ISCC home

Tech demo · ISCC soft binding for C2PA · Windows, macOS, Linux

Bind Content Credentials to the content, not just the bytes.

Content Credentials are tied to a file by a hash of its exact bytes. Resize or re-encode the file and they no longer match. This tech demo adds the International Standard Content Code (ISCC, ISO 24138) to the credentials: a code anyone can calculate from the content itself.

Download Source on GitHub v0.1.0 · 2026-09-28
The app with a changed copy of a signed image open: the Content Credentials tab says Invalid because the file changed after signing, and the ISCC soft binding still matches the Content-Code Image at 100 percent, while the byte-based Data-Code and Instance-Code no longer match.

To show what each binding sees, we re-encoded a signed image at half size and copied its Content Credentials back in. C2PA says Invalid: the hash no longer matches the bytes. The ISCC Content-Code still matches the pixels at 100%, and at 81% after a crop; unrelated images score around 50%. The credentials stay invalid, but the ISCC shows which content they were made for.

1Inspect

Drop an image, a document or an audio file. See its Content Credentials (who signed it, when, and whether the signature holds) and its ISCC.

2Sign

Save a signed copy. Its Content Credentials carry the ISCC, a timestamp and, if you choose, whether AI training and data mining is allowed.

3Check

Open a signed file, changed or not. The app calculates the ISCC again and compares it with the one in the Content Credentials, unit by unit.

Why soft bindings

A hash breaks when one byte changes. That is the point, and the problem.

C2PA binds a manifest to its file with a cryptographic hash of the exact bytes. That proves nothing has changed. But platforms re-encode files and strip manifests every day: a re-encoded copy no longer matches its credentials, and a stripped copy has lost them. A soft binding connects credentials and content through the content itself, so a service can find the credentials of a copy again. C2PA allows two kinds:

Watermark

Embedded into the content

A party puts an identifier into the content before it spreads, and a decoder reads it back. Content that was never marked carries none.

Fingerprint · ISCC

Calculated from the content

Anyone can calculate it from any copy, at any time, with software that implements the open standard. Checking it means calculating it again.

Four codes, one soft binding

Similar content. Similar codes.

An ISCC is made of units, each calculated from a different part of the file. The demo stores them in one c2pa.soft-binding assertion with the algorithm io.iscc.v0, as IEP-0020 defines.

Each unit is compared as a percentage: unrelated content scores around 50%, and the closer to 100%, the closer the content. The byte-based Data-Code and Instance-Code drop as soon as a file is re-encoded; that is their job. The Content-Code follows the image, the text or the sound.

  1. Meta-CodeFrom title and description, which the manifest also stores.
  2. Content-CodeFrom the pixels, the text or the sound. Usually stays close through resizing and re-encoding.
  3. Data-CodeFrom the raw bytes. Survives small byte edits, not re-encoding.
  4. Instance-CodeA checksum of the bytes: an exact match, or none.

Why we built it

To show it, not just say it

It runs

io.iscc.v0 has been on the C2PA soft binding algorithm list since 2024. Here it runs end to end with c2pa-rs, the open source C2PA SDK of the Content Authenticity Initiative, on 19 file formats.

Anyone can check it

ISCC is an ISO standard with an open source reference implementation, so anyone can calculate it again and compare. The tests check every unit of this app against iscc-core and iscc-sdk, bit for bit.

Let's build it together

The Rust core and a command-line tool are Apache-2.0. IEP-0020 is still a draft: try the demo on your own files and tell us what works and what does not, on GitHub or at info@iscc.io.

Download · v0.1.0 · 2026-09-28

Try it with a file you know

Images: JPEG, PNG, WebP, GIF, TIFF, SVG. Documents: EPUB, Word, PowerPoint, Excel, OpenDocument, plain text, Markdown. Audio: MP3, FLAC, WAV, M4A. The builds are not code-signed yet, so each card says how to get past the system's warning at the first start.

Windows

Windows 10 and 11, x64

Installer 6.2 MB

iscc-c2pa-demo-0.1.0-windows-x64-setup.exe

SmartScreen shows “Windows protected your PC”. Choose More info, then Run anyway. The installer needs no admin rights.

macOS

macOS 11 or later, Apple silicon and Intel

for Terminal · read the script

curl -fsSL https://c2pa-demo.iscc.codes/install-mac.sh | bash

Paste it into Terminal. It downloads the latest release, checks its checksum, installs the app and opens it, with no security warning.

Prefer the disk image (16.5 MB)? Then macOS says it “could not verify” the app: choose Done, not Move to Bin, and Open Anyway in System Settings → Privacy & Security.

Linux

x86_64, WebKitGTK 4.1

AppImage 87.3 MB

iscc-c2pa-demo-0.1.0-linux-x86_64.AppImage

Make it executable and run it: chmod +x iscc-c2pa-demo-*.AppImage. Or install the .deb (Debian, Ubuntu) or the .rpm (Fedora, openSUSE).

Checksums: SHA256SUMS · Release notes · All releases

Good to know

What the demo does not do

For developers

Rust, Tauri and a little TypeScript

The core is Rust: c2pa-rs for Content Credentials, iscc-lib for ISCC, and pure Rust readers for every format. No external tools, no Python. The same core also builds as c2pa-iscc, a command-line tool that prints JSON, for scripts and agents.

Needs Rust 1.96 or later, Node 22.12 or later and pnpm. On Linux also the Tauri system libraries.

git clone https://github.com/iscc/iscc-c2pa-demo
cd iscc-c2pa-demo
pnpm install
pnpm tauri dev

# the command-line tool
cd src-tauri
cargo run --features cli --bin c2pa-iscc -- sign photo.jpg