DeepFake Check
Back to Blog
5 min read

C2PA Actions Assertions: How to Validate Structure and Ingredient References

Preserve the asset and the complete validator output

Save the exact asset before opening it in a C2PA-compatible validator. Record the source URL or local path, retrieval time, file identifier, validator name and version, active manifest label, claim version, and complete output. This worksheet is an operational method proposed here, not a format required by C2PA. Do not re-export the asset or replace it with a screenshot before the first run.

Limit the question to the actions assertion that the validator actually reports. Record whether its label is c2pa.actions or c2pa.actions.v2, where it appears in the claim, and every action value in order. Preserve the literal parameters, ingredients or legacy ingredient, redacted, softwareAgent, softwareAgents, and template fields that the tool exposes. Mark an unreported field as unreported instead of filling it from another file or an expected workflow.

This review checks assertion structure and references. It does not reconstruct an edit history that the manifest did not record. A passing result does not establish who performed an action, whether a caption is accurate, or whether the depicted event happened. A failure also does not show that the media is false.

Check the actions field and the first-action rule

For an assertion labelled c2pa.actions or c2pa.actions.v2, C2PA 2.2 requires an actions field. If it is absent, the claim is rejected with assertion.action.malformed. Record the label, observed field, and exact code together so another reviewer can distinguish a missing field from a different actions failure.

The specification applies an additional order rule when the action is c2pa.created or c2pa.opened. The relevant actions assertion must be the first actions assertion in the created_assertions or gathered_assertions array for a version 2 claim, or the first actions assertion in the assertions array for a version 1 claim. The action must also be the first element in that assertion's actions array. If either condition fails, the code is assertion.action.malformed.

Copy the claim version, array name, assertion position, action-array position, and returned code into separate columns. A validator that shows only a general badge does not provide enough detail to state which order condition failed. Preserve its output and leave that point unresolved.

Resolve ingredient references by action type

For c2pa.opened, c2pa.placed, and c2pa.removed, the action needs a non-empty parameters field and an ingredient reference field. Version 2 uses ingredients; the earlier c2pa.actions form uses ingredient. For the version 2 field, the value must be an array with at least one element. A missing or empty requirement produces assertion.action.ingredientMismatch.

The expected destination depends on the action. c2pa.opened requires exactly one valid hashed URI resolving to an ingredient assertion in the current manifest with relationship equal to parentOf. c2pa.placed requires one or more valid hashed URIs resolving in the current manifest to ingredient assertions whose relationship is componentOf. c2pa.removed also requires one or more componentOf ingredient assertions, but they resolve in another manifest.

For c2pa.transcoded or c2pa.repackaged, ingredient references are optional. When present, each must be a valid hashed URI resolving to a parentOf ingredient assertion in the current manifest. A reference that does not meet the applicable condition produces assertion.action.ingredientMismatch. Record the literal URI, the manifest in which the validator resolved it, the reported relationship, and the code. Do not silently substitute a similarly named ingredient.

Keep redaction and icon checks separate

If the parameters object has a redacted field, check its JUMBF URI. A missing URI or one that cannot be resolved to an assertion produces assertion.action.redactionMismatch. Keep this result separate from an ingredient mismatch; the two codes identify different references.

When an action's softwareAgent, the actions map's softwareAgents, or a template includes an icon, C2PA directs the validator to apply its reference-validation procedure. Record only what the validator exposes about that reference. An icon, agent name, or template label is not evidence that the action happened as described.

A useful table contains the asset identifier, manifest and claim identifiers, assertion label and position, action and position, parameters status, literal ingredient or redaction URI, resolved manifest, relationship, exact validator code, validator version, and unresolved fields. Attach the full output rather than converting a green or red badge into assumed field-level results.

Report the technical result without a truth verdict

A passing actions check supports a limited statement: the inspected assertion met these structural and reference rules in that validator run. Other checks still cover the claim signature, certificates, assertion hashes, asset binding, and ingredient manifests. Verify publisher, people, caption, date, place, and event through the original source and independent evidence.

If you also analyze the preserved asset with DeepFakeCheck, keep that probabilistic signal outside the C2PA table and link it to the exact file. Automated detection can produce false positives on authentic media and false negatives on synthetic or altered media. DeepFakeCheck does not validate actions assertions or issue these C2PA failure codes.

Sources

  • C2PA, “C2PA Technical Specification, C2PA Actions Validation”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_c2pa_actions_validation

Need to check a suspicious file?

Open the matching detector and interpret the result alongside the source and context.

Open Detector