Configure ClearKey as a testing content-protection mechanism for CENC-encrypted content

domain: w3.org · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Confirm the manifest signals CENC protection and that the player's EME stack supports org.w3.clearkey (the EME spec requires all EME-supporting browsers to implement Clear Key).
  2. For local/offline testing, configure the player directly with a key-ID-to-key hex map (e.g. Shaka Player's drm.clearKeys) — this bypasses any license server and forces Clear Key decryption regardless of manifest contents.
  3. For manifest-driven ClearKey, instead configure a license server URL for the org.w3.clearkey key system so the player performs a real EME license request.
  4. Player builds a JSON license request per the EME spec's Clear Key request format and POSTs it to that server.
  5. Server responds using the EME spec's Clear Key license format (JSON mapping key IDs to raw keys), which the CDM uses to decrypt the content.

Known gotchas

Related routes

Roll out a strict-dynamic Content Security Policy with nonce-based script trust and dual reporting endpoints before enforcing it
w3.org/TR/CSP3 · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans