Guide
What is C2PA? Content Credentials, explained
C2PA is an open standard for attaching a signed, tamper-evident record of how a photo, video or sound file was made. Here is how it works, who uses it and what it can and can’t tell you.
The short version
A Content Credential is like a nutrition label for a media file. It lists who made the file, with what device or software, and what was done to it afterwards — and it is cryptographically signed, so any change to the file or the label afterwards is detectable. When a generative AI tool creates an image, the credential says so in a standard, machine-readable way.
How it works
The manifest
Each time a C2PA-aware tool creates or edits a file, it writes a manifest. A manifest contains assertions — statements such as “this file was created”, “these edits were made”, “this is a thumbnail of the result”, “this is a hash of the image data” — and a claim that lists the assertions and names the software. The claim is then signed with the tool maker’s certificate.
Binding to the content
One assertion is a hash of the file’s actual content. If anyone changes a single pixel without writing a new manifest, the hash no longer matches and a validator reports the file as tampered.
The chain of edits
When a credentialed file is edited, the new manifest includes the old one as an ingredient. The result is a history: captured on a camera, cropped in an editor, a background extended with generative fill, exported for the web.
Saying “AI” in a standard way
Actions carry an IPTC digital source type. The value trainedAlgorithmicMedia means the content was created by a generative model; compositeWithTrainedAlgorithmicMedia means real content combined with generated parts; digitalCapture means a camera captured it. This is what lets a detector say “made with AI” with certainty instead of guessing.
Why most files don’t have one
Credentials are metadata, and the internet is very good at destroying metadata. Screenshots never carry it. Most social networks, messaging apps and image hosts re-encode uploads and drop it. Older editing software discards what it doesn’t understand. On top of that, most cameras and phones in use today don’t create credentials at all. So in practice, credentials are excellent evidence when present and silent when absent — which is why GPTTrace pairs them with metadata and content analysis. To inspect a file’s manifest, use the C2PA viewer.