Content Authenticity Initiative
unknown · United StatesScores
1 product on the map — 1 open.
C2PA SDK (Content Authenticity Initiative)
Openness
5 high confidence- license
- Apache-2.0/MIT(dual-licensed at the recipient's choice, in both repositories)
- source
- public
- core features withheld
- no
The Rust library and the Python bindings are each dual-licensed under MIT or Apache-2.0 at the user's choice, and the published code is the whole SDK. Content Credentials are an open standard, and nothing in the repositories is held back for a paid edition.
- https://raw.githubusercontent.com/contentauth/c2pa-python/main/LICENSE-APACHE recorded 2026-09-26
c2pa-python: Apache License, Version 2.0, full text
- https://raw.githubusercontent.com/contentauth/c2pa-python/main/LICENSE-MIT recorded 2026-09-26
c2pa-python: "MIT License © Copyright 2020 Adobe"
- https://raw.githubusercontent.com/contentauth/c2pa-rs/main/LICENSE-APACHE recorded 2026-09-26
Apache License, Version 2.0, full text
- https://raw.githubusercontent.com/contentauth/c2pa-rs/main/LICENSE-MIT recorded 2026-09-26
"MIT License © Copyright 2020 Adobe. All rights reserved. Permission is hereby granted, free of charge..."
- https://raw.githubusercontent.com/contentauth/c2pa-rs/main/README.md recorded 2026-09-26
"The CAI Rust library is part of the Content Authenticity Initiative open-source SDK"
- https://raw.githubusercontent.com/contentauth/c2pa-rs/main/sdk/Cargo.toml recorded 2026-09-26
crate c2pa manifest: license = "MIT OR Apache-2.0"
- https://ungh.cc/repos/contentauth/c2pa-rs/files/main recorded 2026-09-26
Full file listing of contentauth/c2pa-rs main, 650 paths; no ee/, enterprise/, commercial/ or proprietary/ directory
Adoption
3 high confidenceDownloads of the two packages the SDK ships through, the c2pa-python bindings on PyPI and the c2pa crate on crates.io, measure its use.
- https://crates.io/api/v1/crates/c2pa recorded 2026-09-26
crate c2pa: recent_downloads (90 days) = 1,150,875; repository github.com/contentauth/c2pa-rs; version 0.91.0
- https://pypistats.org/api/packages/c2pa-python/recent recorded 2026-09-26
last_month downloads = 406,979 for c2pa-python
Capability
4 high confidenceA manifest is signed, so anyone holding the file can check that it was not altered and which certificate signed it, offline and without the publisher's help. What it cannot show is that the signer's claims about the content are true, which is the gap between this and NVIDIA's hardware attestation.
- https://opensource.contentauthenticity.org/docs/conformance/trust-lists/ recorded 2026-09-26
CAI documentation on the C2PA trust list used to validate manifest signing certificates
- https://opensource.contentauthenticity.org/docs/signing/get-cert/ recorded 2026-09-26
CAI documentation on obtaining a signing certificate for Content Credentials
- https://raw.githubusercontent.com/contentauth/c2pa-rs/main/docs/usage.md recorded 2026-09-26
Usage guide for reading, validating and signing C2PA manifests with the Rust library