A provenance standard, not a truth test

C2PA is an open standard for recording a file's provenance in a signed manifest of claims and assertions. Content Credentials can describe camera capture, AI generation or editing, so they are not only an AI label. Finding a manifest is an observation; trusting it requires validating the cryptographic signature and checking the signer against an appropriate trust list.

How to check Content Credentials

Use a validator that checks signatures and explains its trust decisions, such as the Content Authenticity Initiative's Verify tool, which shows the signer, the recorded actions and any edit history it can read. Google has also added C2PA verification to Gemini, and platforms such as TikTok and YouTube read C2PA data when applying AI labels. Upload only files you are entitled to share.

What absence does not mean

A file without credentials may still be a photograph or an AI output. Screenshots and re-exports can preserve the appearance while discarding the manifest, and many devices and tools do not write credentials at all. Pixels cannot reconstruct a missing history. Likewise, a camera-related assertion does not prove that the pictured event happened as described; origin, editing history and factual context remain separate questions.

Use an original and compare records

Ask for the source export rather than a resized preview when the owner can provide it. Note how it reached you and preserve the creator's explanation in your own notes. If an important credential is present, review it with a tool that validates signatures and explains its trust policy. That is a follow-up step, not a guarantee that the result will settle ownership, permissions or the truth of the scene.

Limits and privacy

Image Evidence does not certify C2PA signatures today, and an unverified credential should stay unverified in any report you write. We do not train on user content and provide no face recognition, person search, watermark removal or legal authenticity opinions. Do not use a provenance check or detector score as the only basis for a consequential decision about a student, applicant, creator or other person.

How do I check if an image has Content Credentials?

Open the original file in a C2PA validator such as the Content Authenticity Initiative's Verify tool. It shows whether a manifest is present, who signed it and which actions were recorded. Some apps and platforms also display a Content Credentials icon. If nothing is found, check whether you have the original rather than a screenshot or a re-saved copy.

Does C2PA prove an image is real?

No. When validation succeeds, C2PA shows that a signer made certain claims about a file and that the file has not changed since it was signed. A camera-signed photo can still be staged or captioned misleadingly, and the trust you place in a manifest depends on who signed it.

Which AI tools add C2PA Content Credentials?

OpenAI says images from ChatGPT, its API and Codex carry Content Credentials, and TikTok attaches them to some AI-generated content made on its platform. Many other generators, apps and cameras now write C2PA data, but coverage changes often, so check each provider's current documentation rather than relying on a fixed list.