What is C2PA? Content Credentials explained
4 min read
C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard developed by Adobe, Microsoft, Google, Sony, the BBC and others. Information written into a file under this standard is called Content Credentials — a kind of "birth certificate plus edit history" that travels with an image, video, audio file or PDF.
The problem it solves
With AI generation and editing so easy, you can no longer tell from the pixels alone whether an image was captured, edited or generated. C2PA does not try to guess; instead creators and tools declare and sign who created or changed the file, when, and with what.
How it works
- Manifest: records how the asset was made, edit actions, which source assets (ingredients) were used, and whether AI was involved.
- Digital signature: a camera, app or platform signs the manifest with a certificate; any change breaks the signature or data hash.
- Trust lists: validators use the official C2PA trust list to decide whether the signing certificate comes from a recognized organization.
Who uses it
Adobe Firefly and Photoshop, Microsoft Designer / Bing Image Creator, OpenAI image generation, several Leica / Sony / Nikon cameras, and Google Pixel's camera and editing tools write Content Credentials; platforms such as LinkedIn and TikTok read and display them.
What to keep in mind
Credentials prove who signed the claims and that the file has not changed since — not that the claims themselves are true. Screenshots, re-uploads and compression often strip credentials, so "no credentials" does not mean "fake", only that the origin cannot be confirmed.