ChronoVerify

What are Content Credentials (C2PA), and how do you check them?

A field guide from ChronoVerify, written by a veteran intelligence analyst.

Content Credentials are a cryptographically signed C2PA record attached to an image that states who made it, with what tool, and how it was edited. They are the open standard behind content authenticity verification. Unlike plain EXIF, any change to that record breaks the signature, so it is tamper-evident rather than merely asserted. You can check them for free at verify.contentauthenticity.org, or on ChronoVerify alongside the rest of a photo's metadata.

What is a C2PA manifest, and what does it record?

A C2PA manifest is a tamper-evident container of assertions bound into a signed claim. Assertions are statements about the asset: the capture device or generating software, the time, the edits applied, and whether AI tools were involved at any stage. Those assertions are bundled into a claim, and the claim is cryptographically signed by the producing hardware or software.

Two things make the record trustworthy rather than just a label. First, a claim signature ties the manifest to a known signer. Second, cryptographic hashes of both the asset bytes and the provenance data are baked in, so any later modification is detectable. Think of it as a nutrition label that cannot be quietly rewritten without leaving a mark. The current published standard is C2PA 2.3 (dated January 5, 2026), with later work tracked at spec.c2pa.org.

How do Content Credentials differ from EXIF?

The difference is signing. EXIF is plain metadata that any free tool can edit or strip, so it is a claim, not a guarantee. A Content Credential adds a cryptographic signature: change a single field in the recorded history and the signature no longer validates, so tampering shows up. That is the gap between "the file says this" and "this can be checked." If you want the EXIF side in depth, see our guide to reading EXIF metadata.

PropertyEXIF metadataContent Credentials (C2PA)
What it isA block of tag fields (camera, date, GPS) written into the fileA signed manifest of assertions about origin and edits
Tamper resistanceNone: editable and removable with free toolsTamper-evident: edits break the cryptographic signature
Who can write itAnyone with a metadata editorThe signing camera, app, or AI tool with a certificate
Records AI generationNot reliablyYes, AI-generated content can be labeled in the manifest
Survives re-savingOften, but trivially alteredOnly if tools preserve it; soft bindings can aid recovery
What it provesA claim about the fileA validated provenance chain, not the truth of the scene

What is the difference between Content Credentials, the CAI, and C2PA?

They are related but distinct. C2PA, the Coalition for Content Provenance and Authenticity, is the body that publishes the open technical standard. The Content Authenticity Initiative (CAI), founded by Adobe in 2019, is the cross-industry community that promotes adoption. Content Credentials is the consumer-facing brand for a C2PA manifest. In short: C2PA is the standard, CAI is the community, and Content Credentials is what you see on a signed image.

How does a Content Credential resist tampering?

It resists tampering through binding. C2PA defines two kinds. A hard binding is a cryptographic hash that ties the manifest to the exact bytes of the asset, so a single changed pixel invalidates it. A soft binding is an invisible watermark or content fingerprint that can help rediscover the associated credential after the metadata has been stripped. Hard bindings prove integrity; soft bindings help recovery. Neither makes a credential unstrippable, and that limit is important to keep in mind.

Which cameras, phones, and AI tools sign images in 2026?

Adoption moved from niche to mainstream across three categories. Treat these as illustrative examples, not a frozen list, since firmware and policies change:

How to check an image's Content Credentials

Verification confirms whether a credential is present and valid; it does not judge the truth of the scene. Follow these steps:

  1. Open the Verify tool. Go to the free Content Credentials Verify tool at verify.contentauthenticity.org (also reachable via contentcredentials.org/verify).
  2. Add the image. Drag in the file or paste its URL. The tool parses any embedded C2PA manifest in your browser.
  3. Read the signer and recorded edits. Check the validated signer, the camera or tool used, the signing date and time, and the list of recorded edits or AI generation.
  4. Cross-check on ChronoVerify. Check the same photo on ChronoVerify, which reads Content Credentials alongside EXIF, capture time, and pixel signals, then returns a plain triage verdict.
  5. Treat absence as neutral. If no credential is present, read it as "no signed history available," not as proof of fakery, and corroborate with other signals.

An "unrecognized signer" result usually means a test certificate or a tool not yet in the trust list, not proof of fakery. ChronoVerify's free C2PA inspector reads and cryptographically validates a manifest against the official trust lists. Developers and platforms verifying C2PA at scale can do this through the ChronoVerify API, with flat per-image pricing and no operation multipliers.

What can Content Credentials not tell you?

Three limits keep the picture honest. Provenance is not truth: a credential attests to a signed chain of who did what, not whether the scene depicted is real, so C2PA does not detect deepfakes. Absence is normal: most authentic media still carries no C2PA data, so a missing credential says nothing about authenticity. Credentials are fragile: re-saving, screenshots, and many platforms strip the metadata, and while soft bindings help recovery they are not guaranteed. For where these signals fit in a full check, see how ChronoVerify's pipeline works and its limits, and our guide to whether a photo is AI-generated.

Want to see whether an image carries valid Content Credentials?

Check a photo now

Common questions

What is a C2PA manifest, and what does it actually record?

A C2PA manifest is a tamper-evident container of assertions: statements about the asset such as the capture device, the edits applied, and whether AI tools were involved. Those assertions are bundled into a claim that is cryptographically signed by the producing camera or software.

What is the difference between Content Credentials, the CAI, and C2PA?

C2PA, the Coalition for Content Provenance and Authenticity, publishes the open technical standard. The Content Authenticity Initiative, founded by Adobe in 2019, is the cross-industry community that promotes adoption. Content Credentials is the consumer-facing name for a C2PA manifest.

How do I check the Content Credentials on an image?

Upload or link the file at verify.contentauthenticity.org, the free Content Credentials Verify tool. It parses the manifest, validates the signatures, and shows the signer, the tools used, and recorded edits. You can also check it on ChronoVerify, which reads Content Credentials alongside EXIF and capture-time signals.

Do AI image generators add Content Credentials?

Many do. OpenAI adds C2PA metadata to images from DALL-E 3, ChatGPT, and its API. Adobe Firefly, Photoshop, and Creative Cloud attach Content Credentials to generative output, and Microsoft Designer signs generated images. The metadata identifies the content as AI-generated.

Does a missing Content Credential mean a photo is fake?

No. The absence of a Content Credential only means no signer attached provenance metadata. Most cameras, phones, and editing tools still do not embed C2PA, and credentials can be removed by re-saving, screenshotting, or by platforms that strip metadata. Absence is normal, not evidence of fakery.

Does C2PA detect deepfakes or prove a photo is real?

No. C2PA asserts positive provenance: who signed what, and when. It does not judge whether the depicted scene is true and does not classify content as real or fake. A valid credential confirms a recorded provenance chain, not the reality of the image.

Is ChronoVerify C2PA conformant?

Yes. ChronoVerify is a C2PA Conformant Validator on the C2PA Conforming Products List, record 019f8a20-6452-7a43-b11b-59d0b0e4a84a, covering validation of JPEG, PNG, WebP and AVIF under C2PA specification 2.2. The list is public, so you can check the record yourself. It covers validation rather than generation: ChronoVerify reads and validates Content Credentials, it does not sign them.

Sources and further reading: C2PA Specifications index; C2PA FAQ; Content Credentials Verify; Google Security Blog on Pixel and Android C2PA; OpenAI on content provenance; Adobe Content Credentials overview; LinkedIn on its C2PA rollout; Meta Transparency Center on labeling AI content.