Skip to content

Record

Content Credentials for Readers: What the Label Can and Cannot Tell You

A Content Credentials label is a signed history of a file: who made it, with what, and what changed. Here is how to read one, and where its authority stops.

You may have started to see a small label on some photographs and news images, sometimes a pin-shaped icon in a corner, that opens to show where the picture came from. That label is a Content Credential, and it is the visible end of an open standard called C2PA. This guide is written for readers rather than for the companies that make the tools: what the content credentials label can tell you about an image or an article, how it is protected, how to look at one, what removes it, and why an image without one is not automatically suspect.

A matte photographic print with a small wax seal on its corner under a loupe, beside a caption sheet with one yellow highlighted line

In short

Content Credentials are a signed record attached to an image, video, audio file or document that lists its origin, the tools used, the edits made and whether AI was involved. The C2PA standard defines the record and the signature. A reader can inspect it through a label icon or a verify tool where the file still carries it.

What a Content Credentials label tells you

A Content Credential is the plain name for what the standard calls a C2PA manifest: a set of signed statements, called assertions, about a file. The C2PA explainer lists the kinds of things a manifest can assert: where and when the content was created, what modifications were made and with which tools, and how AI was used in making it. Publishers can add their own assertions, such as who created the content or whether they permit it to be used for AI training.

Read one and you might learn that a photograph was captured on a particular camera model, opened in an editing application, cropped and colour-corrected, and published by a named news organisation on a given date. Or you might learn that an image was generated by an AI tool from a text prompt. What you will not learn is whether the caption is accurate, whether the scene was staged before the shutter opened, or whether the news organisation is one you should trust. The explainer is direct about this: the technology makes no judgement about whether the provenance is true, only whether the record is well formed, untampered, and signed by someone on a known trust list.

How the C2PA standard signs a manifest

The mechanism is worth knowing in outline, because it explains both the strength of the label and its fragility. When a credential-aware camera or application creates or edits a file, it writes a manifest containing the assertions and a cryptographic hash of the content, a short fingerprint that changes if any pixel changes. The manifest is then signed with the private key of the device or software, and the signature can be checked with the matching public key.

The C2PA explainer describes the hashing as a chain: hashes of each part are folded into further hashes and the whole is signed using standard X.509 certificates, the same family of certificates that secures websites. Change the image, the assertions or the signature and the pieces no longer match, so the record is tamper-evident. The manifest is usually embedded inside the file. The standard also allows a soft binding, an invisible watermark or a fingerprint lookup, so that a manifest can sometimes be found again after it has been stripped.

Each edit in a credential-aware tool adds a new manifest that refers to the previous one, so a fully documented file carries its history as a chain. The coalition behind the C2PA standard, whose members include camera makers, software companies such as Adobe and Microsoft, and news organisations, publishes the specification openly and royalty free; anyone can build a tool that writes or reads these records.

How to inspect a content credential

  1. Look for the label on the page. On sites that support the standard, an icon sits on or beside the image, and clicking or hovering opens a panel that summarises the credential. BBC News began publishing images with these labels in March 2024, and its research department has described how the panel looks on its site.
  2. Open the full credential. The panel usually links to a fuller view. Read the signer's name, the date, the list of tools and edits, and any statement about AI. Note which assertions are present and which are absent.
  3. Check the file with a verify tool. If you have the file itself, upload it to a verification page run by the coalition or by a publisher, or use one of the open-source command line tools built on the standard. The tool reports whether the signature is valid, who signed it, and the chain of edits.
  4. Read the file's other metadata. Standard photo metadata defined by the IPTC (creator, copyright notice, credit, caption) lives in the same file and is not signed, but it is often filled in and worth reading alongside the credential. The IPTC's own metadata viewer shows it.
  5. Decide with context. Combine what the credential says with what you know about the signer and with ordinary checks: where the image was first published, whether it appears elsewhere with a different story, and whether the caption matches what is in the frame.
Checking a Content Credential1Find the labelon the image2Open the credentialand read the signer3Verify the fileif you have it4Weigh it againstcontext
The verify step confirms the record is intact. The last step is where the reader's judgement enters.

What the credential can show and cannot show

Both columns come from the C2PA explainer's own goals and non-goals. The right-hand column is the one readers most often forget.
The credential can showThe credential cannot show
That the file has not been changed since the last signed manifest was writtenThat the scene in the file was not staged, or that the caption describes it correctly
Which organisation or device signed it, if the signer is on a trust listWhether that organisation is honest or its reporting is accurate
Which tools were used and what edits were recorded by credential-aware softwareEdits made in tools that do not write credentials; those steps are simply missing
Whether an AI tool was used, if the tool recorded itWhether an image with no credential was made by AI; absence is not evidence
The chain of earlier manifests, where each tool kept itAnything about a screenshot or a re-saved copy that lost the manifest

The point about missing edits matters. The explainer notes that if a file is cropped in a tool that does not understand credentials and then brought back into one that does, the new signer implicitly vouches for the earlier crop. The record is then still trustworthy to the degree the last signer is, but it is not complete, and a careful reader keeps that distinction.

What strips or breaks a credential

A screenshot has no credential, because a screenshot is a new image of your screen, not a copy of the file. Re-saving an image in software that does not understand the standard usually discards the manifest, and re-saving it in software that does understand the standard but after an unrecorded edit produces a mismatch, which a verify tool reports as invalid or broken. Format conversion can do the same.

Social platforms are the largest gap. The IPTC's 2019 tests of photo metadata across about a dozen social sites found that most removed at least some embedded metadata on upload or download, and that rescaling an image was a common point of loss. Credentials are newer than the metadata tested then, and support has been announced by some platforms since, but the safe assumption for a reader is that an image copied through a social feed has lost its history unless the platform says otherwise. This is why soft bindings exist, and why the original publisher's page is the place to look.

What the absence of a credential does and does not mean

Most images on the web today have no credential, and the standard's own FAQ says that no assumption about trustworthiness should be made purely on that basis. Adding provenance is optional; the explainer says the intention is not a two-tier web where unlabelled media is treated as suspect. An unlabelled image from a publisher you already trust is exactly as trustworthy as it was before the standard existed.

What absence does mean is that you have to do the work the other way: find where the image was first published, compare versions, and read what the publisher says about it. Treat a label as a shortcut through some of that work, not as the work itself. And a credential from an unknown signer tells you little more than no credential at all.

The reader's side of provenance

There is a parallel here with the rest of this site. A Content Credential is the publisher's record of how a file came to be. A reader's record is the same idea from the other side: a highlight on the passage you relied on, a dated note saying what you took from it, and a link that opens the page at that line. A text fragment link made with the highlight tool is the reader's signature on a passage: it fixes which words, on which page, at which date, you are vouching for.

The two records meet in practice. When you cite an image, note whether it carried a credential and what it said. When you quote a claim, run it through the source verification workflow for text and log the result. And when your own work used AI in some part, say so plainly, in the same spirit as the AI assertion inside a manifest; stating which parts of a piece had AI help is a credential you write yourself. For the claims inside an article rather than its images, checking an article's statements against the sources it cites is the reader's equivalent of opening the manifest.

Pitfalls when reading Content Credentials

  • Treating the label as a truth mark. It marks integrity and origin. A signed image of a staged scene is still a staged scene.
  • Reading a valid signature as a trusted signer. Validity means the record is intact. Trust comes from knowing who the signer is.
  • Assuming a missing edit did not happen. Tools that do not write credentials leave no trace. The record shows what was recorded, not everything that occurred.
  • Judging an image by its screenshot. The screenshot never had a credential. Find the original file or page.
  • Counting absence against an image. Most of the web is unlabelled. Absence sends you to ordinary checks; it is not a verdict.

A credential describes a file's history; your own record describes your reading of it. The two meet in the section on highlights as evidence: logging a verified source with a highlight link is what you do once the credential has told you where the file came from, and citing the exact line you rely on is how the check ends up in your work.

Common questions

What are Content Credentials?

Content Credentials are a signed record attached to a media file that lists its origin, the tools used, the edits made and any use of AI, following the open C2PA standard. A reader can view the record through a label on supporting sites or by checking the file with a verify tool.

How do I check where an image came from?

Look for a credential label on the image and read the signer, date and edit list. If there is none, find the earliest publication of the image, compare copies, and read the file's standard metadata. Treat a screenshot as having no history and go back to the original page.

Does a Content Credential prove an image is real?

No. It proves the file has not been altered since it was signed and identifies the signer and the recorded edits. It says nothing about what happened in front of the camera or whether the caption is right. Those remain the reader's job.

Can Content Credentials be removed?

Yes. Screenshots, re-saving in unaware software, format conversion and many social platforms strip the manifest. The standard allows soft bindings such as watermarks so a stripped file can sometimes be matched back to its record, but a reader should assume a shared copy has lost it.

Is an image without Content Credentials fake?

No. The standard's own guidance says no assumption should be made about trustworthiness from the absence of a credential, because adding one is optional and most images do not have one. Judge an unlabelled image the way you did before: by its source and its context.

Content credentials give readers something they have never had for images: a signed, checkable history of the file. Read the label for what it is, an account of origin and edits from a named signer, and keep your own record on your side of the screen, a highlight, a date and a link, so that what you took from the image is as checkable as the image itself.