Generate imagesGenerate videosGenerate music

C2PA Content Credentials: Metadata, Checker and How to Verify Any Image or Video

A C2PA Content Credentials manifest is a signed record of who made a file and how it was edited. See what the metadata contains, which checker reads it best, why it vanishes on social platforms, and how to verify images, video and music yourself, step by step.

C2PA Content Credentials: Metadata, Checker and How to Verify Any Image or Video
Cristian Da Conceicao
Founder of Picasso IA

A photo lands in your inbox with a confident caption and a source you cannot confirm. Is it a real shot, a retouched shot, or a picture someone typed into a prompt box? C2PA Content Credentials are the closest thing the industry has to a tamper-evident label for that question. They attach a signed record to an image, video or audio file that says who made it, with which tool, and what happened to it afterwards.

This article explains what sits inside that record, which metadata fields matter, which C2PA checker gives a fast answer, and how to verify a file by hand when you need proof instead of a badge. It also looks at the unglamorous part: why credentials disappear, what a green check really means, and what to do with the media you generate yourself.

What C2PA Content Credentials Are

C2PA stands for the Coalition for Content Provenance and Authenticity, a group formed in 2021 that merged the Content Authenticity Initiative led by Adobe with Project Origin from Microsoft and the BBC. The coalition publishes an open technical specification for content provenance. Content Credentials is the public-facing name for the feature built on that specification, the one you see as a small "CR" badge in supported apps.

A Signed Receipt for Media

Think of a credential as a receipt stapled to a file. When a camera, an editing app or a generative model creates or changes a file, it writes a manifest: a bundle of statements about the file, signed with a certificate that identifies the software or hardware vendor. If anyone alters the pixels afterwards without re-signing, the numbers stop matching and a checker raises a flag.

That is the "tamper-evident" part. Credentials do not stop edits. They make silent edits visible.

Hand pressing a brass stamp into red wax on an envelope holding a printed photograph

C2PA vs EXIF Metadata

Most people have seen EXIF data: camera model, lens, date, sometimes GPS. It is plain text that any free tool can rewrite in seconds. A C2PA manifest is a different animal because it is cryptographically signed and tied to the file contents.

FeatureEXIF / IPTC metadataC2PA manifest
Who can change itAnyone with a free editorOnly a holder of a signing certificate, and changes are detectable
Digital signatureNoYes
Tied to the pixelsNoYes, through a hash
Records edit historyNoYes, as actions and ingredients
Survives a screenshotNoNo

💡 Tip: EXIF can say "shot on a Leica" even if the file came straight from a prompt. A C2PA manifest can make the same claim, but with a signature a checker can validate against the signer's certificate.

Inside a Manifest

Claims, Assertions and Signatures

A manifest has three layers, and each one answers a different question.

  • Assertions are the statements: the actions taken (created, cropped, color adjusted), the software that did it, a thumbnail, and a digital source type that says whether the content came from a camera capture or from a trained algorithmic model.
  • The claim lists those assertions together with their hashes, so none can be swapped out unnoticed.
  • The claim signature is a digital signature made with an X.509 certificate. It proves which signer stands behind the claim.

When a checker opens a file, it recomputes every hash, verifies the signature, and walks the certificate chain back to an issuer it recognizes.

Hard Bindings and Soft Bindings

Two kinds of links hold a manifest to its file.

A hard binding is a hash of the file's bytes, excluding the manifest region itself. Change a single pixel and the hash no longer matches. This is why an edit made in a tool that does not re-sign leaves the file with an invalid result.

A soft binding is looser: an invisible watermark or a perceptual fingerprint that lets a service look up a manifest even after the embedded copy was stripped. Soft bindings are the basis of what Adobe calls durable Content Credentials.

Developer working at a laptop in a dim home office with rows of code on the screen

Where the Bytes Live

The manifest is packed into a JUMBF container (the JPEG universal metadata box format). In a JPEG it sits in APP11 segments. In a PNG it lives in a dedicated chunk called caBX. In an MP4 it sits in its own box. Audio formats such as WAV and MP3 can carry manifests too.

A manifest can also be stored remotely, with the file holding only a link to it. That is handy for size, but it means the credential is only as durable as the server hosting it.

Best C2PA Checker Options

You do not need to be a developer to check a file. You do need to pick the right tool for the question you are asking.

Browser Verify Tools

The simplest path is the Content Credentials Verify page run by the Content Authenticity Initiative. Drop a file onto it and it shows a summary: the signer, the tools used, the actions recorded, and whether anything was generated by AI. Several third-party viewers parse the manifest in the browser with WebAssembly, so the file never leaves your computer. Check the privacy note of any viewer before dropping in a sensitive file.

Command Line With c2patool

For batches, audits and automation, the open-source c2patool reads and writes manifests from a terminal.

c2patool photo.jpg
c2patool photo.jpg -d
c2patool clip.mp4 --info

The first line prints the manifest as JSON. The second adds the detailed, JUMBF-level view with assertion URLs and hashes. The third prints a short validation summary, which is useful in scripts. Recent versions of ExifTool will also list that a JUMBF block exists, though they will not validate the signature for you.

Top-down view of a desk with a laptop showing a photo with a small badge, a smartphone and a notebook

Phones and Editing Apps

Photoshop shows a Content Credentials panel for files that carry a manifest. Google Photos displays credentials on supported phones, and some social platforms, LinkedIn among them, show the small CR badge on posts. These views are convenient but shallow. They rarely show the certificate details, so use them for a first look, not for a ruling.

Checker typeBest forWatch out for
Browser Verify pageQuick answers, readable edit historyUploading private files to a third party
In-browser WebAssembly viewerLocal inspection of the raw manifestVariable trust list handling
c2patoolBatches, scripts, full JSONNeeds a terminal and some patience
Photoshop panelChecking files already in your workflowLimited signer detail
Social badgeCasual browsingOnly shows what the platform kept

How to Verify in Five Steps

Two hands holding a smartphone that displays a mountain photograph with a small badge in the corner

Follow this order and you will avoid most wrong calls.

  1. Get the original file. A screenshot or a re-saved copy has almost certainly lost its manifest. Ask the sender for the untouched file, or download the original from the publisher.
  2. Run two checkers. Use one browser tool and c2patool. If they disagree, trust the one that shows the raw manifest.
  3. Read the validation state. Valid, well-formed but untrusted, or invalid. The table below explains each.
  4. Inspect the signer. Look at the issuing certificate, the organization name and whether it appears on the C2PA trust list. A random signer you have never heard of is a claim, not a guarantee.
  5. Walk the edit history. Read the actions in order. Look for the source type, any AI generation step, and ingredients that point back to earlier versions.
ResultWhat it meansYour next move
No manifest foundNo credentials were ever added, or they were strippedLook for the original. Do not call the file fake on this alone
Valid, trusted signerSignature intact, file unchanged since signing, signer recognizedRead the actions and the source type
Well-formed, untrusted signerStructure and signature are fine, signer is not on a trust listTreat it as a statement from an unknown party
Invalid or hash mismatchThe file changed after signing or the manifest is damagedDo not rely on it. Request the original

💡 Tip: "No manifest" and "invalid manifest" are very different results. The first is silence. The second is a warning.

Why Credentials Disappear

Platforms That Strip Metadata

The biggest weakness of embedded credentials is also the most boring one: files get rewritten. Any step that decodes the image and encodes it again discards the manifest unless the software knows how to carry it across.

ActionCredentials survive?
Downloading the original from its sourceUsually yes
Sending the unchanged file as an attachmentUsually yes
Taking a screenshotNo
Saving a copy through a basic editorOften no
Uploading to a platform that recompressesOften no
Hosting behind a CDN set to preserve themYes, if the setting is on

Young woman scrolling on her phone in a crowded subway carriage with blurred commuters behind her

If you run a website, check your image pipeline. Resizing plugins, format converters and some CDNs strip metadata by default, and some now offer a switch to preserve Content Credentials.

Durable Credentials and Watermarks

Because stripping is so common, the industry layers several methods together.

MethodSurvives a screenshotTamper-evidentShows edit history
Embedded C2PA manifestNoYesYes
Cloud manifest plus soft bindingOften retrievableYesYes
Invisible watermark such as SynthIDOftenNot by itselfNo
Visible labelUntil it is croppedNoNo

An invisible watermark can tell a service that an image came from a certain generator. It does not carry a signed history. A manifest carries the history but can be stripped. Pairing them is the idea behind durable credentials, and it is why a serious provenance setup rarely depends on one method alone.

Cameras and Generators That Sign

Cameras and Phones

Hardware signing starts at capture, which is the strongest place to sign because the file never existed unsigned. Leica shipped the first mainstream camera with the feature. Sony added support on the Alpha 1 II and Alpha 9 III. Google's Pixel 10 series signs photos in the Pixel Camera app at Assurance Level 2, and Google Photos can display the result.

The picture is not perfectly tidy. Nikon rolled out credentials for the Z6 III through a firmware update, then revoked its certificates after a flaw let authentic and unauthentic images be combined while keeping a valid signature. That episode shows both sides of the system: signing can fail, and revocation is how the ecosystem responds.

Street photographer raising a mirrorless camera to his eye on a quiet city corner at sunrise

AI Image Generators

Many of the large image generators now attach a manifest to their output, marked with the trainedAlgorithmicMedia source type so a checker can tell the picture was synthesized. Whether a particular file carries one depends on the model provider and on every step between the model and your download folder.

On Picasso IA you can test this yourself with several image models, including Nano Banana Pro, Seedream 4.5, GPT Image 2 and Flux 2 Pro. Generate an image, download the file, run it through a checker, and write down what you see. Do not assume a result, because pipelines differ.

Editing changes the answer. An upscaler rewrites pixels, so a manifest from before the upscale will no longer validate unless the tool signs again. If you finish a picture with Topaz Image Upscale, check the final file, not the source.

Video and Music

Video raises the stakes because clips travel through more transcoders than photos. A manifest on an MP4 can vanish the moment a platform re-encodes it for streaming. The 2.3 release of the specification added support for live streams, which matters for broadcasters who need to sign footage as it is produced.

Bearded video editor seated before two monitors in a dim edit suite

If you work with generated clips, you can test the same loop with Veo 3.1, Sora 2, Kling v3 Video or Seedance 2.0. Download the MP4 before it is compressed anywhere else and inspect that copy.

Audio is the quietest corner of provenance. Music tools such as Lyria 3, ElevenLabs Music, Stable Audio 2.5 and MiniMax Music 2.6 produce tracks that can in principle carry a manifest, but support in players and checkers lags behind images. Expect fewer tools to display the result.

Female musician with headphones at a condenser microphone inside a warm recording booth

What a Valid Signature Can't Prove

Trust Is Not Truth

A green result proves two things: the file has not changed since it was signed, and a named signer stands behind the claim. It does not prove that the scene was real, that the caption is honest, or that the photographer did not stage the moment. A staged photo taken with a signing camera is still a staged photo.

Likewise, a missing manifest is not evidence of fakery. Most genuine photos in circulation carry no credentials at all, because the camera never signed them or a platform stripped them on the way. Use credentials as one signal next to reverse image search, source checking and common sense.

⚠️ Heads up: Never accept a badge screenshot as proof. A screenshot of a verification page is just another image. Open the file itself in a checker.

Rules Pushing Adoption

Regulation is nudging the market. The EU AI Act includes transparency duties under Article 50 that call for synthetic content to be marked in a machine-readable way, and C2PA is one of the most frequently cited mechanisms for doing it. Newsrooms, stock libraries and ad platforms are adding provenance checks to their intake processes for the same reason: they want a paper trail when a picture is challenged.

For creators, the practical takeaway is simple. Keep your original exports, keep any manifest intact when you publish, and note which tools touched a file.

Woman reading a bound policy document at a long oak table in a quiet library

Make and Check Your Own Media

Reading about provenance only goes so far. The fastest way to get comfortable with it is to run the whole loop on files you create.

  1. Generate an image with Nano Banana Pro or Seedream 4.5 and download the original.
  2. Make a short clip with Veo 3.1 and keep the untouched MP4.
  3. Compose a track with Lyria 3 or Stable Audio 2.5.
  4. Drop each file into a browser checker and c2patool, and record whether a manifest is present, valid and trusted.
  5. Change one thing, such as resizing or re-saving, and check again to watch the result flip from valid to missing or invalid.

That last step teaches more than any article. Seeing a signature break after a harmless-looking export shows exactly why provenance depends on the whole pipeline and not on one file.

Ready to try it? Open Picasso IA, pick a model from the full model list, and create your own images, videos and music. Then run your downloads through a C2PA checker and see what your files really say about where they came from.

Share this article