AI images
Content Credentials (C2PA) explained: how to verify where an image came from
Content Credentials are a signed record, defined by the C2PA standard, that says which app, AI model or camera made an image and how it was edited. You can check them for free with the uncrop.si AI image checker or the Content Authenticity Initiative's Verify site. When they are present and trusted they say a lot, but screenshots and many apps remove them, so a missing record proves nothing.
Content Credentials are a signed history attached to an image. They record which app, AI model or camera made it, what was done to it afterwards, and who vouches for that record. They are built on an open standard from the C2PA, and most of the big AI image tools now add them. This guide explains what is inside them, what “trusted” and “valid” mean, who adds them, and how to check an image yourself.
What Content Credentials are
The Coalition for Content Provenance and Authenticity (C2PA) was announced in February 2021 by Adobe, Arm, BBC, Intel, Microsoft and Truepic to fight misleading content with an open provenance standard (C2PA). Its steering committee now includes Adobe, Amazon, BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic (C2PA). The C2PA writes the standard; the Content Authenticity Initiative, which Adobe founded in 2019, builds the open-source tools and calls the result Content Credentials (Content Authenticity Initiative).
The record lives inside the image file, signed with a certificate the way a secure website is. If anyone changes the image or the record afterwards, the signature no longer matches.
What a Content Credential records
Here is what we found in a ChatGPT image made in October 2026, read with the uncrop.si AI image checker:
| Field | What it said |
|---|---|
| Signed by | OpenAI OpCo, LLC, with a certificate from a C2PA certificate authority |
| Written by | OpenAI Media Service API |
| How it was made | Created with ChatGPT (gpt-image), digital source type “trained algorithmic media”, which means generative AI |
| Later steps | Converted, and an invisible watermark added to the pixels |
| When | The signing time, from OpenAI’s time-stamping service |
It did not contain the prompt. Other records can list more: a camera model, each edit made in an app such as Photoshop, and the earlier files (“ingredients”) an image was built from.
Trusted, valid and invalid
The C2PA specification grades a record in steps, and every trusted record is also valid (C2PA Technical Specification):
- Valid: the record is intact, the file has not changed since signing, and the signature checks out with a certificate that was valid and not revoked at the time.
- Trusted: valid, and the signer’s certificate also leads back to a trust list. Checkers must include the official C2PA Trust List.
- Invalid: something does not match, usually because the image was changed after it was signed.
The C2PA’s July 2026 deployment guidance puts it simply: valid means intact, while trusted means intact and signed by someone on the C2PA Trust List (C2PA). The official list comes from the C2PA conformance program, which launched in 2025. An older interim list was frozen on 1 January 2026, and content signed under it while its certificate was valid still counts (C2PA). The uncrop.si checker uses both lists.
Who adds Content Credentials
| Source | What gets Content Credentials |
|---|---|
| OpenAI | Images from ChatGPT and the OpenAI API, since early 2024 (OpenAI) |
| Images from Nano Banana Pro in the Gemini app, Vertex AI and Google Ads, since November 2025 (Google) | |
| Adobe Firefly | Files where every pixel comes from Firefly, such as Text to Image (Adobe) |
| Microsoft | Images generated or edited with AI in Designer and Copilot (Microsoft), and every Bing Image Creator image (Bing) |
| Google Pixel 10 | Every photo from the Pixel Camera app, and AI-edited images in Google Photos (Google) |
Some professional cameras can sign photos as well. Check your camera maker’s documentation for your model.
Where you will see them
- LinkedIn shows a C2PA icon on images and videos that carry Content Credentials. Clicking it shows the app or device, the issuer, the signing date and any AI use the signer declared. LinkedIn notes it cannot yet label all AI content (LinkedIn Help).
- YouTube shows “Captured with a camera” under “How this content was made” when a video comes from a capture tool with built-in Content Credentials and was not edited in a way that breaks them (YouTube Help).
- Gemini reads Content Credentials when you ask whether an image was made with Google AI.
- TikTok says it has labelled more than 3 billion items as AI-generated, using Content Credentials alongside invisible watermarks and its own labelling tools (C2PA).
How to check Content Credentials
- Use the original file. A screenshot, or a copy downloaded from most social apps, usually has no credentials left.
- Drop it into the uncrop.si AI image checker. It reads the record on your device, verifies the signature against the C2PA trust lists and tells you whether it is trusted, valid or invalid, along with what it says about AI.
- For a second opinion, upload it to the Content Authenticity Initiative’s free Verify site, which shows the full history, including earlier versions of the image when they are recorded.
Why credentials disappear
The C2PA’s own guidance warns that screenshots, and exporting through tools that strip metadata, remove embedded Content Credentials, and that a “no Content Credentials found” result can simply mean they were lost along the way (C2PA). That is why companies such as OpenAI and Google pair them with an invisible watermark, which is built to survive those steps. See what SynthID is and how to check it.
Content Credentials, AI labels and SynthID
| Question | Content Credentials | IPTC AI label | SynthID |
|---|---|---|---|
| Where it lives | A signed record in the file | A plain metadata field in the file | An invisible pattern in the pixels |
| Can it be checked by anyone? | Yes, with free tools | Yes | No, only by Google and OpenAI |
| Proves who made it? | Yes, when trusted | No, anyone can write it | That a participating company’s AI made it |
| Survives a screenshot? | No | No | Built to survive many edits |
No single mark covers every case, so check all three. The full routine, including what to do when the file says nothing, is in how to tell if an image is AI-generated.
Check an image for AI labels and watermarks
The free uncrop.si checker reads Content Credentials, AI labels and generator settings on your device, and runs OpenAI's SynthID check with your own key.
Questions
What does C2PA stand for?
The Coalition for Content Provenance and Authenticity. Adobe, Arm, BBC, Intel, Microsoft and Truepic founded it in February 2021 to write an open standard for recording where digital content comes from.
What is the difference between valid and trusted Content Credentials?
Valid means the record is intact, the file has not changed since it was signed, and the signature checks out. Trusted also means the signer's certificate leads back to a trust list, such as the official C2PA Trust List.
Do ChatGPT images have Content Credentials?
Yes. OpenAI has added Content Credentials to its generated images since early 2024. ChatGPT images we checked in October 2026 were signed by OpenAI OpCo, LLC and recorded that they were created with ChatGPT.
Why does LinkedIn show a label on some images?
LinkedIn shows a C2PA icon on images and videos that carry Content Credentials. Clicking it shows details such as the app or device used, the issuer and the signing date, including any AI use the signer declared.
Do phones add Content Credentials?
Some do. Google says the Pixel 10 adds them to every photo taken with the Pixel Camera app, and Google Photos adds them to images edited with AI.
Can Content Credentials be faked?
A record signed by a trusted company cannot be forged without that company's signing key, and any change to the image breaks the signature. Two weaker cases need care: a valid record from a signer that is not on any trust list, and an image whose real credentials were simply removed.
Sources
Steps were checked against official help pages on 8 October 2026. Menus change, so tell us if something moved.
- C2PA founding press release (C2PA)
- C2PA membership and Steering Committee
- How it works (Content Authenticity Initiative)
- C2PA Technical Specification 2.4
- Content Credentials Deployment Guidance, July 2026 (C2PA)
- Conformance program and trust list (C2PA)
- Trust lists (Content Authenticity Initiative documentation)
- Content Credentials Verify (Content Authenticity Initiative)
- Understanding the source of what we see and hear online (OpenAI)
- AI image verification in the Gemini app (Google)
- Content Credentials overview (Adobe Firefly Help)
- Frequently asked questions about Microsoft Designer (Microsoft Support)
- Bing Image Creator help (Microsoft)
- Pixel 10 and Content Credentials (Google)
- LinkedIn rolls out the C2PA standard (LinkedIn)
- Content Credentials on LinkedIn (LinkedIn Help)
- How this content was made: Captured with a camera (YouTube Help)
- C2PA welcomes TikTok to its Steering Committee (C2PA)
Free tools for this
Related guides
AI images
What is SynthID, and how do you check for it?
SynthID is the invisible watermark in images from Google AI and, since May 2026, ChatGPT. What it is, how to check for it for free, and what a result means.
AI images
How to tell if an image is AI-generated
A five-step routine that works: read the file's labels, check for SynthID, look for visual clues, then check the source. Free tools, and what each can prove.
Decision guide
Can you uncrop a photo?
Sometimes. A crop can be undone if the app kept the original, the file hides the cut-off part, or a copy survives. How to check, and what to do if not.