is checked once more before it is stored.
What the seal „Von verstag signiert“ means
It appears only when two things hold at once: the manifest is structurally valid, and the producer of the current step begins with „verstag“.
"Structurally valid" only means the signature and the record are intact — a self-signed manifest satisfies it too. Whether the signer is on the official list is a second check; it is covered under Timestamps and trust.
When signing happens
At render time, not at export. The signing time and the certificate number then sit on the output. A signed manifest does not change afterwards — not even if you change your usage statement later.
Downloading the original bypasses signature and label; see What is signed and what is not.
Who reads this
Not only verstag. The record follows an open standard that platforms, search engines and verification tools can evaluate.
The display inside the application shows long chains shortened. The complete record is the manifest download — „Manifest herunterladen“ on the result card, „Content Credentials (JSON)“ in an output's menu.
On these pages
- Usage and rights — what third parties may do, and the creator and rights fields.
- Timestamps and trust — what "trusted" means and who decides it.
- What is signed and what is not — original versus output, and the tags in the downloads drawer.