Markup and code content provenance
A signed C2PA manifestC2PA manifest: The signed label itself: a small package inside a file that records who signed it, what they declared and how to check it. sits in the characters, or in a comment block the standard defines for the format. It shows who signed the file and whether it changed, and anyone can check it free.

- Formats
- 10 formats that carry the label the same way.
- Where the label sits
- In the characters, or in a comment block the standard defines for the format.
- Standard
- C2PAC2PA: The Coalition for Content Provenance and Authenticity: the group that publishes the open standard for content labels., the open standard for content labels.
- Made for
- Web pages, Documentation, Config files, Source code
What Encypher supports for markup and code files
- SignSupported
Encypher signs all 10 formats on this page, under C2PA 2.4.
- CheckPartial
The free checker reads 9 of the 10 formats. The table below names each one.
- Formal conformanceNot yet
None is in our formal conformance record. That record is a narrower test than signing and checking.
How to check markup and code files

Open the free checker.
It runs in your browser. No account needed.
Open the checkerPaste the text or add the file.
Drop it in or pick it from your device.
Read the result.
It shows who signed and what they declared, such as AI use. It also shows if the file changed.
The 10 formats this guide covers
Each one carries the label the same way. Each is named with its media typeMIME type: The standard name for a file format, such as image/jpeg or audio/wav, that software uses to decide how to read a file..
| Format | File ending | Sign | Check | Media type |
|---|---|---|---|---|
| HTML | .html, .htm | Yes | Yes | text/html |
| XHTML | .xhtml | Yes | Yes | application/xhtml+xml |
| XML | .xml | Yes | Yes | text/xml |
| XML (as application/xml) | .xml | Yes | Yes | application/xml |
| Markdown | .md | Yes | Yes | text/markdown |
| CSS | .css | Yes | Yes | text/css |
| JavaScript | .js | Yes | Yes | application/javascript |
| YAML | .yaml, .yml | Yes | Yes | application/yaml |
| TOML | .toml | Yes | Yes | application/toml |
| Python | .py | Yes | No | text/x-python |
Where the label sits in markup and code files
Markup, code and config files have a comment syntax. The C2PA standard lets the label sit in one comment block, at the start or the end of the file. In HTML it sits in a script element of its own.

HTML, XML, Markdown, CSS, JavaScript, YAML, TOML and Python files can carry the label in their characters or in one comment block.
What keeps the label on markup and code files

- Copying the file as it is keeps the label.
- A minifier, formatter or build step that drops comments or rewrites the text drops the label. Sign the file you ship.
- A change to the text after signing shows as a change.
For engineers
Show the technical detail
- Embedding
- POST /api/v1/sign: C2PA unstructured text embedding (2.4 Section A.8), with the media type recorded as dc:format. POST /api/v1/sign/registered-media: C2PA 2.4 structured text (Section A.9), a BEGIN C2PA MANIFEST comment block; HTML uses Section A.7, a script element of type application/c2pa.
- Signing versions
- C2PA 2.4, per format in the live matrix
- Verification
- Any version. The checker reads any C2PA manifest it can parse, and the report names the version it checked against.
| Format | Media type | Sign with |
|---|---|---|
| HTML | text/html | POST /api/v1/sign |
| XHTML | application/xhtml+xml | POST /api/v1/sign |
| XML | text/xml | POST /api/v1/sign |
| XML (as application/xml) | application/xml | POST /api/v1/sign |
| Markdown | text/markdown | POST /api/v1/sign |
| CSS | text/css | POST /api/v1/sign |
| JavaScript | application/javascript | POST /api/v1/sign |
| YAML | application/yaml | POST /api/v1/sign |
| TOML | application/toml | POST /api/v1/sign |
| Python | text/x-python | POST /api/v1/sign/registered-media |
# The signed text comes back in data.document.signed_text.
curl -X POST https://api.encypher.com/api/v1/sign \
-H "Authorization: Bearer $ENCYPHER_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"text": "<file contents>", "options": {"content_mime_type": "text/html"}}'# Returns the signed file as asset_base64.
curl -X POST https://api.encypher.com/api/v1/sign/registered-media \
-H "Authorization: Bearer $ENCYPHER_API_KEY" \
-F "file=@example.py" \
-F "media_type=text/x-python" \
-F "spec=2.4"curl -X POST https://api.encypher.com/api/v1/public/verify \
-H "Content-Type: application/json" \
-d '{"text": "<signed text>"}'Support rows come from the live API capability matrix. Full reference: C2PA media types.
Create. Mark. Endure.
Sign your first markup and code file free. Checking stays free for everyone.