All Products
Search
Document Center

AI DeepSign:SignUserImage

Last Updated:Sep 07, 2026

Signs an image with a basic C2PA signature by using a platform-owned certificate, supports content integrity verification, and returns the download URL of the signed image.

Operation description

Signature types

  • Basic signature: Signs with a platform-owned certificate and supports content integrity verification.

  • Trusted signature: In addition to integrity verification, the signing certificate chain can be verified through the C2PA official trust list.

This operation provides basic signing. For trusted signing, call CreateC2paSignTask to create a task and call GetC2paSignResult to query the result.

Request description

  • ImageUrl is required and must be a publicly accessible HTTP/HTTPS URL.

  • External image URLs are not currently supported. Only image URLs that are publicly accessible within the Chinese mainland are supported. Upload the image to an Alibaba Cloud OSS bucket in a region within the Chinese mainland first, and then use the pre-signed URL of the image as the input parameter of this operation. References: How to obtain the URL of a single file or the URLs of multiple files.

  • Supported image formats: JPEG and PNG. Unsupported formats return the C2PA_FORMAT_UNSUPPORTED fault.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

aideepsign:SignUserImage

update

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

ClientToken

string

No

The client token that is used to ensure the idempotency of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can contain only ASCII characters and cannot exceed 64 characters in length.

5A2CFF0E-5718-45B5-9D4D-70B3FF3898

ImageUrl

string

No

The URL of the image to be signed. HTTP/HTTPS URLs are supported. Specify either ImageUrl or ObjectKey. At least one of them is required.

https://example.com/photo.jpg

Response elements

Element

Type

Description

Example

object

  • Success: Indicates whether the request is successful.

  • Code: The business error code. "OK" is returned if the request is successful.

  • Message: The additional information. "success" is returned if the request is successful.

  • HttpStatusCode: The HTTP status code. 200 is returned if the request is successful.

  • SignedImageUrl: The pre-signed download URL of the signed image. You can use this URL as the ImageUrl input parameter of other operations within the validity period.

  • CertificateSubject: The subject information of the signing certificate.

  • Algorithm: The algorithm used for signing, such as ps256 or es256.

  • SignTime: The signing time in ISO 8601 format, such as 2026-01-15T08:30:00Z.

SignTime

string

The signing time in ISO 8601 format, such as 2026-01-15T08:30:00Z.

2026-06-18T10:30:00Z

RequestId

string

The request ID.

A1B2C3D4-E5F6-7890-ABCD-EF1234567890

SignedImageUrl

string

The pre-signed download URL of the signed image.

https://bucket.oss-cn-hangzhou.aliyuncs.com/deepsign/123456789/signed/abc12345.png?Expires=1718700000&OSSAccessKeyId=...

CertificateSubject

string

The subject information of the signing certificate.

CN=AIDeepSign User Certificate,O=Alibaba Cloud

ObjectKey

string

The ObjectKey of the signed image in OSS. You can use this value for subsequent API calls.

deepsign/123456789/signed/abc12345-def6-7890-abcd-ef1234567890.png

Algorithm

string

The algorithm used for signing, such as ps256 or es256.

ps256

Success

boolean

Indicates whether the request is successful.

Message

string

The additional information. "success" is returned if the request is successful.

success

HttpStatusCode

integer

The HTTP status code. 200 is returned if the request is successful.

200

Code

string

The business error code. "OK" is returned if the request is successful.

OK

Examples

Success response

JSON format

{
  "SignTime": "2026-06-18T10:30:00Z",
  "RequestId": "A1B2C3D4-E5F6-7890-ABCD-EF1234567890",
  "SignedImageUrl": "https://bucket.oss-cn-hangzhou.aliyuncs.com/deepsign/123456789/signed/abc12345.png?Expires=1718700000&OSSAccessKeyId=...",
  "CertificateSubject": "CN=AIDeepSign User Certificate,O=Alibaba Cloud",
  "ObjectKey": "deepsign/123456789/signed/abc12345-def6-7890-abcd-ef1234567890.png",
  "Algorithm": "ps256",
  "Success": false,
  "Message": "success",
  "HttpStatusCode": 200,
  "Code": "OK"
}

Error codes

HTTP status code

Error code

Error message

Description

400 IdempotentParameterMismatch The request uses the same client token as a previous, but non-identical request. Do not reuse a client token with different requests, unless the requests are identical.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.