Skip to main content
Encypher Logo

ZIP package content provenance

A signed C2PA manifestC2PA manifest: The signed label itself: a small package inside a file that records who signed it, what they declared and how to check it. sits in its own entry inside the ZIP package that holds the file. It shows who signed the file and whether it changed, and anyone can check it free.

A file holds a signed label in four layers: who signed it, what they declared including AI use, a fingerprint of the content, and a signature that seals them together.
The label sits inside the file. It names the signer, carries what they declared, fingerprints the content, and is sealed by a signature.
Formats
7 formats that carry the label the same way.
Where the label sits
In its own entry inside the ZIP package that holds the file.
Standard
C2PAC2PA: The Coalition for Content Provenance and Authenticity: the group that publishes the open standard for content labels., the open standard for content labels.
Made for
Digital painting, Page layout handoff, Maps, 3D printing, Archives

What Encypher supports for ZIP package files

  • SignSupported

    Encypher signs all 7 formats on this page, under C2PA 2.2 and 2.4.

  • CheckPartial

    The free checker reads 6 of the 7 formats. The table below names each one.

  • Formal conformanceNot yet

    None is in our formal conformance record. That record is a narrower test than signing and checking.

How to check ZIP package files

Four of the five answers a provenance check can give: Verified, Modified after signing, Issuer not recognized, and No provenance found. The fifth is Could not verify.
A check reports who signed and whether the content changed. It never says whether the content is true.
  1. Open the free checker.

    It runs in your browser. No account needed.

    Open the checker
  2. Add your file.

    Drop it in or pick it from your device.

  3. Read the result.

    It shows who signed and what they declared, such as AI use. It also shows if the file changed.

The 7 formats this guide covers

Each one carries the label the same way. Each is named with its media typeMIME type: The standard name for a file format, such as image/jpeg or audio/wav, that software uses to decide how to read a file..

ZIP package files: what Encypher supports, live from our API.
FormatFile endingSignCheckMedia type
Krita drawing.kra, .krzYesYesapplication/x-krita
OpenRaster drawing.oraYesYesimage/openraster
InDesign package (IDML).idmlYesYesapplication/vnd.adobe.indesign-idml-package
Google Earth map (KMZ).kmzYesYesapplication/vnd.google-earth.kmz
3D print file (3MF).3mfYesYesmodel/3mf
ZIP archive.zipYesYesapplication/zip
Other ZIP-based filesVariousYesNoapplication/x-zip-based

Where the label sits in ZIP package files

Krita drawings, InDesign packages, Google Earth maps, 3D print files and plain ZIP archives are all ZIP packages. The label is one more entry in each.

In a DOCX, EPUB, ODT or OXPS package, the label is one entry among the files inside the package.
Zip-based documents keep the label as one entry in the package.

Many creative, map and 3D formats are ZIP packages under another name. A plain ZIP archive, and a Sketch file signed as one, carry the label the same way.

What keeps the label on ZIP package files

Three versions of a paper, preprint, accepted manuscript and version of record, each with its own seal, linked back to the version it was made from.
Each new version carries its own label and points back to the one it came from, so anyone can trace it to the first.
  • Krita opens signed Krita and OpenRaster files and shows the same pixels.
  • InDesign, Google Earth and slicer apps were not tested. The package checks passed.
  • A change to any entry after signing shows as a change.
  • Saving again in the app can drop the label. Sign the final copy.

For engineers

Show the technical detail
Embedding
JUMBF manifest store in the META-INF/content_credential.c2pa entry of the ZIP package, with a c2pa.hash.collection.data hard binding over every entry and the central directory. In 3MF, the label part is also declared as application/c2pa in [Content_Types].xml.
Signing versions
C2PA 2.2, 2.4, per format in the live matrix
Verification
Any version. The checker reads any C2PA manifest it can parse, and the report names the version it checked against.
How each of the 7 formats signs through the API.
FormatMedia typeSign with
Krita drawingapplication/x-kritaPOST /api/v1/sign/registered-media
OpenRaster drawingimage/openrasterPOST /api/v1/sign/registered-media
InDesign package (IDML)application/vnd.adobe.indesign-idml-packagePOST /api/v1/sign/registered-media
Google Earth map (KMZ)application/vnd.google-earth.kmzPOST /api/v1/sign/registered-media
3D print file (3MF)model/3mfPOST /api/v1/sign/registered-media
ZIP archiveapplication/zipPOST /api/v1/sign/declared-media
Other ZIP-based filesapplication/x-zip-basedPOST /api/v1/sign/declared-media
# Returns the signed file as asset_base64.
curl -X POST https://api.encypher.com/api/v1/sign/registered-media \
  -H "Authorization: Bearer $ENCYPHER_API_KEY" \
  -F "file=@example.kra" \
  -F "media_type=application/x-krita" \
  -F "spec=2.4"

Support rows come from the live API capability matrix. Full reference: C2PA media types.

Create. Mark. Endure.

Sign your first ZIP package file free. Checking stays free for everyone.