Skip to main content
Encypher Logo

Apple iWork content provenance

A signed C2PA manifestC2PA manifest: The signed label itself: a small package inside a file that records who signed it, what they declared and how to check it. sits in its own entry inside the ZIP package that holds the file. It shows who signed the file and whether it changed, and anyone can check it free.

A file holds a signed label in four layers: who signed it, what they declared including AI use, a fingerprint of the content, and a signature that seals them together.
The label sits inside the file. It names the signer, carries what they declared, fingerprints the content, and is sealed by a signature.
Formats
3 formats that carry the label the same way.
Where the label sits
In its own entry inside the ZIP package that holds the file.
Standard
C2PAC2PA: The Coalition for Content Provenance and Authenticity: the group that publishes the open standard for content labels., the open standard for content labels.
Made for
Mac and iPad documents, Slide decks, Spreadsheets

What Encypher supports for Apple iWork files

  • SignSupported

    Encypher signs all 3 formats on this page, under C2PA 2.4.

  • CheckSupported

    Free in the browser checker, with no account.

  • Formal conformanceNot yet

    None is in our formal conformance record. That record is a narrower test than signing and checking.

How to check Apple iWork files

Four of the five answers a provenance check can give: Verified, Modified after signing, Issuer not recognized, and No provenance found. The fifth is Could not verify.
A check reports who signed and whether the content changed. It never says whether the content is true.
  1. Open the free checker.

    It runs in your browser. No account needed.

    Open the checker
  2. Add your file.

    Drop it in or pick it from your device.

  3. Read the result.

    It shows who signed and what they declared, such as AI use. It also shows if the file changed.

The 3 formats this guide covers

Each one carries the label the same way. Each is named with its media typeMIME type: The standard name for a file format, such as image/jpeg or audio/wav, that software uses to decide how to read a file..

Apple iWork files: what Encypher supports, live from our API.
FormatFile endingSignCheckMedia type
Apple Pages.pagesYesYesapplication/vnd.apple.pages
Apple Numbers.numbersYesYesapplication/vnd.apple.numbers
Apple Keynote.keyYesYesapplication/vnd.apple.keynote

Where the label sits in Apple iWork files

Pages, Numbers and Keynote can save a document as one ZIP file. The label is one more entry in it.

In a DOCX, EPUB, ODT or OXPS package, the label is one entry among the files inside the package.
Zip-based documents keep the label as one entry in the package.

Pages, Numbers and Keynote are Apple's office apps for documents, sheets and slides. Their single-file documents are ZIP packages.

What keeps the label on Apple iWork files

Three versions of a paper, preprint, accepted manuscript and version of record, each with its own seal, linked back to the version it was made from.
Each new version carries its own label and points back to the one it came from, so anyone can trace it to the first.
  • Signed test documents opened in Pages, Numbers and Keynote.
  • This covers single-file documents, not folder bundles or older iWork files.
  • Editing or saving in the app can change or remove the label. Check the saved copy.
  • Exporting to PDF or Office makes a new file without the label.

For engineers

Show the technical detail
Embedding
JUMBF manifest store in the META-INF/content_credential.c2pa entry of the ZIP package, with a c2pa.hash.collection.data hard binding over every entry and the central directory (iWork ZIP documents; the other entries stay byte for byte unchanged)
Signing versions
C2PA 2.4, per format in the live matrix
Verification
Any version. The checker reads any C2PA manifest it can parse, and the report names the version it checked against.
How each of the 3 formats signs through the API.
FormatMedia typeSign with
Apple Pagesapplication/vnd.apple.pagesPOST /api/v1/sign/media
Apple Numbersapplication/vnd.apple.numbersPOST /api/v1/sign/media
Apple Keynoteapplication/vnd.apple.keynotePOST /api/v1/sign/media
# The format is read from the file itself.
curl -X POST https://api.encypher.com/api/v1/sign/media \
  -H "Authorization: Bearer $ENCYPHER_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -F "file=@example.pages"

Support rows come from the live API capability matrix. Full reference: C2PA media types.

Create. Mark. Endure.

Sign your first Apple iWork file free. Checking stays free for everyone.