Back to All Guides
Provenance

What Is C2PA? Content Credentials and Provenance Explained

An in-depth look at the Coalition for Content Provenance and Authenticity (C2PA) standard, cryptographic manifests, and what they reveal.

MetaClean Security & Privacy Team
•
March 20, 2026
•
7 min read
## Introduction to C2PA In an era of ubiquitous synthetic media and digital content generation, verifying the origin and history of an image has become a central challenge. The Coalition for Content Provenance and Authenticity (C2PA) is an open technical standard founded by Adobe, Microsoft, Intel, Arm, the BBC, and Truepic to establish a standardized architecture for content provenance. --- ## How C2PA Works C2PA operates on the principle of **tamper-evident cryptographic manifests**: 1. **Manifest Creation:** When an image is captured on a C2PA-enabled camera or generated via an AI tool supporting Content Credentials, a manifest is generated. 2. **Assertions:** The manifest contains claims regarding: - Creator identity or signing certificate. - Actions taken (e.g., capture, crop, color balance, or generative AI synthesis). - Ingredients (source images used in composition). 3. **Cryptographic Binding:** A cryptographic hash of the image pixel data is signed with a private key belonging to the issuer. 4. **Embedding:** The signed manifest is packaged in a JUMBF (JPEG Universal Metadata Box Format) container and inserted into JPEG APP11 markers or PNG/WebP chunk structures. --- ## What C2PA Does — And What It Does Not Do ### What C2PA DOES: - Provides verifiable proof that a specific organization or hardware device signed a statement regarding how the image was produced. - Alerts viewers if the image has been modified in a way that breaks the cryptographic signature. ### What C2PA DOES NOT: - **C2PA presence does NOT automatically mean an image is AI-generated.** C2PA is equally used by photojournalists to verify real-world camera authenticity. - **C2PA absence does NOT mean an image is human-made.** Anyone can save an image without a C2PA signature. --- ## Inspecting C2PA with MetaClean MetaClean inspects file headers for JUMBF containers, APP11 markers, and C2PA chunk identifiers entirely in your browser sandbox, allowing you to see if content credentials are present without transferring your image to third-party servers.

Inspect Your Own Images

Check what metadata, GPS tags, or C2PA provenance credentials are embedded inside your photos directly in your browser.