01 / OVERVIEW
A licence token is evidence,
not currency.
Proof turns a specific permission to use a person or protected identity into a signed, machine-readable credential. The credential can be checked without calling the original production tool and can change status without rewriting history.
Identity, parties, scope, dates, duties, prohibitions and status.
Possession never grants rights. Every use is evaluated against actor and context.
No speculative ownership, transferability or public-chain dependency.
The contract remains authoritative; the token is its operational projection and evidence link.
02 / ARCHITECTURE
Six layers. One decision.
Proof separates concerns so a compromised media file, production provider or distribution platform cannot silently rewrite the underlying authority.
Verified subject, representative and organisation identifiers.
→Signed evidence of informed approval; sensitive evidence remains private.
→Portable scope expressed as permissions, prohibitions, duties and constraints.
→Exact SHA-256 byte binding, perceptual DCT fingerprinting and Google SynthID watermark detection.
→C2PA 2.4 manifest records media provenance, ingredients, transformations and Proof assertions.
→Current revocation state and append-only issuance/event receipts.
→03 / TOKEN LIFECYCLE
From human approval
to machine enforcement.
- 1
Request
A brand or producer submits a structured use request: purpose, script, model, territories, channels, duration and volume.
- 2
Resolve authority
Proof verifies the identity root and that the approving person or agency is authorised to act.
- 3
Collect consent
The human-readable summary and legal terms are approved. Proof hashes the signed evidence and records the consent ceremony.
- 4
Compile policy
Contract clauses are normalized into an AVATARZ ODRL profile. Ambiguity or unsupported constraints block issuance.
- 5
Issue + sign
A canonical credential is assigned an immutable ID, signed by an isolated issuer key and time-stamped.
- 6
Authorize job
Before generation, the requester, reference asset, provider, model and intended context are evaluated against the current credential.
- 7
Bind outputs
Each final asset references the licence token; its exact and optional soft bindings are recorded with C2PA provenance.
- 8
Monitor + close
Verification events, counters, expiry, suspension and revocation are appended without mutating past evidence.
04 / CREDENTIAL MODEL
Small public envelope.
Precise private evidence.
Public / portable
- Stable token ID and schema version
- Issuer and verification key reference
- Pseudonymous subject and licensee IDs
- Permissions, prohibitions and duties
- Territory, channel, language, time and volume constraints
- Status-list entry and evidence digests
Private / access-controlled
- Identity documents and liveness evidence
- Contracts, signatures and approval recordings
- Contact details, remuneration and commercial terms
- Internal review notes and incident evidence
- Key ceremony and privileged audit records
{
"@context": ["https://www.w3.org/ns/credentials/v2"],
"id": "https://proof.avatarz.com/licences/AAP-LIC-2026-C91F",
"type": ["VerifiableCredential", "AvatarzLikenessLicence"],
"issuer": "did:web:proof.avatarz.com",
"validFrom": "2026-07-27T14:08:19Z",
"validUntil": "2026-09-30T23:59:59Z",
"credentialSubject": {
"id": "urn:avatarz:identity:marcus-vale",
"licensee": "urn:avatarz:org:northstar-sports",
"policy": {
"profile": "https://proof.avatarz.com/ns/odrl/likeness/v1",
"permissions": ["generate", "translate", "distribute"],
"prohibitions": ["paid-media", "political-use", "model-training"],
"territories": ["FR", "GB"],
"channels": ["owned-social", "crm", "stadium"],
"languages": ["fr", "en"],
"maxAssets": 50
},
"consentReceipt": "sha256:0c38…c7a1"
},
"credentialStatus": {
"type": "BitstringStatusListEntry",
"statusPurpose": "revocation",
"statusListIndex": "4192",
"statusListCredential": "https://proof.avatarz.com/status/2026-07"
}
}05 / GENERATION
Deterministic before
cryptographic.
The issuing service never signs raw form input. It validates, resolves, normalizes and canonicalizes the policy first, producing the same digest for semantically identical approved data.
Schema gate
Strict Zod/JSON Schema validation; unknown policy fields fail closed.
Authority gate
Representative mandate and identity status checked at issuance time.
Policy compiler
Human clauses mapped to atomic ODRL-style rules; conflicts default to invalid.
Canonical form
Stable JSON representation hashed with SHA-256 before signing.
Key operation
Ed25519/EdDSA or approved enterprise profile; private key isolated in KMS/HSM.
Trusted time
RFC 3161 time-stamp over the credential digest for long-term evidence.
Status allocation
A privacy-preserving status-list index allocated independently of identity.
Transparency receipt
Digest appended to a Merkle-based log; inclusion receipt returned.
06 / VERIFICATION
Verification returns
a reasoned decision.
Cryptographic hard binding, multi-signal corroboration, watermark detection, or perceptual candidate.
C2PA signer, manifest integrity, ingredients graph, actions and trusted timestamp.
Accreditation, representation mandate, consent ceremony and active signing key status.
Actor, action, territory, channel, purpose, dates, volume quota and current revocation status.
A missing key, stale status list, unknown policy term, conflicting signal or mismatched context does not become “probably valid”. The engine returns deny or review with stable reason codes.
Anchored Licence Check (POST /v1/verify) evaluates a known token ID against a declared action and asset hash. Inbound Multi-Signal Discovery (POST /v1/verify-inbound) accepts raw media bytes or URLs, running C2PA, Google SynthID, and perceptual hashing in parallel to discover candidate records and evaluate rights automatically.
POST /v1/verify
{
"token_id": "AAP-LIC-2026-C91F",
"action": "distribute",
"context": {
"territory": "FR",
"channel": "owned-social",
"language": "fr",
"asset_sha256": "89d2c6…a01f"
}
}
200 OK
{
"integrity": "valid",
"provenance": "verified",
"authority": "verified",
"usage": "allow",
"reason_codes": [],
"checked_at": "2026-07-27T18:42:11Z",
"receipt": "pvr_01JZCC2Y…"
}07 / C2PA BRIDGE
C2PA proves the media chain.
Proof adds the rights chain.
What happened to the asset?
Claim generator, ingredients, edits, content bindings, claim signature and trusted time-stamp.
Was this use authorised?
Identity authority, consent, licensee, purpose, channels, territories, dates, duties and revocation.
For each final media asset, the intended design places the Proof token URI and credential digest in a namespaced custom C2PA assertion. The C2PA manifest remains the source of media provenance. Proof evaluates the linked commercial and consent scope.
Cryptographic hash detects any byte-level change.
Fingerprint or watermark helps recover provenance after transcoding or metadata stripping.
Soft binding locates the repository record; signatures and hard bindings still determine integrity.
The planned assertion label is com.avatarz.proof.binding.v1. It is an AVATARZ interoperability profile, not a registered C2PA standard assertion and not a claim of C2PA conformance. It carries references and digests—not contracts, identity documents or private commercial terms.
Signature, timestamp, ingredients, actions and content binding are checked according to C2PA.
✓The verifier retrieves the signed licence by URI and confirms its digest and current status.
→The Trust Registry connects signing key, accreditation, mandate and protected subject.
→Proof returns allow, deny or review with stable reason codes and a verification receipt.
✓{
"@context": "https://proof.avatarz.com/ns/c2pa/v1",
"profile": "https://proof.avatarz.com/profiles/c2pa-bridge/v0.1",
"licence": {
"id": "https://proof.avatarz.com/licences/AAP-LIC-2026-C91F",
"credentialDigest": "sha256:55f1…a80c",
"status": "https://proof.avatarz.com/status/2026-07"
},
"authorization": {
"grantDigest": "sha256:103e…9f11",
"providerJob": "heygen:job:demo_1042"
},
"binding": {
"receipt": "https://proof.avatarz.com/receipts/pbr_01JZDB1P"
}
}Non-equivalence rule. A trusted C2PA manifest never means that a commercial use is authorised. A valid Proof licence never guarantees that a file has an intact Content Credential. When C2PA manifests are stripped during distribution, Proof engages durable signal verification via SynthID and perceptual hashing.
08 / SYNTHID & MULTI-SIGNAL
C2PA proves the history.
SynthID survives the journey.
Embedded C2PA manifests can be dropped during social media re-encoding, video transcoders, or metadata scrubbers. Proof combines C2PA cryptographic claims with Google SynthID imperceptible watermarking and perceptual hashing into a unified multi-signal verification pipeline, recovering detached credentials and detecting unauthorized modifications.
Signed manifest, claim signature, ingredient tree and tamper evidence. Fragile to platform re-encoding.
Imperceptible watermark in pixels, video or audio. Survives cropping, filters, frame-rate shifts and lossy compression.
64-bit DCT visual fingerprint matching within Hamming distance thresholds to locate candidate assets.
Evaluates identity authority, consent, licensee, purpose, channels, territories, dates and real-time revocation.
Cryptographic match directly yields verified (1.0 confidence) and evaluates rights.
Independent durable signals agree, yielding corroborated (0.90–0.95 confidence) and recovering the licence.
Perceptual soft-binding queries the registry to restore the detached manifest, yielding corroborated (0.95 confidence).
Watermark carries a resolvable ID mapped to Proof, yielding corroborated (0.85 confidence).
AI origin is recorded (detected, 0.50 confidence), but rights remain unresolved; cannot authorize on watermark alone.
Mismatched external IDs trigger an immediate collision flag (conflicting), escalating to review.
Detecting a Google SynthID watermark confirms synthetic media origin and persistence across modifications, but never proves that a person’s likeness, voice, or character was licensed for a specific commercial campaign, territory, or channel. The resolver rejects naive “if SynthID then authorized” shortcuts.
A missing SynthID watermark must not be interpreted as evidence that content is human-made or authorized. It may originate from another model, an unsupported media modality, or modifications outside detector tolerances.
POST /v1/verify-inbound
{
"source_url": "https://cdn.example.com/campaigns/spot_cut_04.mp4",
"mime_type": "video/mp4"
}
200 OK (Async Job Resolved)
{
"job_id": "vjb_01JK88P9E2",
"state": "done",
"identification_state": "corroborated",
"identification_confidence": 0.94,
"provenance_integrity": "corroborated",
"rights_resolution": "resolved",
"authorization_decision": "allow",
"resolved_licence_id": "AAP-LIC-2026-C91F",
"reason_codes": [
"C2PA_MISSING",
"SYNTHID_DETECTED",
"PHASH_CANDIDATE_MATCH",
"AUTONOMOUS_ALLOW_HIGH_CONFIDENCE"
],
"signal_observations": [
{
"provider": "c2pa",
"signal_type": "provenance",
"status": "not_detected",
"limitations": ["no_embedded_c2pa_manifest", "c2pa_manifest_may_be_stripped_on_re_encode"]
},
{
"provider": "synthid",
"signal_type": "watermark",
"status": "detected",
"confidence": 0.96,
"detector_version": "synthid-v2.0",
"limitations": ["synthid_watermark_persistence_depends_on_media_modifications", "score_is_probabilistic_not_cryptographic_proof"]
},
{
"provider": "phash",
"signal_type": "fingerprint",
"status": "detected",
"confidence": 0.92,
"external_id": "ast_01JH92KA9P",
"limitations": ["perceptual_similarity_is_not_cryptographic_identity"]
}
]
}09 / OPTIONAL CHAIN ANCHORING
Blockchain-capable.
Never blockchain-dependent.
Proof works end to end without a blockchain. Credentials are signed, status is independently resolvable, trusted time can be provided through RFC 3161, and transparency receipts can be verified against the AVATARZ append-only log. A chain adapter is an optional publication destination for selected digests — not the source of truth and never a condition for issuing or verifying a token.
Identity, consent, policy, signature, asset binding, revocation and audit remain chain-agnostic.
A batch Merkle root or selected receipt digest may be published to a public, consortium or private ledger.
The anchor corroborates existence and ordering; it cannot create consent, validate a licence or override revocation.
Neutrality across organisations
A shared external anchor can reduce reliance on AVATARZ alone when agencies, rightsholders, platforms and auditors need common evidence.
Digests, never sensitive evidence
Only batched roots, timestamps and protocol identifiers by default. No identity documents, contracts, personal data, media or commercial terms.
Replaceable by design
The adapter interface supports several networks or none. Verification continues if a partner chain is unavailable, expensive or discontinued.
Enterprise anchoring policy
Customers could choose anchor frequency, network, redundancy, retention receipts and independent audit exports as paid assurance options.
Proof would retain protocol governance, multi-chain portability and a fully functional off-chain profile. Partnership language must never imply exclusivity, token speculation, legal validity “created” by the chain or mandatory use of the partner network.
10 / SECURITY ARCHITECTURE
Keys sign facts.
Controls protect meaning.
Non-exportable KMS/HSM keys, least-privilege signing role, dual control for root and rotation operations.
Versioned public JWK set / controlled identifier; every token pins a key ID and algorithm.
Short operational key periods, overlapping verification window, emergency revocation and historical key retention.
TLS in transit; envelope encryption at rest; evidence separated by tenant and purpose.
Workload identity and mutually authenticated service calls for privileged issuance paths.
Fine-grained policy checks; no UI role alone can sign, revoke or export sensitive evidence.
Every privileged read, decision and key operation produces an immutable, correlated audit event.
Pseudonymous public identifiers, minimum disclosure, status-list caching and no identity in list indexes.
11 / STATUS & REVOCATION
History is immutable.
Authority is not.
Proof never deletes or rewrites an issued credential. It publishes a signed status transition and preserves the previous state, reason, actor and effective time.
Credential can be evaluated.
Temporarily blocked during review.
Permanently invalid for new use.
Retained as evidence only.
Distribution cannot be magically recalled. Revocation changes future verification results, triggers notices and takedown workflows, and creates evidence of non-compliant reuse.
12 / THREAT MODEL
Designed around
how proof fails.
Signature and canonical digest fail.
RejectAudience, action, territory, channel and asset are re-evaluated.
DenySynthID watermark + pHash soft-binding recover manifest & token.
Recover / reviewConflicting provider external IDs trigger immediate collision flag.
ReviewRevoke key, publish incident time, re-issue unaffected credentials.
ContainSuspend identity authority and dependent credentials.
SuspendAsset counter and unregistered hash reveal out-of-scope media.
FlagUse bounded cache; stale beyond policy threshold never returns allow.
ReviewSeparation of duties, dual control and independent audit stream.
Escalate13 / PRODUCT SURFACES
One protocol.
Several trust surfaces.
POST /v1/licence-requestsRequest issuance; sign only after authority, consent and policy validation.
POST /v1/authorizationsEvaluate one generation job and return a short-lived grant or reasoned refusal.
POST /v1/assetsBind the final output, provider evidence and C2PA manifest to the authorised job.
POST /v1/verifyContextual allow, deny or review check for a declared licence and asset hash.
POST /v1/verify-inboundIngest media bytes or URL for async C2PA, SynthID and pHash multi-signal discovery.
GET /v1/status/:listCacheable signed status lists with privacy-preserving indexes.
proof.licence.revokedSigned webhooks for expiry, suspension, revocation and misuse.
Product names describe operational surfaces, not separate trust systems. See how Issue, Authorize, Bind and Verify form one control loop ↗
14 / GOVERNANCE
Cryptography cannot decide
who deserves trust.
Production readiness requires governance around issuer admission, identity assurance levels, representative mandates, schema changes, dispute resolution, retention, law-enforcement requests and transparent incident reporting.
15 / STANDARDS & REFERENCES
Built on standards.
Explicit about extensions.
Media provenance, claim signatures, content bindings and trust model
Imperceptible generative AI watermarking and Content Detection architecture
Discrete Cosine Transform perceptual hashing for media soft-binding and similarity recovery
Portable issuer–subject credentials, validity and status references
Standards-based signing and encryption envelopes for credentials
Privacy-preserving suspension and revocation status
Permissions, prohibitions, duties and constraints
Trusted time-stamp protocol
JSON Web Signatures and public key discovery
Edwards-curve digital signatures including Ed25519
Merkle inclusion and consistency proof design; Proof does not claim CT conformance
Key lifecycle, protection, accountability and audit guidance