Provenance chain and components

What came before this version, what went into it — and where the display stops.

Three words, three layers. The manifest is the signed provenance record of the current state. The chain is its predecessors. The components are what went into that state.

The signed-in product is in German, so its wording is quoted in German here, with the English rendering in italics.

The chain

Beside the result the chain runs from top to bottom: the newest state at the top, marked „Aktuell“ (Current), its predecessors below it. Each step shows the preview image carried in the manifest — where it says „kein Vorschaubild“ (no preview image), the signer embedded none — the signing time or „ohne Zeitstempel“ (without a timestamp), and the application that produced the manifest.

Third-party manifests are preserved. A camera, Adobe, an image generator — whatever history a file arrived with is never removed.

Process and components

Below the details sits the section „Prozess“ (Process): the application used, and under it the editing steps of the current manifest in the order they were recorded — „Geöffnet“ (Opened), „Zugeschnitten“ (Cropped), „Skaliert“ (Resized), „Text eingefügt“ (Text added) and the rest. A step that carries further detail can be expanded: time, agent, parameters, source type, description.

Beneath that the „Bestandteile“ (Components), each with its role: „Ausgangsbild“ (parent image), „Bestandteil“ (component) or „Eingabe“ (input). And, where the manifest names one, the issuer under „Ausgestellt von“ (Issued by).

The content classification

The statement about how a file came about — „Digitalaufnahme“ (digital capture), „Mit generativer KI erzeugt“ (created with generative AI), „Mit generativer KI bearbeitet“ (edited with generative AI), „Montage mit KI-Elementen“ (composite with AI elements), „Bildschirmaufnahme“ (screen capture) and others — comes from the IPTC vocabulary, a fixed list. verstag inherits it from the file on import and never invents it.

It appears in the details under „Quelle“ (Source) and, where an individual editing step carries one, under „Quelltyp“ (Source type) in the expanded step. Its absence does not mean “not an AI image” — most files do not carry the value at all.

Where the display stops

At most 10 chain steps and 20 components are shown. Where the chain is longer, the list ends with „… weitere Schritte vorhanden (Anzeige begrenzt)“ (… further steps present (display limited)). Very long values and descriptions are not shown.

Anyone who needs the complete record downloads the manifest. The button „Manifest herunterladen“ (Download manifest) sits on the result card and appears only if the file carries a manifest. The downloaded file takes the name of the checked one without its extension, plus .c2pa-manifest.jsonphoto.jpg becomes photo.c2pa-manifest.json. It holds the chain, the statements and the validation results.

For an asset in the library

There the chain is a button rather than an automatic display: „Herkunftsdetails anzeigen“ (Show provenance details). It appears only once the asset’s verification has finished.

Where it sits depends on whether the asset can be edited. For a file with an editor it is not on the page but inside the dialog „Technische Informationen“ (Technical information), which the button „Technische Details“ (Technical details) in the editor header opens; at the bottom of it, under the heading „Herkunftskette“ (Provenance chain). For a verification-only asset — a format that can be verified but not edited — it is on the page directly.

If the read takes too long it ends with „Die Prüfung dauert ungewöhnlich lange. Bitte erneut versuchen.“ (The check is taking unusually long. Please try again.)

Two answers look alike and are not:

  • „Diese Datei enthält kein C2PA-Manifest.“ (This file contains no C2PA manifest.) — there is none.
  • „Ein C2PA-Manifest ist vorhanden, aber die Herkunftskette konnte nicht gelesen werden.“ (A C2PA manifest is present, but the provenance chain could not be read.) — there is one, and reading it failed.

Manifests held outside the file

The standard allows the manifest to live outside the file, with only a reference to it inside. A file whose manifest sits only at an address is read as carrying none. Such files are rare.