C2PA 2.2: file types that can carry credentials vs Sume outputs

C2PA 2.2 manifests can be embedded in JPEG, PNG, WebP, SVG, MP4, MOV and more. How that list lines up with the formats Sume image and video jobs return.

4 min readSume
All posts

The C2PA 2.2 specification lists JPEG, PNG, GIF, PDF, SVG, TIFF, DNG, WebP, MP4, MOV and HEIC as formats that can embed a manifest. Sume image jobs can return png, jpeg, webp or svg and video jobs return MP4, so every listed Sume format is one the spec can carry; whether a given file actually has a manifest is a separate question.

What a manifest is

The C2PA 2.2 specification, published in May 2025 and read on 2026-10-03, describes a manifest as a signed collection of assertions. It binds those assertions to the content in two ways.

C2PA 2.2 binding types (read 2026-10-03)
BindingHow it worksTypical weakness
Hard bindingHashes of the asset data tie the manifest to exact bytesAny change to the bytes breaks the match
Soft bindingFingerprints or invisible watermarks let a manifest be found by contentNeeds a lookup service or a detector

Formats named by the spec and Sume's outputs

The spec lists the container formats below as able to embed a manifest. The right column cites Sume's docs for what jobs return.

C2PA 2.2 embeddable formats against Sume output formats (spec read 2026-10-03)
C2PA 2.2 format listIn Sume docs
JPEGImage output_format: jpeg
PNGImage output_format: png
WebPImage output_format: webp
SVGImage output_format: svg, listed in the Image API docs
MP4Video artifacts are video/mp4
GIF, PDF, TIFF, DNG, MOV, HEICNot named in the Sume pages read for this post

What this does and does not tell you

Being on the spec's list says a format can hold a manifest. It does not say that a Sume file contains one. Sume's public docs do not describe credentials on outputs, so verify on your own downloads with a C2PA reader.

The hard-binding idea has a practical consequence for video. A file that was re-encoded has different bytes from the file that was signed, so a manifest bound by hash does not match unless the tool that re-encoded it signed a new one. Video trim with precision: "exact" re-encodes, while keyframe is a stream copy. Test which one keeps what you need.

A version note

The page read for this post was the 2.2 specification, and a redirect page referenced version 2.4 as current. Pin the version you validate against, and check the current one before committing to a field name in code.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume