All Products
Search
Document Center

AI DeepSign:VerifyImageSignature

Last Updated:Sep 07, 2026

Verifies the C2PA signature in an image and returns the content integrity verification status and issuer certificate trust information.

Operation description

Signature types

  • Basic signature: Uses the platform's own certificate for signing. Supports content integrity verification.

  • Trusted signature: In addition to integrity verification, the signing certificate chain can be verified through the C2PA official trust list.

Verification result description

  • Content integrity verification checks whether the image and its signature-protected provenance information remain consistent with the state at the time of signing. It does not indicate that the visual content itself is authentic.

  • VerificationState=Valid indicates that the signature and data hash are valid and content integrity verification has passed. This alone cannot be used to determine that the signature is a trusted signature.

  • VerificationState=Trusted and IssuerTrusted present the certificate trust verification results. Whether a signature qualifies as a trusted signature as defined in this topic depends on whether the signing certificate chain can be verified through the C2PA official trust list, not solely on the certificate issuer name.

Request description

  • This operation verifies the C2PA (Coalition for Content Provenance and Authenticity) digital signature embedded in a specified image.

  • ImageUrl does not currently support images from external networks. Only image URLs accessible over the China public network are supported. Upload the image to an Alibaba Cloud OSS bucket in a China region first, and then use the presigned URL of the image as the input parameter for this operation. References: How do I obtain the URL of one or more objects?

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

aideepsign:VerifyImageSignature

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

ImageUrl

string

No

The URL of the image to verify. Specify either ImageUrl or ObjectKey. At least one of them is required.

https://example.com/signed-photo.jpg

Response elements

Element

Type

Description

Example

object

Message

string

The additional information. The value success is returned if the request is successful.

success

RequestId

string

The request ID.

A1B2C3D4-E5F6-7890-ABCD-EF1234567890

Issuer

object

The issuer information.

CommonName

string

The common name (CN) of the issuer.

AIDeepSign User Certificate

Organization

string

The organization name (O) of the issuer.

Alibaba Cloud

HttpStatusCode

integer

The HTTP status code. The value 200 is returned if the request is successful.

200

VerificationState

string

The signature verification status. Valid values:

  • Unsigned: The image does not contain C2PA data.

  • Invalid: The signature, data hash, or C2PA structure is invalid.

  • Valid: The signature and data hash are valid, but the issuer is not necessarily trusted.

  • Trusted: The signature is valid and the issuer certificate is trusted.

Valid values:

  • Unsigned :

    Unsigned

  • Valid :

    Valid

  • Trusted :

    Trusted

  • Invalid :

    Invalid

Valid

IssuerTrusted

boolean

Indicates whether the issuer is trusted. A value of true indicates that the issuer certificate is issued by a trusted certification authority (CA).

Manifest

object

The content credentials manifest information. This parameter is returned only when the image contains a C2PA signature.

Assertions

array<object>

The list of assertions, which contains metadata such as the provenance and editing history of the image.

object

Data

string

The assertion data, which is detailed metadata in JSON format.

{"actions":[{"action":"c2pa.created"}]}

Label

string

The assertion label, such as c2pa.actions or stds.exif.

c2pa.actions

SignatureInfo

object

The signature details.

Alg

string

The signature algorithm, such as ps256 or es256.

ps256

Issuer

string

The distinguished name (DN) of the signing certificate issuer.

CN=AIDeepSign CA,O=Alibaba Cloud

Time

string

The signing time in ISO 8601 format.

2026-06-18T10:30:00Z

Success

boolean

Indicates whether the request is successful.

Code

string

The business error code. The value "OK" is returned if the request is successful.

OK

Examples

Success response

JSON format

{
  "Message": "success",
  "RequestId": "A1B2C3D4-E5F6-7890-ABCD-EF1234567890",
  "Issuer": {
    "CommonName": "AIDeepSign User Certificate",
    "Organization": "Alibaba Cloud"
  },
  "HttpStatusCode": 200,
  "VerificationState": "Valid",
  "IssuerTrusted": false,
  "Manifest": {
    "Assertions": [
      {
        "Data": "{\"actions\":[{\"action\":\"c2pa.created\"}]}",
        "Label": "c2pa.actions"
      }
    ],
    "SignatureInfo": {
      "Alg": "ps256",
      "Issuer": "CN=AIDeepSign CA,O=Alibaba Cloud",
      "Time": "2026-06-18T10:30:00Z"
    }
  },
  "Success": false,
  "Code": "OK"
}

Error codes

HTTP status code

Error code

Error message

Description

400 IdempotentParameterMismatch The request uses the same client token as a previous, but non-identical request. Do not reuse a client token with different requests, unless the requests are identical.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.