Provenance
Checking Content Credentials before you share an image

Quick answer
Open the image in a tool that reads C2PA manifests and look at three things: who signed the credential, what actions it records (captured, generated, edited) and whether the signature validates. A valid credential is evidence about the file's history; a missing one proves nothing, because most uploads strip it. Record what you found before you publish.
On this page
What a Content Credential is
A Content Credential is a signed record, defined by the C2PA specification, attached to an image or video file. It lists assertions about the file, such as the device or software that created it and the edits applied, and it is signed with a certificate so that tampering can be detected. The guide to Content Credentials on shared images explains why they so often disappear during sharing.
Check an image in five steps
Start from the original file
Ask the photographer or source for the file they exported, not a screenshot or a copy saved from a feed. Re-saved copies rarely keep the manifest.
Open it in a C2PA reader
Use a verification tool or editing software that reads C2PA manifests. It will show whether a manifest exists and whether its signature is valid.
Read the signer and the actions
Note who signed the credential and which actions are listed: captured by a camera, created by a generative model, cropped, colour corrected, composited.
Look for a digital source type
Many manifests carry an IPTC digital source type value that says whether the content came from a camera, an algorithm, or a composite of both.
Record the result
Keep a note with the file name, the date checked, the signer and the key actions. If you publish, say in the caption what you know and do not overstate it.
Reading the result honestly
| What you find | What it supports | What it does not prove |
|---|---|---|
| Valid credential, camera capture, few edits | The file came from that device with those edits | That the scene was not staged |
| Valid credential, generative action listed | The signer's tool generated or altered it | Who asked for it or why |
| Credential present but signature invalid | The file changed after signing | That the change was malicious |
| No credential | Nothing either way | That the image is fake or real |
The last row is the one people misread. Most images online have no credential at all, because the camera or app did not add one or because a platform removed it on upload, as where image metadata gets stripped shows. Absence is the normal state, not a warning sign.
When to go further
For an image that will carry weight in a story, provenance data is one input among several. Ask the source directly, look for other photographs of the same event, and try a reverse image search to find earlier copies. The guide to spotting AI images in your feed lists the checks that hold up and the ones that do not. In the provenance section, the publishing side of the same question is covered for your own images.
Sources
- C2PA Content Credentials technical specification 2.1
- C2PA, the Coalition for Content Provenance and Authenticity
- IPTC NewsCodes: digital source type vocabulary
Questions
How do I check if an image has Content Credentials?
Open the original file in a tool that reads C2PA manifests. It shows whether a manifest is present, who signed it and whether the signature validates.
Does a missing Content Credential mean an image is fake?
No. Most images have none, and most social uploads strip them. Absence tells you nothing on its own.
Can Content Credentials show an image was AI-generated?
Yes, when the generating tool added a manifest recording a generative action and it survived. They cannot show anything about files that never had one.
Can Content Credentials be faked?
The signature makes tampering detectable. A manifest can still be removed, and a credential only says what its signer asserted.
Hannah Voss, Editor. Checks every guide against a working WordPress install and the networks' current documentation. Last reviewed September 2026.
Related reading
- Content Credentials on shared images: what survives a shareWhat C2PA Content Credentials are, why WordPress image sizes and social uploads often strip them, and how to keep provenance on the images you share.4 min read
- Where image metadata gets stripped: WordPress, CDNs and uploadsWhere IPTC, EXIF and Content Credentials metadata is lost between your camera and a reader's feed: WordPress resizing, optimisers, CDNs and social uploads.3 min read
- Spotting AI images in your feed: checks that hold upWhich checks for AI-generated images in a social feed actually hold up: platform labels, provenance data, earlier copies and the source, and which tells fail.3 min read
- Invisible watermarks on AI images: what they can proveHow invisible watermarks on AI-generated images work, how they differ from Content Credentials, what a detected watermark proves and what it cannot.3 min read