C2PA (Coalition for Content Provenance and Authenticity) live video validation for BMFF and MP4 containers.
Supported C2PA segment validation methods:
npm i @svta/cml-c2pa
Note:
@svta/cml-iso-bmff,@svta/cml-utils, andcbor-xare peer dependencies. Most package managers install them automatically, but you may need to add them explicitly.
Note: This library uses the Web Crypto API (
crypto.subtle) to verify COSE signatures and compute BMFF hashes. In Node.js 20+,crypto.subtleis available globally. In browsers, it requires a secure context (HTTPS orlocalhost).
import { validateC2paManifestBoxSegment } from '@svta/cml-c2pa'
import type { ManifestBoxValidationState } from '@svta/cml-c2pa'
async function validateManifestBoxStream(segmentUrls: string[]): Promise<void> {
let lastManifestId: string | null = null
let state: ManifestBoxValidationState | undefined
for (const segmentUrl of segmentUrls) {
const response = await fetch(segmentUrl)
const bytes = new Uint8Array(await response.arrayBuffer())
const { result, nextManifestId, nextState } = await validateC2paManifestBoxSegment(
bytes,
lastManifestId,
state,
)
lastManifestId = nextManifestId
state = nextState
console.log(result.isValid, result.errorCodes)
}
}
import { validateC2paInitSegment, validateC2paSegment } from '@svta/cml-c2pa'
async function validateVsiSegment(initUrl: string, segmentUrl: string): Promise<void> {
const initResponse = await fetch(initUrl)
const init = await validateC2paInitSegment(new Uint8Array(await initResponse.arrayBuffer()))
const segmentResponse = await fetch(segmentUrl)
const segmentBytes = new Uint8Array(await segmentResponse.arrayBuffer())
const validated = await validateC2paSegment(segmentBytes, init.sessionKeys)
console.log(validated?.result.isValid)
}
import { validateC2paInitSegment, validateC2paMerkleSegment } from '@svta/cml-c2pa'
async function validateMerkleSegment(initUrl: string, segmentUrl: string): Promise<void> {
const initResponse = await fetch(initUrl)
const init = await validateC2paInitSegment(new Uint8Array(await initResponse.arrayBuffer()))
const segmentResponse = await fetch(segmentUrl)
const segmentBytes = new Uint8Array(await segmentResponse.arrayBuffer())
const { result } = await validateC2paMerkleSegment(segmentBytes, init.merkleMaps)
console.log(result.isValid, result.errorCodes)
}
C2PA (Coalition for Content Provenance and Authenticity) validation for BMFF/MP4 live video streams.
See
C2PA Specification