What Is C2PA? Content Credentials Explained

If you want the C2PA meaning in one sentence: C2PA stands for the Coalition for Content Provenance and Authenticity, an open technical standard that lets a photo, video, or audio file carry a signed record of where it came from and what happened to it. When you hear “Content Credentials” in the context of AI images, that is the C2PA manifest — the same thing, under its consumer-facing name.

This guide explains what C2PA is, who adds it, what it actually contains, and how to read it. No jargon required.

The problem C2PA solves

Before C2PA, there was no standard way for a file to say “this is who made me.” An image was just pixels plus whatever metadata a camera or app happened to write. That made it hard to answer a simple question: is this photo real, or was it generated by an AI model?

C2PA gives media a standard, cryptographically signed way to carry its own history. The idea is that a trusted tool — a camera, an editing application, or an AI generator — records the facts of how a file was made, signs them so they cannot be silently changed, and attaches the record to the file. Anyone with the right viewer can then read that history.

The coalition behind it is broad: OpenAI, Google, Microsoft, and Adobe are members, alongside major camera manufacturers, and it operates as a project under the Linux Foundation. That breadth is the point — provenance only works if everyone writes the same format.

What a C2PA manifest contains

A manifest is not one field; it is a small structured record. The fields you will most often see, and that a decoder surfaces, include:

  • Producer — who or what created the content. For an AI image, this might be “OpenAI” or “Google.” For a photo, the camera maker.
  • Actions — the operations performed, such as that the content was created, or edited with a given tool.
  • Timestamp — when the content or an edit happened.
  • InstanceID — a unique identifier for that specific piece of content, so it can be tracked across platforms.

These fields are recorded in a compact binary format called CBOR, packed inside a container attached to the file. In a JPEG, that container sits in an APP1 segment; PNG and WebP use their own equivalent chunks. The whole thing is then signed, so if someone tampers with the record, the signature no longer matches.

The key detail for understanding removal: the manifest lives in a block separate from the pixels. The image data and its provenance are side by side, not fused.

Who adds C2PA — and where you will see it

Adoption is uneven, but the direction in 2026 is clear.

  • OpenAI attaches C2PA metadata to images generated with ChatGPT and DALL·E, alongside a SynthID watermark (source: help.openai.com, accessed August 2026).
  • Google signs content with C2PA across several products while also embedding its SynthID watermark.
  • Adobe adds Content Credentials to images created or edited in tools like Photoshop and Firefly.
  • Midjourney has adopted C2PA, so images generated on the platform can carry a signed manifest.
  • Camera manufacturers sign photos at capture, so provenance can start the moment an image exists.

On the user side, you will encounter it as a small “Content Credentials” or “C2PA” indicator in some apps, or not at all — because the manifest is invisible until a tool reads the file.

There is a well-documented catch: platforms often remove it for you. Social networks that re-encode uploads routinely strip metadata blocks, which is why a C2PA manifest frequently does not survive a trip through a feed. Our article C2PA Content Credentials: Why Platforms Strip Metadata explains that behavior in detail.

How to read a C2PA manifest

You do not need to be a developer to read one. A decoder reads the CBOR structure and turns it into plain fields.

When you drop a file into the detector, OutWatermark AI decodes the C2PA manifest and shows you the producer, actions, timestamp, and instanceID directly — alongside a preview stamp (⚠️ AI WATERMARK DETECTED or ✅ NO WATERMARK DETECTED) and a map of exactly where the block sits in the file’s bytes. That is the difference between trusting a badge you see on a website and reading the record inside the file itself.

Why C2PA matters

Three reasons, in ascending order of importance to most people.

First, traceability. A signed record of origin makes it harder to pass off synthetic media as real without a trail. It is the infrastructure behind the “AI-generated” labels you increasingly see.

Second, regulation. The EU AI Act’s Article 50 (Regulation (EU) 2024/1689) requires transparency for AI-generated content, and applies from August 2, 2026. C2PA and similar markings are part of how providers meet that obligation.

Third, control. Because the manifest is removable, and because platforms strip it anyway, understanding it matters for anyone who manages their own media. You should know what your files carry before they go somewhere you cannot control.

Can you remove C2PA?

Yes — it is one of the few provenance signals that is straightforward to remove, precisely because it is separate from the pixels. OutWatermark AI removes the C2PA manifest and related metadata surgically, without re-compressing the image, so there is no quality loss. The same applies to the metadata in video files, within the tool’s supported formats.

The legal note is the same one that applies to every provenance signal: removing it from content you own is about controlling your own data, but it does not remove any disclosure obligation under the EU AI Act, and removing provenance from content you do not own can violate copyright law. The compliance overview covers both.

FAQ

Is C2PA visible? Not in the image itself. The manifest is invisible metadata stored inside the file. Some apps show a “Content Credentials” indicator, but the record is machine-readable, not something you see in the pixels.

Who uses C2PA? Adobe, OpenAI, Google, Midjourney, and camera manufacturers are among the adopters. AI image generators and editing tools increasingly sign their output, and the coalition operates under the Linux Foundation.

Can I remove C2PA from my own image? Yes. Because the manifest is stored separately from the pixels, a tool like OutWatermark AI can remove it surgically without re-compressing or degrading the image.

Is removing C2PA legal? For content you own, removing provenance is about controlling your own data. But it does not remove labelling obligations under the EU AI Act, and removing provenance from content you do not own can violate copyright law. See the compliance overview for sources.


Check what your file contains with the free detector →

For more on removing C2PA specifically, read our page on the C2PA remover.