C2PA stands for the Coalition for Content Provenance and Authenticity. It was formed in 2021 by companies including Adobe, Arm, the BBC, Intel, Microsoft and Truepic, and has since been joined by Google, OpenAI, Sony, Leica and many others.
"Content Credentials" is the name you will see in apps and on websites. It comes from the Content Authenticity Initiative, the Adobe-led effort that promotes the standard. The two terms describe the same thing from different sides: C2PA is the specification, Content Credentials is what it looks like to a person.
A C2PA manifest is embedded in the file itself. It contains a set of statements, called assertions, and a signature over all of them.
| Part | What it records |
|---|---|
| Hash binding | A hash of the file's content, so any later change to the pixels is detectable |
| Actions | What was done: created, opened, cropped, colour adjusted, generated by AI |
| Ingredients | Earlier files the image was made from |
| Claim generator | The camera, app or AI model that wrote the manifest |
| Signature | An X.509 certificate identifying who signed, and a timestamp |
Two things, and only two. Who signed the manifest, as far as their certificate can be trusted. And that the file has not changed since signing.
The identity part depends on the certificate. Anyone can create a certificate claiming to be anyone, so a signature is only meaningful if the certificate chains to a trusted authority. C2PA maintains a trust list for this. A manifest signed by an unlisted, self-issued certificate is mathematically valid and tells you nothing about who made it.
A camera-signed photo of a staged scene is still a staged scene. C2PA records the history of a file, not the truth of what is in it.
And the absence of credentials proves nothing. Most cameras and phones do not add them yet, and most social networks and messaging apps strip metadata on upload. A photo with no Content Credentials is the normal case, not a warning sign.
Because manifests live in metadata, re-saving or screenshotting a file usually removes them. The standard anticipates this with "soft bindings" - invisible watermarks such as TrustMark embedded in the pixels, which can point back to a copy of the credentials stored elsewhere.
Reads and cryptographically verifies C2PA Content Credentials against the official trust list, on iPhone, iPad and Mac. · iPhone, iPad & Mac
You’re browsing inside Instagram, and its built-in browser isn’t allowed to hand links over to the App Store. Open this page in Safari and the link will work.
Tap the three-dot menu at the top right, then choose Open in external browser.