- c2pa_trusted
- Chain reaches the current official C2PA Trust List.
- roma_trusted
- Signer is verified in Roma’s identity layer, not official Trusted.
- self_signed
- Self-signed or test certificate; the signature may still verify.
- unknown
- Cannot conclude Trusted against the list.
- legacy
- Older/partially parsed format.
- untrusted
- Explicitly not trusted; not necessarily a crypto failure.
- invalid
- Signature, binding, or certificate validation failed.
Docs
trust_status
trust_status describes signer trust, not whether signature bytes verify. Use invalid when the signature fails. Valid signatures off the Trust List are usually unknown or self_signed.