C2PA 2.2: file types that can carry credentials vs Sume outputs
C2PA 2.2 manifests can be embedded in JPEG, PNG, WebP, SVG, MP4, MOV and more. How that list lines up with the formats Sume image and video jobs return.

The C2PA 2.2 specification lists JPEG, PNG, GIF, PDF, SVG, TIFF, DNG, WebP, MP4, MOV and HEIC as formats that can embed a manifest. Sume image jobs can return png, jpeg, webp or svg and video jobs return MP4, so every listed Sume format is one the spec can carry; whether a given file actually has a manifest is a separate question.
What a manifest is
The C2PA 2.2 specification, published in May 2025 and read on 2026-10-03, describes a manifest as a signed collection of assertions. It binds those assertions to the content in two ways.
| Binding | How it works | Typical weakness |
|---|---|---|
| Hard binding | Hashes of the asset data tie the manifest to exact bytes | Any change to the bytes breaks the match |
| Soft binding | Fingerprints or invisible watermarks let a manifest be found by content | Needs a lookup service or a detector |
Formats named by the spec and Sume's outputs
The spec lists the container formats below as able to embed a manifest. The right column cites Sume's docs for what jobs return.
| C2PA 2.2 format list | In Sume docs |
|---|---|
| JPEG | Image output_format: jpeg |
| PNG | Image output_format: png |
| WebP | Image output_format: webp |
| SVG | Image output_format: svg, listed in the Image API docs |
| MP4 | Video artifacts are video/mp4 |
| GIF, PDF, TIFF, DNG, MOV, HEIC | Not named in the Sume pages read for this post |
What this does and does not tell you
Being on the spec's list says a format can hold a manifest. It does not say that a Sume file contains one. Sume's public docs do not describe credentials on outputs, so verify on your own downloads with a C2PA reader.
The hard-binding idea has a practical consequence for video. A file that was re-encoded has different bytes from the file that was signed, so a manifest bound by hash does not match unless the tool that re-encoded it signed a new one. Video trim with precision: "exact" re-encodes, while keyframe is a stream copy. Test which one keeps what you need.
A version note
The page read for this post was the 2.2 specification, and a redirect page referenced version 2.4 as current. Pin the version you validate against, and check the current one before committing to a field name in code.
Sources
Related posts
More in Developers
- C2PA 2.2 in plain terms: manifests, hard and soft bindings
C2PA 2.2 describes signed manifests with hash-based hard bindings and fingerprint or watermark soft bindings. What that implies after a re-encode or trim.
- Watch the Sume video catalog for new ids and changed limits in Python
Fetch GET /v1/videos/models, save a snapshot and diff new ids, removed ids and changed durations or resolutions. A Python script, testable offline.
- Claude Code 2.1.285 lists WebSocket MCP servers; Sume uses HTTP
Claude Code 2.1.285 shows WebSocket MCP servers in claude mcp list. Sume's hosted MCP is a remote HTTP server, added with --transport http.
- Claude Code 2.1.289 plugin loading fix: recheck Sume MCP after upgrade
Claude Code 2.1.289 fixed plugin loading after an upgrade. A four-call read-only check confirms the Sume MCP connection and scopes before you run a paid job.
Written by Sume