ZIP package content provenance
A signed C2PA manifestC2PA manifest: The signed label itself: a small package inside a file that records who signed it, what they declared and how to check it. sits in its own entry inside the ZIP package that holds the file. It shows who signed the file and whether it changed, and anyone can check it free.

- Formats
- 7 formats that carry the label the same way.
- Where the label sits
- In its own entry inside the ZIP package that holds the file.
- Standard
- C2PAC2PA: The Coalition for Content Provenance and Authenticity: the group that publishes the open standard for content labels., the open standard for content labels.
- Made for
- Digital painting, Page layout handoff, Maps, 3D printing, Archives
What Encypher supports for ZIP package files
- SignSupported
Encypher signs all 7 formats on this page, under C2PA 2.2 and 2.4.
- CheckPartial
The free checker reads 6 of the 7 formats. The table below names each one.
- Formal conformanceNot yet
None is in our formal conformance record. That record is a narrower test than signing and checking.
How to check ZIP package files

Open the free checker.
It runs in your browser. No account needed.
Open the checkerAdd your file.
Drop it in or pick it from your device.
Read the result.
It shows who signed and what they declared, such as AI use. It also shows if the file changed.
The 7 formats this guide covers
Each one carries the label the same way. Each is named with its media typeMIME type: The standard name for a file format, such as image/jpeg or audio/wav, that software uses to decide how to read a file..
| Format | File ending | Sign | Check | Media type |
|---|---|---|---|---|
| Krita drawing | .kra, .krz | Yes | Yes | application/x-krita |
| OpenRaster drawing | .ora | Yes | Yes | image/openraster |
| InDesign package (IDML) | .idml | Yes | Yes | application/vnd.adobe.indesign-idml-package |
| Google Earth map (KMZ) | .kmz | Yes | Yes | application/vnd.google-earth.kmz |
| 3D print file (3MF) | .3mf | Yes | Yes | model/3mf |
| ZIP archive | .zip | Yes | Yes | application/zip |
| Other ZIP-based files | Various | Yes | No | application/x-zip-based |
Where the label sits in ZIP package files
Krita drawings, InDesign packages, Google Earth maps, 3D print files and plain ZIP archives are all ZIP packages. The label is one more entry in each.

Many creative, map and 3D formats are ZIP packages under another name. A plain ZIP archive, and a Sketch file signed as one, carry the label the same way.
What keeps the label on ZIP package files

- Krita opens signed Krita and OpenRaster files and shows the same pixels.
- InDesign, Google Earth and slicer apps were not tested. The package checks passed.
- A change to any entry after signing shows as a change.
- Saving again in the app can drop the label. Sign the final copy.
For engineers
Show the technical detail
- Embedding
- JUMBF manifest store in the META-INF/content_credential.c2pa entry of the ZIP package, with a c2pa.hash.collection.data hard binding over every entry and the central directory. In 3MF, the label part is also declared as application/c2pa in [Content_Types].xml.
- Signing versions
- C2PA 2.2, 2.4, per format in the live matrix
- Verification
- Any version. The checker reads any C2PA manifest it can parse, and the report names the version it checked against.
| Format | Media type | Sign with |
|---|---|---|
| Krita drawing | application/x-krita | POST /api/v1/sign/registered-media |
| OpenRaster drawing | image/openraster | POST /api/v1/sign/registered-media |
| InDesign package (IDML) | application/vnd.adobe.indesign-idml-package | POST /api/v1/sign/registered-media |
| Google Earth map (KMZ) | application/vnd.google-earth.kmz | POST /api/v1/sign/registered-media |
| 3D print file (3MF) | model/3mf | POST /api/v1/sign/registered-media |
| ZIP archive | application/zip | POST /api/v1/sign/declared-media |
| Other ZIP-based files | application/x-zip-based | POST /api/v1/sign/declared-media |
# Returns the signed file as asset_base64.
curl -X POST https://api.encypher.com/api/v1/sign/registered-media \
-H "Authorization: Bearer $ENCYPHER_API_KEY" \
-F "file=@example.kra" \
-F "media_type=application/x-krita" \
-F "spec=2.4"# The engine still checks that the bytes are a real ZIP package.
curl -X POST https://api.encypher.com/api/v1/sign/declared-media \
-H "Authorization: Bearer $ENCYPHER_API_KEY" \
-F "file=@example.zip" \
-F "declared_media_type=application/zip"curl -X POST https://api.encypher.com/api/v1/public/verify/media \
-F "file=@signed-example.kra" \
-F "mime_type=application/x-krita"Support rows come from the live API capability matrix. Full reference: C2PA media types.
Create. Mark. Endure.
Sign your first ZIP package file free. Checking stays free for everyone.