Ship C2PA Content Credentials in one line of code
0byte is the managed C2PA signing service for generative AI companies. Managed certificate — none to procure — and a public fingerprint registry, so the proof survives when platforms strip the file.
Screenshot it. Re-upload it. It still knows.
Manifests get stripped on upload and watermarks wash off. 0byte’s fingerprint is derived from what the image looks like — so the origin survives the trip.
c2paVerified origin — from the last copy alone.
Manifest absent, registry match at distance 3. The record comes back: acme-ai · imagen-x, proof 0b_3f2a8c91.
Marking AI content is now a legal duty. Keeping the mark alive is the hard part.
The EU AI Act, its Code of Practice, and California's SB 942 all require machine-readable marking and detection. The standard exists — the internet just doesn't preserve it.

- 01
The image
A model generates an image, and it spreads across the open internet.
- 02
Trust is embedded
A watermark or C2PA manifest is written into the file to record its origin.
- 03
Platforms strip it
On upload, platforms re-encode the file — and the embedded proof is discarded.
- 04
Detection is a guess
With only raw pixels left, detectors can estimate the source, never prove it.
The C2PA spec itself calls for a soft binding that lives outside the file. 0byte operates one — openly, for any signer.
Manifests get stripped
C2PA Content Credentials are the right standard — signed, structured, verifiable. But most platforms strip metadata on upload, and the credential leaves with it. That gap is what 0byte closes for C2PA.
Watermarks cover one vendor
Invisible watermarks only mark one company's models and degrade with screenshots and re-encoding. Open-weights models — a huge share of generation — carry no watermark at all.
Detectors are guessing
AI detectors return a probability, not proof, and need retraining every time a new model ships. A guess doesn't hold up in a newsroom, a courtroom, or an audit.
The gap is already expensive — and the regulatory clock is running.
C2PA, made survivable.
Standard Content Credentials, signed for you — and a public fingerprint record for the day the file gets stripped. When a format cannot carry a manifest, the record still stands and the response says which binding you got.
# right after your model returns result = client.stamp( image_bytes, provider="acme-ai", model="imagen-x", creator={"name": "Acme Studios"}, )
One line of code
Stamp right after generation and pass your brand — the credential names you as its claim generator, on our certificate. You get back the credentialed file and a signed proof, and the binding field says exactly what you got, never a silent downgrade.
A fingerprint, not a label
Derived from what the image looks like, never embedded in it. Screenshots, re-encodes and crops still match.
A record that can't be rewritten
Every proof lands in an append-only public log with a signed tree head. Added, never edited — not even by us.
One call checks everything
Reads Content Credentials from any signer, matches the fingerprint, and returns a verdict built from evidence — every signal disclosed, never a probability.
Proofs that can't be faked
Signed with our Ed25519 key the moment it's created — check it against our published keys. A record cannot be forged or backdated.
Stamp once. Survive the internet.
The journey every image actually takes — and where the proof comes back.
# right after your model returns result = client.stamp( image_bytes, provider="acme-ai", model="imagen-x", )
Stamp at generation
One call signs a C2PA manifest into the file — your brand as the claim generator — anchors the derived fingerprint in the public transparency log, and hands back a proof URL anyone can open.
metadata removedc2pa
The internet does its worst
Someone uploads it, the platform strips the metadata, someone else screenshots the upload. The manifest is gone — the fingerprint isn't.
Verify recovers the proof
Anyone checks the copy, free and without an account. The fingerprint matches the registry, and the original record comes back — who made it, with which model, when.
Built for the people the deadlines apply to.
Whether you generate AI content or have to judge it — the answer comes from the same public record.
AI model providers
Stamp every generation at the source — Content Credentials in the file and a fingerprint in the public log, recording the model, the moment and the brand you declare. Prompts and weights never leave your side.
Newsrooms & media
Check a viral image in seconds — even a screenshot of a re-upload — and read the signed record behind it: who stamped it, with which model, when. Evidence you can publish, not a detector’s guess.
Developer platforms
Add provenance to your product in a single call — across every model you ship, even the open-source ones. No cryptography to learn.
Creators & rights holders
Publish AI-generated work with your brand named in the credential and a signed, timestamped record in the public log — so a repost or a re-encode still resolves to when it was stamped, and by whom.
C2PA alone, or C2PA that survives.
Content Credentials are the standard. 0byte adds the layer the spec itself calls for — a soft binding that outlives the file — and reads both signals, the manifest and the registry, when you verify.
Works with / extends C2PA
Survives social media upload
Survives screenshots & re-encoding
Covers any AI model, including open-weights
Certificate you must procure
What a match gives you
Admits where it fails
Heavy AI regeneration of content defeats every system on this table — 0byte included. We’re the only column that says so out loud.
The rules are in force. The marking has to survive.
The EU AI Act’s transparency obligations apply to generative AI providers. One stamp covers the marking, the detection, and the audit trail.
Dec 2, 2026
Compliance deadline for generative AI systems already on the market before August 2026.
Regulation (EU) 2024/1689
Machine-readable marking
EU AI Act · Art. 50(2)Providers of generative AI must mark outputs as artificially generated in a machine-readable format. A stamp embeds standard C2PA Content Credentials declaring AI origin — readable by any validator.
Detectability
EU AI Act · Art. 50Markings must be effective and reliable as far as technically feasible — and platforms strip metadata. The registry fingerprint survives screenshots and re-encoding, and verification is free for anyone.
Auditability
Transparency disclosuresEvery proof is anchored in a signed, append-only transparency log. Inclusion and consistency proofs are public and every key we have ever signed with is published, so an auditor recomputes the record rather than trusting 0byte.
C2PA verification is free. Forever.
A provenance registry only works if anyone can check it — so verifying costs nothing, ever. You pay to stamp, by throughput.
Freeforever
Check any content — no key, no account, no meter.
- Evidence-first verdicts
- Manifest + registry signals
- Transparency-log proofs
60req/min
Stamp with Content Credentials from day one.
- C2PA manifest signing
- Fingerprint in the public log
- Brand attribution
300req/min
For pipelines in active development.
- Everything in Free
- Higher stamping throughput
- API key management
1,000req/min
Production volume, compliance-ready.
- Everything in Dev
- Priority support
- Compliance evidence — talk to us
Paid plans finalized at launch — early-access teams lock in launch pricing
The questions we get most.
Straight answers — including what 0byte can't do.
Still have a question? Talk to usMake it verifiable. Forever.
Compliance deadline on the calendar? Ship your first stamped, validating image in an afternoon — and verification stays free for everyone.
Building something bigger? Compliance questions?
Talk to us




