AI Watermark Check

C2PA explained: what content credentials prove

C2PA is the third mechanism in the provenance conversation, alongside statistical watermarking and hidden characters. It is the strongest of the three when it is present, and it is absent more often than not.

The mechanism

The Coalition for Content Provenance and Authenticity defines a format for attaching a signed manifest to a piece of content. The manifest records assertions, what created this, when, with which tool, and what has been done to it since, and it is signed with a certificate, so tampering is detectable and the signer is identifiable.

Editing content that already carries a manifest can add a new manifest referencing the previous one. The result is a chain: generated by a model, cropped in one editor, colour-adjusted in another. Each step is signed by whoever performed it.

Two properties follow. First, a valid credential is strong evidence, because breaking it means breaking a signature. Second, it is metadata, and metadata is fragile in ways the content itself is not.

Why absence proves nothing

This is the part that most discussion skips, and it is the part that decides how you should use C2PA in practice. A manifest is lost by:

That last one is the reason C2PA does very little for text in practice. Text moves by being copied, and copying is precisely the operation that discards the container.

The asymmetry to remember. A valid credential tells you something reliable. A missing credential tells you nothing at all: it is equally consistent with content that never had one, and content that lost it to an ordinary screenshot. Systems that treat missing credentials as suspicious will be wrong most of the time.

How it compares

C2PAStatistical watermarkHidden characters
Where it livesFile metadataThe content itselfThe text itself
Survives copying the content outNoYesSometimes
Survives re-encodingUsually notOftenNot applicable
Who can verifyAnyone, with a validatorOnly the key holderAnyone
Tells you what happened after generationYes, through the chainNoNo
Used for textOnly while the text stays in the fileYesNo, by any serious provider

The two real mechanisms are complementary rather than competing. C2PA answers "what is the history of this file", verifiable by anyone, as long as the file is intact. A watermark answers "did this model generate this content", verifiable only by the key holder, but surviving the journey. Google applies both to its output for exactly that reason, and the Gemini page covers how the two layers sit together.

Who applies it to what

Using it sensibly

Check credentials when they are present, and treat them as what they are: a signed statement by an identifiable party about how a file was made. Do not build a workflow that treats their absence as a signal, because the absence is produced by screenshots and uploads far more often than by anything interesting.

And do not confuse any of this with the invisible characters in your text. Those are typographic debris from a copy-paste journey, they carry no provenance information, and they are the one thing on this page that the checker on this site can find and fix.