C2PA explained: what content credentials prove
C2PA is the third mechanism in the provenance conversation, alongside statistical watermarking and hidden characters. It is the strongest of the three when it is present, and it is absent more often than not.
The mechanism
The Coalition for Content Provenance and Authenticity defines a format for attaching a signed manifest to a piece of content. The manifest records assertions, what created this, when, with which tool, and what has been done to it since, and it is signed with a certificate, so tampering is detectable and the signer is identifiable.
Editing content that already carries a manifest can add a new manifest referencing the previous one. The result is a chain: generated by a model, cropped in one editor, colour-adjusted in another. Each step is signed by whoever performed it.
Two properties follow. First, a valid credential is strong evidence, because breaking it means breaking a signature. Second, it is metadata, and metadata is fragile in ways the content itself is not.
Why absence proves nothing
This is the part that most discussion skips, and it is the part that decides how you should use C2PA in practice. A manifest is lost by:
- Screenshotting. A screenshot is a new image with no history. Nothing survives.
- Re-encoding. Many pipelines rewrite an image and keep only the pixels.
- Platform upload. Plenty of platforms strip metadata on upload, for privacy and for size.
- Copying text out of a file. The manifest belongs to the container. Select the words, paste them elsewhere, and the provenance is gone.
That last one is the reason C2PA does very little for text in practice. Text moves by being copied, and copying is precisely the operation that discards the container.
The asymmetry to remember. A valid credential tells you something reliable. A missing credential tells you nothing at all: it is equally consistent with content that never had one, and content that lost it to an ordinary screenshot. Systems that treat missing credentials as suspicious will be wrong most of the time.
How it compares
| C2PA | Statistical watermark | Hidden characters | |
|---|---|---|---|
| Where it lives | File metadata | The content itself | The text itself |
| Survives copying the content out | No | Yes | Sometimes |
| Survives re-encoding | Usually not | Often | Not applicable |
| Who can verify | Anyone, with a validator | Only the key holder | Anyone |
| Tells you what happened after generation | Yes, through the chain | No | No |
| Used for text | Only while the text stays in the file | Yes | No, by any serious provider |
The two real mechanisms are complementary rather than competing. C2PA answers "what is the history of this file", verifiable by anyone, as long as the file is intact. A watermark answers "did this model generate this content", verifiable only by the key holder, but surviving the journey. Google applies both to its output for exactly that reason, and the Gemini page covers how the two layers sit together.
Who applies it to what
- Anthropic attaches C2PA provenance metadata to files Claude generates. Text pasted out of those files does not carry it. See the Claude page.
- OpenAI applies C2PA to generated images, with no deployed text watermark at the time of writing. See the ChatGPT page.
- Microsoft ships its Content Credentials implementation on images from Copilot and Designer. See the Copilot page.
- Google combines C2PA with SynthID, using metadata where it survives and watermarking where it does not.
Using it sensibly
Check credentials when they are present, and treat them as what they are: a signed statement by an identifiable party about how a file was made. Do not build a workflow that treats their absence as a signal, because the absence is produced by screenshots and uploads far more often than by anything interesting.
And do not confuse any of this with the invisible characters in your text. Those are typographic debris from a copy-paste journey, they carry no provenance information, and they are the one thing on this page that the checker on this site can find and fix.