Skip to main content
Encypher Logo

OpenDocument content provenance

A signed C2PA manifestC2PA manifest: The signed label itself: a small package inside a file that records who signed it, what they declared and how to check it. sits in its own entry inside the ZIP package that holds the file. It shows who signed the file and whether it changed, and anyone can check it free.

A file holds a signed label in four layers: who signed it, what they declared including AI use, a fingerprint of the content, and a signature that seals them together.
The label sits inside the file. It names the signer, carries what they declared, fingerprints the content, and is sealed by a signature.
Formats
4 formats that carry the label the same way.
Where the label sits
In its own entry inside the ZIP package that holds the file.
Standard
C2PAC2PA: The Coalition for Content Provenance and Authenticity: the group that publishes the open standard for content labels., the open standard for content labels.
Made for
Government documents, Open-source office tools, Long-term archives

What Encypher supports for OpenDocument files

  • SignSupported

    Encypher signs all 4 formats on this page, under C2PA 2.2 and 2.4.

  • CheckSupported

    Free in the browser checker, with no account.

  • Formal conformanceNot yet

    None is in our formal conformance record. That record is a narrower test than signing and checking.

How to check OpenDocument files

Four of the five answers a provenance check can give: Verified, Modified after signing, Issuer not recognized, and No provenance found. The fifth is Could not verify.
A check reports who signed and whether the content changed. It never says whether the content is true.
  1. Open the free checker.

    It runs in your browser. No account needed.

    Open the checker
  2. Add your file.

    Drop it in or pick it from your device.

  3. Read the result.

    It shows who signed and what they declared, such as AI use. It also shows if the file changed.

The 4 formats this guide covers

Each one carries the label the same way. Each is named with its media typeMIME type: The standard name for a file format, such as image/jpeg or audio/wav, that software uses to decide how to read a file..

OpenDocument files: what Encypher supports, live from our API.
FormatFile endingSignCheckMedia type
OpenDocument text (ODT).odtYesYesapplication/vnd.oasis.opendocument.text
OpenDocument sheet (ODS).odsYesYesapplication/vnd.oasis.opendocument.spreadsheet
OpenDocument slides (ODP).odpYesYesapplication/vnd.oasis.opendocument.presentation
OpenDocument drawing (ODG).odgYesYesapplication/vnd.oasis.opendocument.graphics

Where the label sits in OpenDocument files

An OpenDocument file is a ZIP package of parts. The label is one more entry in that package.

In a DOCX, EPUB, ODT or OXPS package, the label is one entry among the files inside the package.
Zip-based documents keep the label as one entry in the package.

OpenDocument is the open office format for text, sheets, slides and drawings. Public bodies and LibreOffice users work in it.

What keeps the label on OpenDocument files

Three versions of a paper, preprint, accepted manuscript and version of record, each with its own seal, linked back to the version it was made from.
Each new version carries its own label and points back to the one it came from, so anyone can trace it to the first.
  • Sending, copying and storing the file keep the label.
  • A change to the content after signing shows as a change.
  • LibreOffice 7.4 will not open an OpenDocument file that carries the label entry, which the C2PA standard requires. Test the signed file in the app your readers use.
  • Saving as PDF makes a new file without the label. Sign the PDF as well.

For engineers

Show the technical detail
Embedding
JUMBF manifest store in the META-INF/content_credential.c2pa entry of the ZIP package, with a c2pa.hash.collection.data hard binding over every entry and the central directory (ODF)
Signing versions
C2PA 2.2, 2.4, per format in the live matrix
Verification
Any version. The checker reads any C2PA manifest it can parse, and the report names the version it checked against.
How each of the 4 formats signs through the API.
FormatMedia typeSign with
OpenDocument text (ODT)application/vnd.oasis.opendocument.textPOST /api/v1/sign/media
OpenDocument sheet (ODS)application/vnd.oasis.opendocument.spreadsheetPOST /api/v1/sign/registered-media
OpenDocument slides (ODP)application/vnd.oasis.opendocument.presentationPOST /api/v1/sign/registered-media
OpenDocument drawing (ODG)application/vnd.oasis.opendocument.graphicsPOST /api/v1/sign/registered-media
# The format is read from the file itself.
curl -X POST https://api.encypher.com/api/v1/sign/media \
  -H "Authorization: Bearer $ENCYPHER_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -F "file=@example.odt"

Support rows come from the live API capability matrix. Full reference: C2PA media types.

Create. Mark. Endure.

Sign your first OpenDocument file free. Checking stays free for everyone.