Skip to content

What are Content Credentials (C2PA)?

Updated September 2026

Content Credentials are a cryptographically signed manifest embedded in a media file recording what created it and what was done to it since — the strongest available evidence of origin, and also the easiest to destroy, because saving a screenshot removes it entirely.

Most debate about AI content assumes the only way to judge a file is to examine it. Content Credentials take the opposite approach: instead of inferring origin from pixels, the file carries a signed statement of its own history.

The standard behind them is C2PA, from the Coalition for Content Provenance and Authenticity — a body whose members include Adobe, Microsoft, the BBC, Sony, Nikon and Leica. This is a practical explanation of what the record contains, where it physically lives inside a file, and what it does not solve.

What a manifest contains

A C2PA manifest is a structured record describing an asset's history. At minimum it names the claim generator — the software or device that created the file. It can also record actions taken since: edits, crops, format conversions, or that generative AI was involved.

The record is cryptographically signed. A verifier can check that the manifest was produced by the claimed signer and has not been altered since, and can detect whether the pixels have changed since it was signed.

One field matters particularly for AI detection: the IPTC DigitalSourceType. When set to trainedAlgorithmicMedia, it is an explicit machine-readable declaration that the asset was produced by a generative model. That is the standards-body way of saying “this is AI-generated”.

Where it physically lives in a file

The manifest is packaged as JUMBF — a container format from the JPEG standards family — and then attached to the file in whatever way that format permits. This differs per container, which is why generic metadata tools often miss it entirely.

In JPEG it rides in APP11 marker segments. In PNG it occupies a chunk of type caBX. In WebP it is a RIFF chunk labelled C2PA. In HEIF and AVIF it sits inside the meta box. A tool that only reads EXIF will not see any of these.

Because it is attached to the file rather than derived from its contents, it survives copying and moving but not re-encoding. Anything that rebuilds the file from its pixels — a screenshot, most social platform uploads, many conversion tools — discards it.

Who actually attaches them

Adoption is real but uneven. Adobe attaches Content Credentials to Firefly output and supports them across Creative Cloud. OpenAI attaches them to DALL·E images. Google has added them to several of its image surfaces. On the capture side, Leica and Sony ship cameras that sign photographs at the moment they are taken, and Nikon has committed to the same.

News organisations including the BBC have experimented with them as a way of letting readers verify where a photograph came from — which is arguably the more important application than AI detection.

The uneven part is distribution. Most social platforms still strip metadata on upload, so a credential that existed when the file was created is frequently gone by the time anyone sees the image.

Detecting a manifest is not verifying it

This distinction is routinely blurred by tools that check Content Credentials, including in its lighter form on this site, and it is worth being precise about.

Locating a manifest and reading the tool it names is straightforward — you parse the container and read the fields. Verifying it means checking the cryptographic signature against a trust list of known signers and confirming the asset hash still matches. That requires the full C2PA implementation and a maintained trust list.

A tool doing only the first can be misled by a hand-crafted manifest. If a verdict matters, use a verifier that explicitly checks signatures, such as Adobe's Content Credentials inspector or the C2PA reference tooling.

What it cannot do

Absence proves nothing. The overwhelming majority of images online have no credentials, because the tool that made them does not attach any or because a platform stripped them. A missing manifest is not evidence of anything at all.

It also does not survive adversarial handling. Anyone wanting to conceal an image's origin removes the credential in seconds. Provenance is therefore excellent at confirming origin when someone is cooperating, and useless against someone who is not.

That asymmetry is the honest framing: Content Credentials are strong positive evidence and almost worthless as negative evidence.

Try it on a file

Runs every check described above, in that order, and shows you which one produced the answer.

Drag a file here, or

JPEG, PNG, WebP, AVIF, PDF or .txt · up to 10 MB · you can also paste a screenshot

By uploading you agree to our Terms and Privacy Policy. Your file, IP address, approximate location and device details are stored.

Frequently asked questions

Does C2PA prove an image is real?

It proves what the signing tool asserted and that the file has not changed since. A camera credential is strong evidence a photograph was captured rather than generated. It cannot speak to whether the scene in front of the lens was staged.

Why do most images have no Content Credentials?

Two reasons. Adoption is still partial, so many tools attach nothing. And most social platforms strip metadata on upload, so credentials that did exist are frequently removed before anyone else sees the file.

Can Content Credentials be faked?

A manifest can be fabricated, which is why verification matters — a properly verified credential checks the signature against known signers, so a forgery fails. A tool that only detects a manifest's presence without verifying it would report a fake at face value.

How do I check a file's Content Credentials?

Adobe's Content Credentials inspector and the C2PA reference tooling perform full verification including signatures. Lighter tools, including this one, report the manifest's presence and the generator it names, which is useful for a quick check but is not verification.

Related reading