Skip to content

Provenance

Checking Content Credentials before you share an image

By Hannah Voss, Editor · Reviewed September 2026 · 3 min read

A cut-paper link preview card with a grey landscape panel, two blank text bars and a small embossed seal in one corner

Quick answer

Open the image in a tool that reads C2PA manifests and look at three things: who signed the credential, what actions it records (captured, generated, edited) and whether the signature validates. A valid credential is evidence about the file's history; a missing one proves nothing, because most uploads strip it. Record what you found before you publish.

On this page
  1. What a Content Credential is
  2. Check an image in five steps
  3. Reading the result honestly
  4. When to go further
  5. Sources
  6. Questions

What a Content Credential is

A Content Credential is a signed record, defined by the C2PA specification, attached to an image or video file. It lists assertions about the file, such as the device or software that created it and the edits applied, and it is signed with a certificate so that tampering can be detected. The guide to Content Credentials on shared images explains why they so often disappear during sharing.

Check an image in five steps

  1. Start from the original file

    Ask the photographer or source for the file they exported, not a screenshot or a copy saved from a feed. Re-saved copies rarely keep the manifest.

  2. Open it in a C2PA reader

    Use a verification tool or editing software that reads C2PA manifests. It will show whether a manifest exists and whether its signature is valid.

  3. Read the signer and the actions

    Note who signed the credential and which actions are listed: captured by a camera, created by a generative model, cropped, colour corrected, composited.

  4. Look for a digital source type

    Many manifests carry an IPTC digital source type value that says whether the content came from a camera, an algorithm, or a composite of both.

  5. Record the result

    Keep a note with the file name, the date checked, the signer and the key actions. If you publish, say in the caption what you know and do not overstate it.

Reading the result honestly

What you findWhat it supportsWhat it does not prove
Valid credential, camera capture, few editsThe file came from that device with those editsThat the scene was not staged
Valid credential, generative action listedThe signer's tool generated or altered itWho asked for it or why
Credential present but signature invalidThe file changed after signingThat the change was malicious
No credentialNothing either wayThat the image is fake or real

The last row is the one people misread. Most images online have no credential at all, because the camera or app did not add one or because a platform removed it on upload, as where image metadata gets stripped shows. Absence is the normal state, not a warning sign.

When to go further

For an image that will carry weight in a story, provenance data is one input among several. Ask the source directly, look for other photographs of the same event, and try a reverse image search to find earlier copies. The guide to spotting AI images in your feed lists the checks that hold up and the ones that do not. In the provenance section, the publishing side of the same question is covered for your own images.

Sources

Questions

How do I check if an image has Content Credentials?

Open the original file in a tool that reads C2PA manifests. It shows whether a manifest is present, who signed it and whether the signature validates.

Does a missing Content Credential mean an image is fake?

No. Most images have none, and most social uploads strip them. Absence tells you nothing on its own.

Can Content Credentials show an image was AI-generated?

Yes, when the generating tool added a manifest recording a generative action and it survived. They cannot show anything about files that never had one.

Can Content Credentials be faked?

The signature makes tampering detectable. A manifest can still be removed, and a credential only says what its signer asserted.

Share this guide

Hannah Voss, Editor. Checks every guide against a working WordPress install and the networks' current documentation. Last reviewed September 2026.

  1. Content Credentials on shared images: what survives a shareWhat C2PA Content Credentials are, why WordPress image sizes and social uploads often strip them, and how to keep provenance on the images you share.4 min read
  2. Where image metadata gets stripped: WordPress, CDNs and uploadsWhere IPTC, EXIF and Content Credentials metadata is lost between your camera and a reader's feed: WordPress resizing, optimisers, CDNs and social uploads.3 min read
  3. Spotting AI images in your feed: checks that hold upWhich checks for AI-generated images in a social feed actually hold up: platform labels, provenance data, earlier copies and the source, and which tells fail.3 min read
  4. Invisible watermarks on AI images: what they can proveHow invisible watermarks on AI-generated images work, how they differ from Content Credentials, what a detected watermark proves and what it cannot.3 min read