What are Content Credentials (C2PA)?
Content Credentials are signed records of where an image came from and how it was edited. How C2PA works, where it is stored, and what it can and cannot prove.
· 7 min read
Content Credentials are a signed record, stored inside a file, of where a piece of content came from and what has been done to it. They are built on an open standard from the Coalition for Content Provenance and Authenticity (C2PA), a group founded in 2021 by companies including Adobe, Arm, the BBC, Intel, Microsoft and Truepic. You may see them shown as a small CR icon on images.
What a manifest records
The record is called a manifest. It is made of statements, called assertions, such as:
- Actions: created, opened, edited, cropped, resized, and the software that did each one.
- Digital source type: whether the content was captured by a camera or made with a generative model, using IPTC terms such as
trainedAlgorithmicMedia. - Ingredients: earlier files the image was made from, each possibly with its own manifest.
- A hash of the content, so any later change to the image can be detected.
The manifest is signed with a certificate, much like a website's HTTPS certificate. Anyone can check that the signature is valid and that the image has not changed since it was signed. A file can carry several manifests, one for each step in its history.
Where it is stored
| Format | Where the manifest lives |
|---|---|
| JPEG | APP11 segments holding a JUMBF box |
| PNG | A caBX chunk |
| WebP | A C2PA chunk |
Manifests can also be stored online and linked from the file.
Who adds Content Credentials
Adobe's Photoshop and Firefly can add them, as do several AI image generators, including OpenAI's. A growing number of cameras and phones sign photos at capture, and some news organisations and platforms display them.
What they can and cannot prove
- A valid signature proves who signed the manifest and that the image has not changed since. It is the strongest provenance evidence a file can carry.
- It does not prove that what the picture shows is true. A signer can only vouch for what their software saw.
- Manifests can be removed. A file without Content Credentials is not proof of anything. Some systems pair them with invisible watermarks or fingerprints so they can be recovered.
- Editing a file after signing, even only its other metadata, makes the signature fail its hash check.
How to read them
Drop an image into Exifo Check. It shows the generating tool, the signer, the signing time and the recorded actions, and verifies the signature in your browser with the official C2PA SDK. It also tells you whether the manifest marks the image as AI-generated or AI-edited.
Removing Content Credentials
Clean can remove Content Credentials along with other metadata, for example to protect a photographer's identity. But they often exist to disclose that content was made with AI, and some rules require that disclosure to stay. India's IT Amendment Rules, 2026, prohibit removing AI labels and provenance metadata, and the EU AI Act sets transparency duties for AI-generated content. Check the rules that apply to you, and never use metadata removal to pass off synthetic media as real.