C2PA

What Is C2PA and Content Credentials?

An explainer of the C2PA standard and Content Credentials: signed provenance attached to files, how it differs from invisible watermarks, and what a missing manifest does and does not mean.

Published
Last updated

C2PA — the Coalition for Content Provenance and Authenticity — publishes a technical standard for attaching tamper-evident provenance to media. Implementations of that standard are often presented to people as Content Credentials: a way to inspect where a file says it came from, what software touched it, and whether that history still verifies.

What a C2PA manifest is

A C2PA-enabled file can carry a signed manifest: structured statements about capture, generation, or edits, bound to the asset with cryptography. If the file is later altered in ways the standard treats as breaking that bind, verification should fail rather than silently present the old story as intact.

What C2PA is not

  • It is not a guarantee that an unsigned file is human-made.
  • It is not the same thing as an invisible statistical watermark.
  • It is not immune to stripping: some export paths, screenshot tools, and social platforms do not preserve manifests.
  • It is not a substitute for reading the assertions. A valid signature says the listed signer produced those claims, not that every claim about the world is true.

Why preservation tests matter

Even when a creator embeds Content Credentials, users often receive a derivative: a resized JPEG, a video re-encoded by a platform, or a screenshot. Independent tests should record the software, settings, and date, then state whether the credential survived. Until those tests exist here, this guide does not assert preservation rates.

How this fits the rest of the toolkit

Metadata inspection, hidden-character scanning, and watermark research answer different questions. C2PA is specifically about signed provenance bundled with a file. Mixing those questions produces overconfident labels such as “this image is verified AI” or “this image is verified real” from incomplete evidence.

Where this database currently documents C2PA

  • Claude: documented Content Credentials on supported generated files such as PNG, JPG, and SVG.
  • OpenAI: documented Content Credentials on supported generated images, alongside SynthID.
  • Gemini Apps: documented C2PA metadata for AI-created or edited media in Gemini Apps, not automatically every Google product.
  • Adobe Firefly: automatic Content Credentials on fully generated assets such as Text to Image.
We only claim what we can verify.

Sources

  1. C2PA Specifications — Coalition for Content Provenance and Authenticity

    Accessed August 15, 2026.

  2. Content Credentials — Content Authenticity Initiative

    Accessed August 15, 2026.

  3. c2pa-web SDK — Content Authenticity Initiative

    Accessed August 15, 2026.