Skip to main content
Encypher Logo

Markup and code content provenance

A signed C2PA manifestC2PA manifest: The signed label itself: a small package inside a file that records who signed it, what they declared and how to check it. sits in the characters, or in a comment block the standard defines for the format. It shows who signed the file and whether it changed, and anyone can check it free.

A file holds a signed label in four layers: who signed it, what they declared including AI use, a fingerprint of the content, and a signature that seals them together.
The label sits inside the file. It names the signer, carries what they declared, fingerprints the content, and is sealed by a signature.
Formats
10 formats that carry the label the same way.
Where the label sits
In the characters, or in a comment block the standard defines for the format.
Standard
C2PAC2PA: The Coalition for Content Provenance and Authenticity: the group that publishes the open standard for content labels., the open standard for content labels.
Made for
Web pages, Documentation, Config files, Source code

What Encypher supports for markup and code files

  • SignSupported

    Encypher signs all 10 formats on this page, under C2PA 2.4.

  • CheckPartial

    The free checker reads 9 of the 10 formats. The table below names each one.

  • Formal conformanceNot yet

    None is in our formal conformance record. That record is a narrower test than signing and checking.

How to check markup and code files

Four of the five answers a provenance check can give: Verified, Modified after signing, Issuer not recognized, and No provenance found. The fifth is Could not verify.
A check reports who signed and whether the content changed. It never says whether the content is true.
  1. Open the free checker.

    It runs in your browser. No account needed.

    Open the checker
  2. Paste the text or add the file.

    Drop it in or pick it from your device.

  3. Read the result.

    It shows who signed and what they declared, such as AI use. It also shows if the file changed.

The 10 formats this guide covers

Each one carries the label the same way. Each is named with its media typeMIME type: The standard name for a file format, such as image/jpeg or audio/wav, that software uses to decide how to read a file..

markup and code files: what Encypher supports, live from our API.
FormatFile endingSignCheckMedia type
HTML.html, .htmYesYestext/html
XHTML.xhtmlYesYesapplication/xhtml+xml
XML.xmlYesYestext/xml
XML (as application/xml).xmlYesYesapplication/xml
Markdown.mdYesYestext/markdown
CSS.cssYesYestext/css
JavaScript.jsYesYesapplication/javascript
YAML.yaml, .ymlYesYesapplication/yaml
TOML.tomlYesYesapplication/toml
Python.pyYesNotext/x-python

Where the label sits in markup and code files

Markup, code and config files have a comment syntax. The C2PA standard lets the label sit in one comment block, at the start or the end of the file. In HTML it sits in a script element of its own.

Two files with the label written into them. In article.md, the first line is a comment that holds a C2PA manifest block, starting BEGIN C2PA MANIFEST. In index.html, the head holds a script element typed application/c2pa that carries the label. A checker reads either one back: signed by Town Daily, made with AI: no, unchanged since signing.
Code and markup files carry the label in their own syntax: a comment line in Markdown or code, a script element in an HTML page. A checker reads who signed, what they declared about AI, and whether the file changed.

HTML, XML, Markdown, CSS, JavaScript, YAML, TOML and Python files can carry the label in their characters or in one comment block.

What keeps the label on markup and code files

Signed text copied into most apps and sites keeps its label; some apps strip the invisible characters and the check then finds no label; editing the words breaks the seal and the check shows the change.
Copy and paste keeps the label in most apps. Some apps strip it, and any edit shows up when the text is checked.
  • Copying the file as it is keeps the label.
  • A minifier, formatter or build step that drops comments or rewrites the text drops the label. Sign the file you ship.
  • A change to the text after signing shows as a change.

For engineers

Show the technical detail
Embedding
POST /api/v1/sign: C2PA unstructured text embedding (2.4 Section A.8), with the media type recorded as dc:format. POST /api/v1/sign/registered-media: C2PA 2.4 structured text (Section A.9), a BEGIN C2PA MANIFEST comment block; HTML uses Section A.7, a script element of type application/c2pa.
Signing versions
C2PA 2.4, per format in the live matrix
Verification
Any version. The checker reads any C2PA manifest it can parse, and the report names the version it checked against.
How each of the 10 formats signs through the API.
FormatMedia typeSign with
HTMLtext/htmlPOST /api/v1/sign
XHTMLapplication/xhtml+xmlPOST /api/v1/sign
XMLtext/xmlPOST /api/v1/sign
XML (as application/xml)application/xmlPOST /api/v1/sign
Markdowntext/markdownPOST /api/v1/sign
CSStext/cssPOST /api/v1/sign
JavaScriptapplication/javascriptPOST /api/v1/sign
YAMLapplication/yamlPOST /api/v1/sign
TOMLapplication/tomlPOST /api/v1/sign
Pythontext/x-pythonPOST /api/v1/sign/registered-media
# The signed text comes back in data.document.signed_text.
curl -X POST https://api.encypher.com/api/v1/sign \
  -H "Authorization: Bearer $ENCYPHER_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{"text": "<file contents>", "options": {"content_mime_type": "text/html"}}'

Support rows come from the live API capability matrix. Full reference: C2PA media types.

Create. Mark. Endure.

Sign your first markup and code file free. Checking stays free for everyone.