C2PA Content Credentials: Metadata, Checker and How to Verify Any Image or Video
A C2PA Content Credentials manifest is a signed record of who made a file and how it was edited. See what the metadata contains, which checker reads it best, why it vanishes on social platforms, and how to verify images, video and music yourself, step by step.
A photo lands in your inbox with a confident caption and a source you cannot confirm. Is it a real shot, a retouched shot, or a picture someone typed into a prompt box? C2PA Content Credentials are the closest thing the industry has to a tamper-evident label for that question. They attach a signed record to an image, video or audio file that says who made it, with which tool, and what happened to it afterwards.
This article explains what sits inside that record, which metadata fields matter, which C2PA checker gives a fast answer, and how to verify a file by hand when you need proof instead of a badge. It also looks at the unglamorous part: why credentials disappear, what a green check really means, and what to do with the media you generate yourself.
What C2PA Content Credentials Are
C2PA stands for the Coalition for Content Provenance and Authenticity, a group formed in 2021 that merged the Content Authenticity Initiative led by Adobe with Project Origin from Microsoft and the BBC. The coalition publishes an open technical specification for content provenance. Content Credentials is the public-facing name for the feature built on that specification, the one you see as a small "CR" badge in supported apps.
A Signed Receipt for Media
Think of a credential as a receipt stapled to a file. When a camera, an editing app or a generative model creates or changes a file, it writes a manifest: a bundle of statements about the file, signed with a certificate that identifies the software or hardware vendor. If anyone alters the pixels afterwards without re-signing, the numbers stop matching and a checker raises a flag.
That is the "tamper-evident" part. Credentials do not stop edits. They make silent edits visible.
C2PA vs EXIF Metadata
Most people have seen EXIF data: camera model, lens, date, sometimes GPS. It is plain text that any free tool can rewrite in seconds. A C2PA manifest is a different animal because it is cryptographically signed and tied to the file contents.
Feature
EXIF / IPTC metadata
C2PA manifest
Who can change it
Anyone with a free editor
Only a holder of a signing certificate, and changes are detectable
Digital signature
No
Yes
Tied to the pixels
No
Yes, through a hash
Records edit history
No
Yes, as actions and ingredients
Survives a screenshot
No
No
💡 Tip: EXIF can say "shot on a Leica" even if the file came straight from a prompt. A C2PA manifest can make the same claim, but with a signature a checker can validate against the signer's certificate.
Inside a Manifest
Claims, Assertions and Signatures
A manifest has three layers, and each one answers a different question.
Assertions are the statements: the actions taken (created, cropped, color adjusted), the software that did it, a thumbnail, and a digital source type that says whether the content came from a camera capture or from a trained algorithmic model.
The claim lists those assertions together with their hashes, so none can be swapped out unnoticed.
The claim signature is a digital signature made with an X.509 certificate. It proves which signer stands behind the claim.
When a checker opens a file, it recomputes every hash, verifies the signature, and walks the certificate chain back to an issuer it recognizes.
Hard Bindings and Soft Bindings
Two kinds of links hold a manifest to its file.
A hard binding is a hash of the file's bytes, excluding the manifest region itself. Change a single pixel and the hash no longer matches. This is why an edit made in a tool that does not re-sign leaves the file with an invalid result.
A soft binding is looser: an invisible watermark or a perceptual fingerprint that lets a service look up a manifest even after the embedded copy was stripped. Soft bindings are the basis of what Adobe calls durable Content Credentials.
Where the Bytes Live
The manifest is packed into a JUMBF container (the JPEG universal metadata box format). In a JPEG it sits in APP11 segments. In a PNG it lives in a dedicated chunk called caBX. In an MP4 it sits in its own box. Audio formats such as WAV and MP3 can carry manifests too.
A manifest can also be stored remotely, with the file holding only a link to it. That is handy for size, but it means the credential is only as durable as the server hosting it.
Best C2PA Checker Options
You do not need to be a developer to check a file. You do need to pick the right tool for the question you are asking.
Browser Verify Tools
The simplest path is the Content Credentials Verify page run by the Content Authenticity Initiative. Drop a file onto it and it shows a summary: the signer, the tools used, the actions recorded, and whether anything was generated by AI. Several third-party viewers parse the manifest in the browser with WebAssembly, so the file never leaves your computer. Check the privacy note of any viewer before dropping in a sensitive file.
Command Line With c2patool
For batches, audits and automation, the open-source c2patool reads and writes manifests from a terminal.
The first line prints the manifest as JSON. The second adds the detailed, JUMBF-level view with assertion URLs and hashes. The third prints a short validation summary, which is useful in scripts. Recent versions of ExifTool will also list that a JUMBF block exists, though they will not validate the signature for you.
Phones and Editing Apps
Photoshop shows a Content Credentials panel for files that carry a manifest. Google Photos displays credentials on supported phones, and some social platforms, LinkedIn among them, show the small CR badge on posts. These views are convenient but shallow. They rarely show the certificate details, so use them for a first look, not for a ruling.
Checker type
Best for
Watch out for
Browser Verify page
Quick answers, readable edit history
Uploading private files to a third party
In-browser WebAssembly viewer
Local inspection of the raw manifest
Variable trust list handling
c2patool
Batches, scripts, full JSON
Needs a terminal and some patience
Photoshop panel
Checking files already in your workflow
Limited signer detail
Social badge
Casual browsing
Only shows what the platform kept
How to Verify in Five Steps
Follow this order and you will avoid most wrong calls.
Get the original file. A screenshot or a re-saved copy has almost certainly lost its manifest. Ask the sender for the untouched file, or download the original from the publisher.
Run two checkers. Use one browser tool and c2patool. If they disagree, trust the one that shows the raw manifest.
Read the validation state. Valid, well-formed but untrusted, or invalid. The table below explains each.
Inspect the signer. Look at the issuing certificate, the organization name and whether it appears on the C2PA trust list. A random signer you have never heard of is a claim, not a guarantee.
Walk the edit history. Read the actions in order. Look for the source type, any AI generation step, and ingredients that point back to earlier versions.
Result
What it means
Your next move
No manifest found
No credentials were ever added, or they were stripped
Look for the original. Do not call the file fake on this alone
Valid, trusted signer
Signature intact, file unchanged since signing, signer recognized
Read the actions and the source type
Well-formed, untrusted signer
Structure and signature are fine, signer is not on a trust list
Treat it as a statement from an unknown party
Invalid or hash mismatch
The file changed after signing or the manifest is damaged
Do not rely on it. Request the original
💡 Tip: "No manifest" and "invalid manifest" are very different results. The first is silence. The second is a warning.
Why Credentials Disappear
Platforms That Strip Metadata
The biggest weakness of embedded credentials is also the most boring one: files get rewritten. Any step that decodes the image and encodes it again discards the manifest unless the software knows how to carry it across.
Action
Credentials survive?
Downloading the original from its source
Usually yes
Sending the unchanged file as an attachment
Usually yes
Taking a screenshot
No
Saving a copy through a basic editor
Often no
Uploading to a platform that recompresses
Often no
Hosting behind a CDN set to preserve them
Yes, if the setting is on
If you run a website, check your image pipeline. Resizing plugins, format converters and some CDNs strip metadata by default, and some now offer a switch to preserve Content Credentials.
Durable Credentials and Watermarks
Because stripping is so common, the industry layers several methods together.
Method
Survives a screenshot
Tamper-evident
Shows edit history
Embedded C2PA manifest
No
Yes
Yes
Cloud manifest plus soft binding
Often retrievable
Yes
Yes
Invisible watermark such as SynthID
Often
Not by itself
No
Visible label
Until it is cropped
No
No
An invisible watermark can tell a service that an image came from a certain generator. It does not carry a signed history. A manifest carries the history but can be stripped. Pairing them is the idea behind durable credentials, and it is why a serious provenance setup rarely depends on one method alone.
Cameras and Generators That Sign
Cameras and Phones
Hardware signing starts at capture, which is the strongest place to sign because the file never existed unsigned. Leica shipped the first mainstream camera with the feature. Sony added support on the Alpha 1 II and Alpha 9 III. Google's Pixel 10 series signs photos in the Pixel Camera app at Assurance Level 2, and Google Photos can display the result.
The picture is not perfectly tidy. Nikon rolled out credentials for the Z6 III through a firmware update, then revoked its certificates after a flaw let authentic and unauthentic images be combined while keeping a valid signature. That episode shows both sides of the system: signing can fail, and revocation is how the ecosystem responds.
AI Image Generators
Many of the large image generators now attach a manifest to their output, marked with the trainedAlgorithmicMedia source type so a checker can tell the picture was synthesized. Whether a particular file carries one depends on the model provider and on every step between the model and your download folder.
On Picasso IA you can test this yourself with several image models, including Nano Banana Pro, Seedream 4.5, GPT Image 2 and Flux 2 Pro. Generate an image, download the file, run it through a checker, and write down what you see. Do not assume a result, because pipelines differ.
Editing changes the answer. An upscaler rewrites pixels, so a manifest from before the upscale will no longer validate unless the tool signs again. If you finish a picture with Topaz Image Upscale, check the final file, not the source.
Video and Music
Video raises the stakes because clips travel through more transcoders than photos. A manifest on an MP4 can vanish the moment a platform re-encodes it for streaming. The 2.3 release of the specification added support for live streams, which matters for broadcasters who need to sign footage as it is produced.
If you work with generated clips, you can test the same loop with Veo 3.1, Sora 2, Kling v3 Video or Seedance 2.0. Download the MP4 before it is compressed anywhere else and inspect that copy.
Audio is the quietest corner of provenance. Music tools such as Lyria 3, ElevenLabs Music, Stable Audio 2.5 and MiniMax Music 2.6 produce tracks that can in principle carry a manifest, but support in players and checkers lags behind images. Expect fewer tools to display the result.
What a Valid Signature Can't Prove
Trust Is Not Truth
A green result proves two things: the file has not changed since it was signed, and a named signer stands behind the claim. It does not prove that the scene was real, that the caption is honest, or that the photographer did not stage the moment. A staged photo taken with a signing camera is still a staged photo.
Likewise, a missing manifest is not evidence of fakery. Most genuine photos in circulation carry no credentials at all, because the camera never signed them or a platform stripped them on the way. Use credentials as one signal next to reverse image search, source checking and common sense.
⚠️ Heads up: Never accept a badge screenshot as proof. A screenshot of a verification page is just another image. Open the file itself in a checker.
Rules Pushing Adoption
Regulation is nudging the market. The EU AI Act includes transparency duties under Article 50 that call for synthetic content to be marked in a machine-readable way, and C2PA is one of the most frequently cited mechanisms for doing it. Newsrooms, stock libraries and ad platforms are adding provenance checks to their intake processes for the same reason: they want a paper trail when a picture is challenged.
For creators, the practical takeaway is simple. Keep your original exports, keep any manifest intact when you publish, and note which tools touched a file.
Make and Check Your Own Media
Reading about provenance only goes so far. The fastest way to get comfortable with it is to run the whole loop on files you create.
Drop each file into a browser checker and c2patool, and record whether a manifest is present, valid and trusted.
Change one thing, such as resizing or re-saving, and check again to watch the result flip from valid to missing or invalid.
That last step teaches more than any article. Seeing a signature break after a harmless-looking export shows exactly why provenance depends on the whole pipeline and not on one file.
Ready to try it? Open Picasso IA, pick a model from the full model list, and create your own images, videos and music. Then run your downloads through a C2PA checker and see what your files really say about where they came from.