DeepFake Check
Back to Blog
DeepCheckAI Team 4 min read

C2PA Validation Results: How to Read Status Codes

Save the file and the complete validator output

Start with the exact media copy you received. Save it without editing, then record its filename, source page, acquisition time, and the validator used. If a platform offers several downloads, label the copy that produced the result. This recordkeeping is an operational method proposed here, not a procedure required by C2PA.

Run that copy through a compatible C2PA validator and preserve the complete output. The C2PA 2.2 specification says the validation algorithm returns a consolidated set of results for manifests in the asset's C2PA Manifest Store, including the active manifest and other manifests referenced through ingredient assertions. A screenshot of a green or red badge can omit the code, the affected item, and explanatory text. Copy the machine-readable output when the tool makes it available.

Keep the three result groups separate

C2PA expresses validation results with standard success, informational, and failure codes. These are separate arrays, and each may be empty. Do not collapse them into one home-made label such as "verified" or "fake." Record each group under its original heading.

A result entry contains a code. It may also contain a JUMBF URI identifying the box to which the result applies and a human-readable explanation. Preserve those fields together. The specification also permits custom status codes for process-specific information, so keep an unfamiliar code exactly as shown rather than assigning it to a standard category from memory.

Use one row per entry: file, result group, exact code, URI if shown, explanation if shown, and the question still open. This table is the article's review method. It prevents a code about a signature, assertion, credential, timestamp, or ingredient from silently becoming a statement about the whole file.

Interpret the failed check, not the scene

The standard list includes many distinct checks. A failure code may concern a missing or mismatched claim signature, an inaccessible assertion, an unsupported algorithm, a hash mismatch, a credential result, or another validation step. The exact code identifies the technical check that needs investigation. It does not, by itself, establish who changed the file, why it changed, or whether the depicted event happened.

The same restraint applies to success and informational results. A success code records that a defined check succeeded. An informational code records a condition the validator reports. Neither category independently verifies a caption, date, location, speaker identity, or real-world event. Check those claims against the original publication and independent sources.

When two copies return different results, keep both files and outputs. The difference shows that the copies or their available provenance records do not validate in the same way. Do not infer the editor or motive without separate evidence.

Write the next action beside each unresolved code. That action might be obtaining the original download, trying another compatible validator, asking the publisher for the file it released, or checking a claim against an independent source. Record the result of the action instead of deleting the earlier failure. A dated sequence lets another reviewer see what changed between checks and keeps later evidence from being mistaken for the first result.

Keep provenance and detection findings in separate sections

C2PA validation examines the provenance record and its defined checks. If you also submit the saved media to DeepFakeCheck, place that probabilistic risk signal in a separate section. Attach it to the exact analyzed copy.

Automated detection can produce false positives that flag authentic media and false negatives that miss synthetic or manipulated media. A high-risk result supports further review; a low-risk result does not authenticate the file. It also does not replace the validator's exact status codes.

Finish the review with the preserved file, complete validation output, unresolved technical checks, source-page findings, detector result if used, and the decision taken. Another reviewer should be able to repeat each check without relying on a colored badge or a reconstructed explanation.

Sources

  • C2PA, "Content Credentials: C2PA Technical Specification, Returning Validation Results": https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_returning_validation_results

Suspect an image might be AI-generated?

Use our advanced deepfake detection tool to analyze images with high precision.

Analyze Image Now