C2PA Store

C2PA Manifest Repository · Soft Binding Resolution API · io.iscc.v0

Keep Content Credentials findable after metadata is stripped

This store keeps C2PA Manifest Stores and serves each one at a stable manifest address. It finds them by soft binding through the C2PA Soft Binding Resolution API, and declares their ISCC on the ISCC Discovery Protocol, so that the ISCC C2PA Resolver finds them network-wide.

API reference OpenAPI GitHub

Experimental (beta, MVP). Provided as is, without warranty of any kind. The API, the declaration behaviour and the public instances may change in breaking ways before version 1.0. The test instance declares on the ISCC testnet; its data is disposable.

How it works

An app publishes a signed Manifest Store. The store declares its ISCC. Anyone holding a copy of the content, even with every byte of metadata gone, computes the ISCC and gets the manifest back.

From publishing to recovery Four parts from left to right: your app, this C2PA Store, an ISCC hub and the ISCC C2PA Resolver. Step 1: the app publishes a C2PA Manifest Store to the store. Step 2: the store declares the ISCC of the content on the ISCC hub, with the manifest address as gateway URL. Step 3: the resolver looks up an ISCC on the hub and fetches the manifest from the store. Your app C2PA SIGNER C2PA Store THIS REPOSITORY ISCC hub DISCOVERY PROTOCOL C2PA Resolver NETWORK-WIDE SEARCH 1 PUBLISH 2 DECLARE LOOK UP 3 RECOVER From publishing to recovery Four parts from top to bottom: your app, this C2PA Store, an ISCC hub and the ISCC C2PA Resolver. Step 1: the app publishes a C2PA Manifest Store to the store. Step 2: the store declares the ISCC of the content on the ISCC hub, with the manifest address as gateway URL. Step 3: the resolver looks up an ISCC on the hub and fetches the manifest from the store. Your app C2PA SIGNER C2PA Store THIS REPOSITORY ISCC hub DISCOVERY PROTOCOL C2PA Resolver NETWORK-WIDE SEARCH 1 PUBLISH 2 DECLARE LOOK UP 3 RECOVER
The manifest address is the gateway URL of the ISCC declaration: whoever finds the declaration finds the manifest.
  1. Publish

    Your app signs content with C2PA, adds an io.iscc.v0 soft binding and posts the Manifest Store. The store checks it with c2pa-rs, indexes the soft bindings of the active manifest and serves it byte for byte at its manifest address.

  2. Declare

    The store signs an ISCC declaration with its own did:web key and registers it on an ISCC hub, with the manifest address as gateway URL. Apps that declare by themselves upload with declare=false.

  3. Recover

    Metadata stripped, file re-encoded? Compute the ISCC of the content and ask this store directly, or ask the ISCC C2PA Resolver, which searches every declaration on the network and leads back to the manifest address.

Use it

Plain HTTP, no account. The routes follow the C2PA Soft Binding Resolution API; the API reference has every parameter and status code.

Publish a Manifest Store

Send the bytes of a C2PA Manifest Store. Uploading the same bytes again returns the same answer.

Request
curl --data-binary @manifest.c2pa -H "Content-Type: application/c2pa" "https://c2pa-store-test.iscc.io/v1/manifests"
Answer · 200
{
  "manifestId": "urn:c2pa:F9168C5E-CEB2-4FAA-B6BF-329BF39FA1E4",
  "manifestUrl": "https://c2pa-store-test.iscc.io/v1/manifests/urn%3Ac2pa%3AF9168C5E-CEB2-4FAA-B6BF-329BF39FA1E4",
  "declaration": {
    "status": "declared",
    "isccId": "ISCC:MAIGKV5FAAXOXYAB",
    "hub": "https://staging.iscc.id"
  }
}

The declaration status is declared, pending (the hub was unavailable; the store retries), failed, skipped (no whole-asset io.iscc.v0 binding with a 256-bit Data-Code and Instance-Code, or declare=false) or disabled (this instance does not declare).

Fetch by manifest ID

Percent-encode the manifest ID. Unknown manifests answer 404, deleted ones 410.

Request
curl -o manifest.c2pa "https://c2pa-store-test.iscc.io/v1/manifests/urn%3Ac2pa%3AF9168C5E-CEB2-4FAA-B6BF-329BF39FA1E4"

Find by soft binding

The value is the base64 ISCC-SEQ of the asset (IEP-0020), percent-encoded.

Request
curl "https://c2pa-store-test.iscc.io/v1/matches/byBinding?alg=io.iscc.v0&value=<percent-encoded value>"
Answer · 200
{"matches": [{
  "manifestId": "urn:c2pa:F9168C5E-…",
  "similarityScore": 97,
  "isccId": "ISCC:MAIGKV5FAAXOXYAB"
}]}

Other algorithms on the C2PA Soft Binding Algorithm List match exactly. Long values go in a JSON body to POST /v1/matches/byBinding.

Discover the service

Capabilities, indexed algorithms, status and the C2PA discovery document.

Requests
curl "https://c2pa-store-test.iscc.io/v1/services/capabilities"curl "https://c2pa-store-test.iscc.io/v1/services/supportedAlgorithms"
Requests
curl "https://c2pa-store-test.iscc.io/v1/services/status"curl "https://c2pa-store-test.iscc.io/.well-known/c2pa-soft-binding-resolution"

Numbers

Counted from the database, refreshed every 30 seconds.

Manifestsstored and served
1
Trusted signersmanifests signed with a credential on the C2PA trust list
0
Declaredon the ISCC Discovery Protocol
1
Pendingdeclarations the store retries
0

Soft bindings per algorithm

  • io.iscc.v0 1

Declarations by status

  • declared 1

0 deleted manifests not counted above.

This instance

What this deployment is, who signs its declarations and what it accepts.

Host
c2pa-store-test.iscc.io
Identity
did:web:c2pa-store-test.iscc.io

Signs ISCC declarations with the Ed25519 key in its did:web document.

ISCC hub
https://staging.iscc.id

Holds the declarations, each with its manifest address as gateway URL.

Uploads
Open, limited per client address, up to 2 MB per Manifest Store.

Only Manifest Stores that c2pa-rs reads and whose claim signature verifies. Failed hard bindings and signers outside the C2PA trust list are recorded, not refused. Deleting needs the operator token.

Data
Public: anyone can fetch and query what is stored here.

Experimental service. Data on the testnet is disposable and may be removed without notice.

Version
0.1.0