Tools: Complete Table

Complete table with all fields including TCR4CAP comments.

IDNameCategoryVersionLicenseProvenanceC2PAURLAwarenessTamper EvidenceBindingAI AttributionSubstantiationInteroperability
siegfriedSiegfriedIdentification Tools1.11.4Apache-2.0file-level / n/a / nonenonehomepage: https://www.itforarchivists.com/siegfriedSiegfried identifies file formats against PRONOM and FDD signatures. Siegfried has no C2PA or provenance-specific awareness beyond format identification.Siegfried performs format identification only and does not assess or verify metadata integrity or tamper-evidence.No binding mechanism. Format identification is based on file signatures.AI attribution is out of scope.Outputs are structured and reproducible. Format identification results are aligned with PRONOM and FDD.Apache-2.0. Widely implemented in digipres workflows. Outputs common, open formats: JSON, CSV, YAML.
fidoFIDOIdentification Tools1.6.1Apache-2.0file-level / n/a / nonenonehttps://github.com/openpreserve/fidoFIDO identifies file formats against PRONOM signatures. No C2PA or provenance-specific awareness beyond format identification.FIDO performs format identification only and does not assess or verify metadata integrity or tamper-evidence.No binding mechanism. Format identification is based on file signatures.AI attribution is out of scope.Outputs are structured and format identification results are aligned with PRONOM.Apache-2.0. Python-based. Widely implemented in digipres workflows.
mediainfoMediaInfoCharacterization Tools26.05BSD-2-Clausefile-level / n/a / summarydetect-parsehttps://mediaarea.net/en/MediaInfoMediaInfo extracts and reports technical metadata including C2PA detection and parsing (as of December 2025). Widely used in broadcast and archive workflows.MediaInfo can detect and report C2PA manifest presence. MediaInfo does not perform cryptographic verification of C2PA signatures.MediaInfo reports C2PA manifest presence and characteristics, but does not verify the cryptographic binding between manifest and asset content.MediaInfo can report C2PA AI attribution assertions when present and does not generate or verify them.Outputs are structured and technical metadata reports are reproducible. Widely used as an authoritative tool in preservation workflows for identifying the technical characteristics of audiovisual files.BSD-2-Clause. Widely implemented across broadcast, archive, and repository tools. Outputs XML, JSON, HTML, plain text.
exiftoolExifToolCharacterization Tools13.59GPL/Artisticfile-level / n/a / fulldetect-parsehttps://exiftool.orgExifTool reads and writes EXIF, IPTC, XMP, and many other mechanisms, and provides an extensive open-source structural parsing of C2PA/JUMBF content. Widely used across creative, archive, and repository workflows.ExifTool can structurally parse C2PA manifests but does not perform cryptographic verification. ExifTool can silently overwrite non-C2PA metadata without detection.ExifTool parses and exposes C2PA hard-binding fields but does not verify the cryptographic binding between manifest and asset content.ExifTool can read and structurally parse C2PA AI attribution assertions, IPTC 2025.1 AI fields, and XMP AI attribution fields. ExifTool does not generate or verify C2PA AI attribution assertions.Outputs are structured and metadata reports are reproducible. Widely used as an authoritative metadata extraction source.Artistic/GPL. Widely implemented across creative, archive, and repository tools. Supports a multitude of metadata formats.
jhoveJHOVECharacterization Tools1.34.0LGPL-2.1file-level / n/a / nonenonehomepage: https://jhove.openpreservation.orgJHOVE performs format validation and characterization. JHOVE has no C2PA or provenance-specific awareness beyond format validation.JHOVE performs format validation only and does not assess or verify metadata integrity or tamper-evidence.No binding mechanism. Format validation is based on format structure.AI attribution is out of scope.Outputs are structured and format validation results are reproducible. Widely used in digipres ingest workflows.LGPL-2.1. Widely used in digipres ingest workflows. Outputs XML.
ffprobeFFprobeCharacterization Tools8.1.1LGPL-2.1/GPL-2.0file-level / n/a / summarynonehttps://ffmpeg.org/ffprobe.htmlFFprobe extracts technical metadata from audio, video, image, and text files. FFprobe has no C2PA or provenance-specific awareness.FFprobe reports on technical metadata and does not assess or verify metadata integrity or tamper-evidence.No binding mechanism. Technical metadata reporting is based on containers and encodings.FFprobe can report metadata tags that may include AI attribution fields by convention. No structured AI attribution vocabulary is defined.Outputs are structured and technical metadata reports are reproducible. Widely used in broadcast and archive workflows.LGPL-2.1/GPL-2.0. Widely implemented across broadcast, archive, and repository tools. Outputs JSON, XML, plain text.
md5deepmd5deep / hashdeepFixity Tools4.4Public Domainfile-level / preserves-with-action / summarynonehttps://github.com/jessek/hashdeepmd5deep/hashdeep computes and audits file checksums. No C2PA or provenance-specific awareness beyond fixity checking.Checksum computation and audit against a known-good manifest detects modification of any file. No signing mechanism.Checksum entries bind each digest to a specific file path. No cryptographic binding between the manifest and an external identity or signing authority.AI attribution is out of scope.Outputs are structured and fixity records are reproducible. Widely used in digipres transfer workflows.Public Domain. Widely implemented across digipres, library, and archival transfer tools.
fixity-proFixity ProFixity Tools1.14—file-level / preserves-with-action / summarynonehomepage: https://fixitypro.comFixity Pro monitors file integrity over time. No C2PA or provenance-specific awareness beyond fixity checking.Scheduled fixity checks detect modification of monitored files over time. No signing mechanism.Checksum entries bind each digest to a specific file path. No cryptographic binding between the manifest and an external identity or signing authority.AI attribution is out of scope.Outputs are structured fixity reports with scheduled monitoring history. Supports email reporting for institutional workflows.Maintained by OPF. Used in institutional preservation workflows.
bagit-pythonBagIt-PythonFixity Tools1.9.0CC0-1.0package-level / preserves-with-action / summarynonehttps://github.com/LibraryOfCongress/bagit-pythonBagIt-Python creates and validates BagIt packages. No C2PA or provenance-specific awareness beyond package fixity.Payload and tag manifest checksums detect modification of any file within the bag. No signing mechanism at the BagIt level.Manifest entries bind each checksum to a specific file path within the bag. Tag manifests cover bag metadata files.AI attribution is out of scope.Creates and validates structured, reproducible BagIt packages. Widely used in digipres transfer workflows.CC0-1.0. Library of Congress reference implementation. Widely used across digipres, library, and archival transfer tools.
bwfmetaeditBWF MetaEditMetadata Editors26.01Public Domain / CC0file-level / preserves-with-action / summarynonehomepage: https://mediaarea.net/BWFMetaEditBWF MetaEdit is the reference tool for BEXT chunk metadata in BWF files. Widely used in broadcast and archival audio workflows.BWF MetaEdit embeds and validates BEXT chunk metadata. BWF MetaEdit does not provide cryptographic tamper-evidence for the metadata it writes.BWF MetaEdit embeds metadata directly in the BWF file structure. There is no cryptographic binding between the metadata chunks and audio content, but BWF MetaEdit can write and verify an MD5 chunk that hashes the audio content.BWF MetaEdit can embed CodingHistory, other BEXT fields, XMP, and other metadata that could document AI processing. No structured AI attribution vocabulary or workflow is defined.Outputs are structured metadata in XML and CSV conforming to FADGI guidelines. Widely used as an authoritative metadata embedding tool in archival audio workflows.Public Domain / CC0. Widely implemented across broadcast, archival, and audio tools. GUI and CLI.
ffmpegFFmpegTranscoding Tools8.1.1LGPL-2.1/GPL-2.0file-level / strips / nonenone-officialhttps://ffmpeg.orgFFmpeg is a widely used open-source multimedia framework. No official C2PA support in the mainline codebase as of June 2026.FFmpeg strips most metadata by default. No cryptographic tamper-evidence for metadata it writes or preserves.No cryptographic binding between metadata and media content. Metadata preservation depends on explicit command-line options.No structured AI attribution vocabulary. AI documentation requires explicit metadata injection via command-line options.FFmpeg can preserve or inject metadata fields. No formal mechanism for publishing transformation history or CAP policies.LGPL-2.1/GPL-2.0. Widely implemented across broadcast, archive, and repository tools. Supports virtually all audio/video formats.
handbrakeHandBrakeTranscoding Tools1.11.2GPL-2.0file-level / strips / nonenonehomepage: https://handbrake.frHandBrake is a video transcoder. HandBrake has no C2PA or provenance-specific awareness.HandBrake removes most metadata by default when transcoding. No cryptographic tamper-evidence features.No cryptographic binding between metadata and media content.AI attribution is out of scope.No formal mechanism for publishing transformation history or CAP policies.GPL-2.0. Widely used for video transcoding. GUI and CLI.
c2patoolc2patoolC2PA Tools0.26.62MIT/Apache-2.0file-level / preserves-with-action / fullcreate-signhomepage: https://opensource.contentauthenticity.org/docs/c2patool/c2patool-index/c2patool is the official CAI CLI tool in alignment with the development of the C2PA specification. Widely used as the reference implementation for C2PA manifest creation and verification.c2patool verifies C2PA manifest signatures and hard binding and detects any modification to manifest or asset content.Creates and verifies C2PA hard binding (content hash) between manifest and asset content.Provides full support for C2PA AI attribution assertions.c2patool creates and verifies complete C2PA manifest stores with full transformation history. Supports external trust anchors and timestamps.MIT/Apache-2.0. Official CAI reference implementation. Supports all C2PA-defined embedding paths.
c2pa-rsc2pa-rsC2PA Tools0.26.62MIT/Apache-2.0file-level / preserves-with-action / fullcreate-signhttps://github.com/contentauth/c2pa-rsc2pa-rs is the official CAI Rust SDK with full C2PA specification support. c2pa-rs is the core implementation underlying the C2PA ecosystem.c2pa-rs provides full C2PA manifest signature verification and hard binding verification.Creates and verifies C2PA hard binding (content hash) between manifest and asset content.Provides full support for C2PA AI attribution assertions.c2pa-rs creates and verifies complete C2PA manifest stores with full transformation history. Supports external trust anchors and timestamps.MIT/Apache-2.0. Official CAI reference library. Widely used as the foundation for C2PA implementations across languages and platforms.
c2pa-pythonc2pa-pythonC2PA Tools0.32.12MIT/Apache-2.0file-level / preserves-with-action / fullcreate-signhttps://github.com/contentauth/c2pa-pythonThe official CAI Python bindings with full C2PA specification support via c2pa-rs. Enables C2PA integration in Python-based preservation and DAM workflows.Provides full C2PA manifest signature verification and hard binding verification via c2pa-rs.Creates and verifies C2PA hard binding (content hash) between manifest and asset content via c2pa-rs.Provides full support for C2PA AI attribution assertions via c2pa-rs.Creates and verifies complete C2PA manifest stores with full transformation history via c2pa-rs. Supports external trust anchors and timestamps.MIT/Apache-2.0. Official CAI Python bindings. Enables C2PA integration in Python-based workflows.
verify-contentcredentialsContent Credentials VerifyC2PA ToolsonlineProprietaryfile-level / n/a / fullverifyhttps://contentcredentials.org/verifyThe official CAI online verification tool. Widely used for public verification of Content Credentials.Content Credentials Verify verifies C2PA manifest signatures and reports hard binding status and detects any modification to manifest or asset content.Verifies C2PA hard binding status. The online tool requires file upload.Displays C2PA AI attribution assertions when present.Displays complete manifest content including assertions, signing certificate, timestamp, and provenance chain.Proprietary, online tool. Requires file upload.
archivematicaArchivematicaDigital Preservation Systems1.18.0AGPL-3.0package-level / preserves-with-action / fullnonehomepage: https://www.archivematica.orgArchivematica implements OAIS and generates PREMIS events and METS packages. Widely used in institutional preservation workflows. No native C2PA support.Archivematica generates BagIt packages with payload manifests and PREMIS fixity events. Tamper-evidence depends on the BagIt and PREMIS layers.PREMIS fixity values and BagIt manifests bind checksums to specific file states. No cryptographic binding between metadata and asset content at the C2PA level.No native AI attribution support. PREMIS eventDetail and eventAgent fields could document AI processing actions by convention.Archivematica generates structured PREMIS event records and METS packages documenting the full preservation workflow. Widely supported by repository systems.AGPL-3.0. Widely implemented in institutional preservation workflows. Integrates with DSpace, Fedora, and other repository systems.
synthidSynthIDWatermarking ToolsunknownProprietarycontent-level / preserves / summarynonehttps://deepmind.google/models/synthid/SynthID is a published, deployed watermarking system from Google DeepMind. Widely discussed in AI provenance contexts.Imperceptible watermarks are embedded in content pixels/samples and are resistant to common image processing operations. Detection requires access to the SynthID API.The watermark is embedded directly in the content signal. Binding is content-level and survives format conversion and metadata stripping.SynthID is purpose-built for AI-generated content attribution and embeds AI generation provenance directly in the content signal.Watermark detection confirms AI generation provenance but does not provide a structured, auditable transformation history or external trust anchor.Proprietary. Detection requires access to the SynthID API. No interoperability with C2PA or other open provenance standards.
pronomPRONOMMetadata Standards and Registriesv122Open Government Licence v3.0n/a / n/a / n/anonehttps://www.nationalarchives.gov.uk/PRONOM/PRONOM is the authoritative file format registry for digital preservation. Widely used as the identification authority in institutional workflows.Tamper-evidence is out of scope.Binding is out of scope.AI attribution is out of scope.PRONOM provides authoritative, citable format identifiers (PUIDs) used across digipres tools and policies.Open Government Licence. Widely implemented across digipres tools and systems. PUIDs are a de facto standard for format identification.
yt-dlpyt-dlpCapture and Transmission Tools2026.07.04Unlicensefile-level / strips / nonenonerepo: https://github.com/yt-dlp/yt-dlpyt-dlp has no awareness of C2PA or Content Credentials. It downloads media files and can embed general metadata (title, uploader, upload date, description) via FFmpeg, but does not detect, parse, or preserve C2PA manifests. Source-platform metadata such as YouTube AI disclosure labels is not captured as structured CAP data.No tamper-evidence capabilities. yt-dlp does not generate or verify fixity values. Downloads are byte-for-byte when no re-encoding occurs, but re-encoding via FFmpeg strips embedded C2PA and modifies the file, breaking any existing tamper-evidence chain.No binding mechanism. Metadata embedded by yt-dlp (via --embed-metadata) is written into standard metadata containers (e.g. MP4 atoms, Matroska tags) with no cryptographic binding to content. Any pre-existing C2PA hard binding is lost if re-encoding occurs.No AI attribution support. yt-dlp does not detect or preserve AI provenance metadata from source platforms. YouTube AI disclosure labels and C2PA AI attribution assertions are not captured.No provenance chain preservation. yt-dlp does not record or append its own download actions to a chain of custody. The --embed-info-json option can write a sidecar JSON file with download metadata (URL, extractor, timestamp), but this is informal and not structured CAP data. The relationship between the info.json sidecar and the media file is not maintained by any binding mechanism.Open source (Unlicense). Cross-platform. Relies on FFmpeg for post-processing, inheriting FFmpeg's format support limitations regarding C2PA preservation.
rsyncrsyncCapture and Transmission Tools3.4.4GPL-3.0file-level / preserves / summarynonehomepage: https://rsync.samba.org/rsync has no awareness of CAP metadata. It treats files as opaque byte streams. Embedded CAP data survives transfer because rsync preserves file content exactly, but rsync cannot detect, report, or validate the presence of CAP metadata. Institutions must use separate tools to verify CAP data integrity before and after transfer.rsync uses checksums internally for both its delta-transfer algorithm and its automatic post-transfer whole-file verification, but does not output or persist these checksums as a fixity record. The --checksum (-c) flag changes rsync's file comparison method from size-and-time to a 128-bit checksum, but this is for internal transfer decisions and is not reported to the user. File-level fixity must be computed separately (e.g. with bagit, md5sum, sha256sum, etc) before and after transfer to create a persistent tamper-evidence record.No binding mechanism. rsync does not create or verify any binding between metadata and content. Embedded C2PA hard binding is preserved structurally (since the file is transferred byte-for-byte), but rsync cannot report whether the binding is intact. Sidecar relationships (e.g. .c2pa, .xmp, or PREMIS XML files paired with media files) are not tracked or maintained by rsync; both files must be transferred explicitly and their association managed by the institution.No AI attribution support. rsync does not interact with or preserve AI provenance metadata beyond preserving the file bytes that contain it.rsync does not natively record or append transfer actions to a structured chain of custody. However, the --log-file option can log transfer actions (source, destination, filenames, timestamps, itemized changes) to a file, and --log-file-format allows customization of the log output. This log can serve as an informal provenance record documenting where files came from and when they were transferred, though it is not structured CAP data. Institutions should integrate rsync logs into formal provenance systems (e.g. PREMIS events) for transfer documentation.Open source (GPL-3.0). Universally available on Linux, macOS, and Unix-like systems. Widely used in digital preservation workflows for file transfer and synchronization. The -aAX flag combination preserves permissions, ownership, timestamps, ACLs, and extended attributes, but awareness of these flags and their CAP implications is the institution's responsibility.