$npx skillfedfor your agent

c2pa-python

Python bindings for the C2PA Content Authenticity Initiative (CAI) library

Worth itPyPI CryptographyReleased Aug 2026274.9K downloads / moMIT OR Apache-2.0Platform wheel

Decision gist · record as of 2026-08-14

platform wheels — c2pa_python-0.37.7-py3-none-macosx_10_9_universal2.whl · c2pa_python-0.37.7-py3-none-macosx_10_9_x86_64.whl · c2pa_python-0.37.7-py3-none-macosx_11_0_arm64.whl
v0.37.7 · released 2026-08-13 · Python >=3.10 · 6 runtime deps: wheel, setuptools, toml, pytest, cryptography, requests

Yes. The package is actively maintained (release 1 day old), has no known vulnerabilities, supports current Python versions (3.10+), and solves a real problem in content authenticity. Medium install friction is acceptable given the prebuilt wheels for common platforms. Permissive dual licensing (MIT/Apache-2.0) poses no legal barrier. Install if you need to read, validate, or sign C2PA manifests in media files.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Prebuilt wheels available for macOS (10.9+), Linux (glibc 2.28+), and Windows; other platforms may require building from local c2pa-rs sources.
  • Medium install friction due to prebuilt binary wheels for multiple platforms (macOS universal/x86_64/arm64, Linux x86_64/aarch64, Windows x86_64/arm64).

License · maintenance · safety

MIT OR Apache-2.0 (permissive) — Dual-licensed under MIT OR Apache-2.0 (permissive). Either license permits commercial and private use with minimal restrictions; choose whichever suits your project's existing license.

last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 98 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 274,866 downloads/mo, #8,185 on PyPI

Verify before relying

pip install c2pa-python

import c2pa

# Read and validate a manifest from a media file
manifest = c2pa.read_file('path/to/media_file')
if manifest:
    print(manifest.validation_status)
  • Supported media formats beyond what the description excerpt lists (references external docs for full format support).
  • Performance characteristics when processing large media files or batch operations.
  • Whether cryptography and requests are used directly in typical workflows or only as transitive dependencies.
Same gist for agents: .md · .json

What it is and what it does

c2pa-python is a Python wrapper around the C2PA (Content Authenticity Initiative) Rust library, enabling developers to work with C2PA manifests—cryptographic records that establish the origin, history, and authenticity of digital media. It lets you read and validate existing manifests embedded in media files, and create new manifests by signing media with various cryptographic algorithms and attaching provenance metadata.

The library handles the full lifecycle of manifest operations: reading and verifying signatures, adding assertions (such as "Do Not Train" markers), including ingredient references, and writing signed manifests back to media files. It depends on cryptography for signing operations and requests for network calls, and ships as prebuilt wheels for common platforms, making installation straightforward on macOS, Linux, and Windows.

Use it for

  • Verify the authenticity and provenance chain of media files received from external sources or user uploads.
  • Embed "Do Not Train" or other machine-learning-related assertions into images or media to control downstream use.
  • Build a content management system that signs and tracks the origin of all media assets with cryptographic proof.
  • Validate that media files have not been tampered with since they were signed by a trusted source.
  • Add ingredient references to derived media to document the source materials used in creation.
  • Audit and extract metadata from manifests to generate reports on content provenance and modification history.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package is actively maintained (release 1 day old), has no known vulnerabilities, supports current Python versions (3.10+), and solves a real problem in content authenticity. Medium install friction is acceptable given the prebuilt wheels for common platforms. Permissive dual licensing (MIT/Apache-2.0) poses no legal barrier. Install if you need to read, validate, or sign C2PA manifests in media files.

Install

c2pa-python on PyPI

Before you install

Medium install friction due to prebuilt binary wheels for multiple platforms (macOS universal/x86_64/arm64, Linux x86_64/aarch64, Windows x86_64/arm64). Active maintenance with a release 1 day old; last commit 2026-08-13. Requires Python 3.10+.

Requires Python 3.10 or later. Prebuilt wheels available for macOS (10.9+), Linux (glibc 2.28+), and Windows; other platforms may require building from local c2pa-rs sources.

License in practice

Dual-licensed under MIT OR Apache-2.0 (permissive). Either license permits commercial and private use with minimal restrictions; choose whichever suits your project's existing license.

Quickstart

pip install c2pa-python

import c2pa

# Read and validate a manifest from a media file
manifest = c2pa.read_file('path/to/media_file')
if manifest:
    print(manifest.validation_status)

Verify before relying

  • Supported media formats beyond what the description excerpt lists (references external docs for full format support).
  • Performance characteristics when processing large media files or batch operations.
  • Whether cryptography and requests are used directly in typical workflows or only as transitive dependencies.

Package facts

LicenseMIT OR Apache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionMedium. Platform-specific wheel
Runtime dependencies
6 packages
wheelsetuptoolstomlpytestcryptographyrequests
MaintenanceActively maintained 1 days since the last release
Last repo commit
First released
Downloads274,866 / month, #8,185 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Operating System :: MacOSOperating System :: Microsoft :: WindowsOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3

Evidence: c2pa_python-0.37.7-py3-none-macosx_10_9_universal2.whl; c2pa_python-0.37.7-py3-none-macosx_10_9_x86_64.whl; c2pa_python-0.37.7-py3-none-macosx_11_0_arm64.whl; c2pa_python-0.37.7-py3-none-manylinux_2_28_aarch64.whl; c2pa_python-0.37.7-py3-none-manylinux_2_28_x86_64.whl; c2pa_python-0.37.7-py3-none-win_amd64.whl; c2pa_python-0.37.7-py3-none-win_arm64.whl

Tags

Capabilities
C2PA manifest handlingcontent authenticity verificationmedia file signingprovenance trackingdigital content authenticationmanifest creation and validationcontent origin verification
Topics
content-authenticitymedia-provenancecryptographic-signing

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “C2PA manifest handling”

  • c2pa-pythonRead, validate, create, and sign C2PA manifest data in media files to…
  • java-manifestEncode and decode Java's META-INF/MANIFEST.MF file format in Python,…
  • manifestoo-coreParses and reasons about Odoo addon manifests, detecting Odoo series…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also ansible-sign · signify · java-manifest · manifestoo-core · mediatype · standardwebhooks · endesive · zope.contenttype · vonage-verify · planetary-computer