{"categories":[{"label":"Cryptography","url":"https://skillfed.io/packages/category/security-cryptography/2"}],"enrichment":{"capability":"Read, validate, create, and sign C2PA manifest data in media files to establish content authenticity and provenance.","skillfed_tags":["content-authenticity","media-provenance","cryptographic-signing"],"use_cases":["Verify the authenticity and provenance chain of media files received from external sources or user uploads.","Embed \"Do Not Train\" or other machine-learning-related assertions into images or media to control downstream use.","Build a content management system that signs and tracks the origin of all media assets with cryptographic proof.","Validate that media files have not been tampered with since they were signed by a trusted source.","Add ingredient references to derived media to document the source materials used in creation.","Audit and extract metadata from manifests to generate reports on content provenance and modification history."],"what_it_does":"c2pa-python is a Python wrapper around the C2PA (Content Authenticity Initiative) Rust library, enabling developers to work with C2PA manifests\u2014cryptographic records that establish the origin, history, and authenticity of digital media. It lets you read and validate existing manifests embedded in media files, and create new manifests by signing media with various cryptographic algorithms and attaching provenance metadata.\n\nThe library handles the full lifecycle of manifest operations: reading and verifying signatures, adding assertions (such as \"Do Not Train\" markers), including ingredient references, and writing signed manifests back to media files. It depends on cryptography for signing operations and requests for network calls, and ships as prebuilt wheels for common platforms, making installation straightforward on macOS, Linux, and Windows.","worth_installing":"Yes. The package is actively maintained (release 1 day old), has no known vulnerabilities, supports current Python versions (3.10+), and solves a real problem in content authenticity. Medium install friction is acceptable given the prebuilt wheels for common platforms. Permissive dual licensing (MIT/Apache-2.0) poses no legal barrier. Install if you need to read, validate, or sign C2PA manifests in media files."},"id":"c2pa-python","links":{"html":"https://skillfed.io/packages/c2pa-python","md":"https://skillfed.io/packages/c2pa-python.md","pypi":"https://pypi.org/project/c2pa-python/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-13","license_spdx":null,"license_treatment":"permissive","name":"c2pa-python","python_support":"supports_current","summary":"Python bindings for the C2PA Content Authenticity Initiative (CAI) library"},"popularity":{"monthly_downloads":274866,"position":8185,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"0.37.7"}
