Content Credentials

What the manifest records, who signs it — and what it does not contain.

Content Credentials are the machine-readable provenance details inside the file — signed to the open C2PA standard. verstag embeds them into every output file while rendering.

The signed-in product speaks German, so its labels are quoted in German throughout, with the English rendering in italics.

What the manifest records

The producer. Always verstag, with the software version.

Creator and rights — only if you enter them. Settings → Content Credentials holds three fields: creator, copyright notice and credit line. What you leave empty is not in the manifest. verstag puts nothing there on its own — who owns a picture is something only you know.

The editing history. A list of actions in the order they happened.

The source material. The uploaded file is carried as an ingredient, titled "Source image" or "Source video" depending on the container.

A small thumbnail of its own. That is what a third-party verification tool shows as "this is what was signed".

Your workspace's usage statement — what the content may be used for. It sits together with the rights fields under Usage and rights.

What it does not contain

Nothing about you, your workspace or your customers. Neither your name nor a workspace or user identifier reaches the manifest.

Not what the source material was made with.

The editing history

The manifest always begins with c2pa.opened: verstag does not produce the pixels, it opens the delivered material as an ingredient.

After that, each editing step gets its own action:

What you doWhat the manifest recordsHow the app displays it
Cropc2pa.cropped„Zugeschnitten“ (Cropped)
Scale to a formatc2pa.resized„Skaliert“ (Resized)
Burn in the labelc2pa.addedText„Text eingefügt“ (Text added)

Steps that are switched off do not appear. A disabled label, a crop set to none and a resize set to none are skipped.

Each of these actions carries the source type „Von Menschen bearbeitet“ (edited by humans). That is a statement about the editing step, not about the origin of the picture. The asset's own origin is recorded separately and only ever taken over from the source material: where it is unknown, the field is absent entirely.

Foreign manifests are preserved

If the uploaded file already carried Content Credentials from elsewhere, they are preserved and carried forward as an ingredient. Only a previous verstag manifest is removed, and even that only where no foreign provenance sits beneath it.

For video no previous manifest is removed at all.

Who signs

There is no workspace-specific signing identity. Signing always happens with verstag's identity.

Where signing is not possible, no output is produced. An unsigned file is never served; the signed file is checked once more before it is stored.

What the seal „Von verstag signiert“ means

It appears only when two things hold at once: the manifest is structurally valid, and the producer of the current step begins with „verstag“.

"Structurally valid" only means the signature and the record are intact — a self-signed manifest satisfies it too. Whether the signer is on the official list is a second check; it is covered under Timestamps and trust.

When signing happens

At render time, not at export. The signing time and the certificate number then sit on the output. A signed manifest does not change afterwards — not even if you change your usage statement later.

Downloading the original bypasses signature and label; see What is signed and what is not.

Who reads this

Not only verstag. The record follows an open standard that platforms, search engines and verification tools can evaluate.

The display inside the application shows long chains shortened. The complete record is the manifest download — „Manifest herunterladen“ on the result card, „Content Credentials (JSON)“ in an output's menu.

On these pages