Verify C2PA

← Guides

What is C2PA? Content Credentials explained

What is C2PA?

C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard that attaches a signed “manifest” to a digital file — image, video, audio, or document. The manifest records who produced the content, which tool or device was used, what edits were applied, and whether generative AI was involved. The user-facing name for this data is Content Credentials.

The coalition includes Adobe, Microsoft, Google, OpenAI, Intel, the BBC, the AP, and others. By 2026 it had been adopted across camera makers (Leica, Sony, Nikon, Canon, Samsung), AI generators (Adobe Firefly, OpenAI, Google), and platforms (Meta, TikTok, LinkedIn, X).

What a credential proves — and what it doesn’t

A valid Content Credential proves two things:

  1. The manifest has not been altered since it was signed (cryptographic integrity).
  2. Who claims to have signed it (the certificate holder).

It does not prove the scene is real, accurate, or lawfully owned. A camera can honestly sign a staged photo; a model can honestly label its own output as AI. Trust still depends on whether you trust the signer — which is exactly why recognising the signer against a database of major known issuers (Adobe, OpenAI, Google, Leica, and others) matters more than a bare “signature valid” check.

Why “no credential” is inconclusive

Most images online carry no credential at all. Screenshots, re-uploads, re-compression, and most messaging apps strip the manifest. So “no credentials found” proves nothing in either direction — only a present credential carries verifiable information.

→ Verify a file with the C2PA verifier