Conformance corpus

C2PA test vectors, with the answer key.

One small signed (or unsigned) sample per verification state, each paired with the exact result a verifier should report. Download any file, drop it on verify.reconize.me, and confirm the verdict matches.

01

Download a sample

Each file below is a real signed asset (or a plain control), hosted for anyone to fetch.

02

Check it

Drop it on verify.reconize.me, or run it through any C2PA verifier you are testing.

03

Compare

Confirm the verifier reports the expected verdict listed here (and in the machine-readable manifest).

The vectors

Signed by Sample Creator (Lil Dog Productions, LLC), identity credential did:web:id.reconize.me. Every Reconize signature carries a Do Not Train assertion, so each trusted sample also demonstrates the machine-readable no-training state.

trusted trusted-photo.jpg image/jpeg · 626 KB
Expected: Verified: signed and unaltered

Signed by a trusted issuer, content unaltered since signing. Carries the CAWG X.509 + ICA identity credential with 2 vouched channels and a Do Not Train assertion.

sha256 babec9b1467b96af373b386f08fa9f76725dc86b2f4783d975e38d3306e4594a
trusted trusted-print.tiff image/tiff · 2.3 MB
Expected: Verified: signed and unaltered

Signed by a trusted issuer, content unaltered since signing. TIFF signed with C2PA only (no pixel-watermark layer). Identity credential valid, Do Not Train declared.

sha256 db0e49c44b7fa93bb3be374d2becee43c0be74e68419aa0f797f7e2a501fde1d
trusted trusted-video.mov video/quicktime · 6.8 MB
Expected: Verified: signed and unaltered

Signed by a trusted issuer, content unaltered since signing. Video carries pixel + audio watermark. Identity credential valid, Do Not Train declared.

sha256 47a274c68c8ea82d00ca273735194125b0b54135dc4f6cb32c349aa6440641c3
trusted trusted-audio.m4a audio/mp4 · 227 KB
Expected: Verified: signed and unaltered

Signed by a trusted issuer, content unaltered since signing. Audio carries an AudioSeal watermark (no pixel layer). Identity credential valid, Do Not Train declared.

sha256 203d599f56affdb4c24fe7cf68747dacb8c4a8e79c917774ce30443cee0c8ef8
altered altered-photo.jpg image/jpeg · 626 KB
Expected: This file does not verify

Derived from trusted-photo.jpg by flipping one content byte. The manifest and signature are intact, but the content hash no longer matches, so the hard binding fails: the content was changed after it was signed.

sha256 1e08935b817ab434a67886ae0ce8538f42c0664f71064fa64a0bf91540658a7d
none none-photo.jpg image/jpeg · 341 KB
Expected: No Content Credentials

A plain, unsigned photo with no C2PA manifest and no watermark. The control case.

sha256 396185aa0916447a6e047c1dfe5c6cad2e790d580a7de703e3d9b4723460ff82
Machine-readable manifest: the same data, with SHA-256 and expected verdicts, is at corpus.json. Phase 2 will add valid-but-untrusted, revoked, and higher-assurance (IAL2) vectors.