@contentauth/c2pa-js
    Preparing search index...
    interface TrustSettings {
        allowedList?: string | string[];
        trustAnchors?: string | string[];
        trustConfig?: string | string[];
        userAnchors?: string | string[];
        verifyTrustList?: boolean;
    }
    Index

    Properties

    allowedList?: string | string[]

    End-entity certificates.

    Possible values are: the text content of a end-entity cert file, a URL to fetch a end-entity cert file from, or an array of URLs that will be fetched and concatenated.

    trustAnchors?: string | string[]

    "System" trust anchors. Any asset validated off of this trust list will have a "signingCredential.trusted" result with an explanation noting the trust source is a "System" anchor.

    Possible values are: the text content of a .pem file, a URL to fetch a .pem file from, or an array of URLs that will be fetched and concatenated.

    trustConfig?: string | string[]

    Trust store

    Possible values are: the text content of a .cfg file, a URL to fetch a .cfg file from, or an array of URLs that will be fetched and concatenated.

    userAnchors?: string | string[]

    "User" trust anchors. Any asset validated off of this trust list will have a "signingCredential.trusted" result with an explanation noting the trust source is a "User" anchor.

    Possible values are: the text content of a .pem file, a URL to fetch a .pem file from, or an array of URLs that will be fetched and concatenated.

    verifyTrustList?: boolean

    Enable trust-list validation for this section (trust or cawgTrust). The default value is "true."

    c2pa-rs 0.91 removed the separate cawg_trust settings section and the underlying "check trust but don't report anything" toggle it backed. Setting this to false is approximated by omitting this section's anchors entirely from the resolved settings, which prevents the corresponding certificate chain from being trusted — but unlike before, the SDK's own validation still runs and now reports an explicit "untrusted" status rather than staying silent.