SSL Provenance API

Fully managed C2PA and CAWG

Focus on your core proposition. We handle C2PA and CAWG. A fully managed REST API that creates, edits, and signs C2PA and CAWG manifests for your assets in a single API call.

Try the sandbox
How it works

Three ways to use the SSL Provenance API

Pick the signing model that matches how much of the identity you want to own.

Option A

SSL.com is the signing entity

SSL.com acts as the C2PA signing entity for your assets.

Use this when you want provenance on your content without operating any signing infrastructure or holding a certificate of your own.

Content Credentials readSigned by SSL.com
Option B

SSL.com is the signing entity, with your CAWG identity

SSL.com signs as the C2PA entity, and your organization's identity is asserted through a CAWG certificate compatible with the IPTC Verified News Publisher trust list.

Use this when your brand needs to appear on the asset but you would rather not take on C2PA conformance.

Content Credentials readSigned by SSL.com
Publisher: Your Company
Option C
Requires C2PA conformance

Your own signing certificate

You sign with your own C2PA certificate, with CAWG identity as an option. This route requires C2PA conformance, and we can accelerate that process.

Use this when you need full control of the signing identity.

Content Credentials readSigned by Your Company
Publisher: Your Company

Optional: durable Content Credentials. Add watermarking so Content Credentials survive transformations that strip metadata. An imperceptible watermark lets the manifest be recovered even when the embedded metadata is gone.

Why teams build on SSL.com

A conformant CA, in production since 2025

The first publicly trusted certificate authority on the C2PA conformance list, issuing production certificates since 2025.

The first publicly available C2PA sandbox, so you can test signing before you commit to an integration.

A dedicated C2PA team active in both the C2PA and CAWG working groups.

Among the five largest public certificate authorities by volume, issuing millions of certificates and signatures daily.

EU AI Act, Article 50

Built for the transparency deadline

Article 50 disclosure rules became enforceable on 2 August 2026, and the grace period for systems already on the market closes on 2 December 2026. The rules ask for AI output to be marked in a machine-readable format, for that marking to be robust and interoperable rather than reliant on any single method, and for disclosure to reach users at first exposure. Signed C2PA manifests layered with watermarking answer all three.

See the EU AI Act guide

Start signing

Test against the sandbox, or talk to our team about the route that fits your infrastructure.

Talk to our provenance team

Related: C2PA Certificates | CAWG Certificates | C2PA Time Stamping

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

For more information read our Cookie and privacy statement.

3rd Party Cookies

This website uses Google Analytics & Statcounter to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.

Show details