Explainer · 4 min read

What is C2PA (Content Credentials)?

The provenance standard behind "verified" photos, in plain English.

You've seen the little "CR" pin on images in Adobe apps and, increasingly, in news photos. That's Content Credentials — the consumer face of an open standard called C2PA. Here's what it actually is and how to use it.

The one-sentence version

C2PA is an open standard that attaches a tamper-evident record of where a photo came from and how it was edited — a "Content Credential" — that anyone can read and verify. It doesn't decide whether content is true or good; it makes the content's history checkable, so trust is based on traceable origin rather than on how convincing an image looks.

Who's behind it

C2PA stands for the Coalition for Content Provenance and Authenticity, a standards body whose steering members include Adobe, Microsoft, Sony, Nikon, Intel, and the BBC. Its sister effort, the Content Authenticity Initiative (CAI), drives adoption — the "Content Credentials" branding, the Verify tool, and a membership community of thousands of organisations. Trustamp is a member of the CAI, building capture-side proof on the same open standard.

What a Content Credential actually contains

A credential is a small, cryptographically signed manifest travelling with (or alongside) the image. Depending on the tool that created it, it can record:

Because it's signed, you can tell whether the record itself has been altered — that's what makes it evidence rather than just a caption.

C2PA vs a watermark vs EXIF

Three things people confuse — only one is real proof.

Decoration

Visible watermark

A time/GPS overlay burned into the pixels. Readable at a glance, but anyone can fake one in an editor. Good for context, worthless as proof on its own.

Editable

EXIF metadata

The hidden date/location tags in an image file. Free-text fields any tool can rewrite, and most platforms strip them on upload. Not tamper-evident.

Verifiable

Content Credential (C2PA)

A signed, tamper-evident provenance record. Alter the image or the record and verification fails. This is the one an independent party can actually check.

Where Trustamp fits

Most C2PA tools today live in editing software — they credential a file after it's made. Trustamp works at the other end, at the moment of capture. It witnesses a server-verified timestamp and your real GPS — giving a public verify link anyone can open for the when and where — and, when you turn on C2PA, seals the image itself in an open Content Credential right on your phone. It's built on the open C2PA standard with Trust List certification in progress, so C2PA tools like Adobe Verify and Chrome read the credential today and will show the issuer as trusted once certification completes.

Frequently asked

What does C2PA stand for?

C2PA is the Coalition for Content Provenance and Authenticity — and, by extension, the open technical standard that coalition publishes. The standard defines how to attach a tamper-evident record of origin and edit history to a piece of media. When you see the consumer-facing name "Content Credentials," that is C2PA in practice.

Is C2PA the same as Content Credentials?

Effectively yes. "C2PA" is the underlying standard; "Content Credentials" is the user-friendly brand for the little provenance record it produces, promoted by Adobe and the Content Authenticity Initiative. A photo "with Content Credentials" is a photo carrying a C2PA manifest.

How do I check a photo for Content Credentials?

Open it in a C2PA-aware tool: Adobe's Verify tool (verify.contentauthenticity.org), the Content Credentials indicator in Chrome, or Photoshop. If a credential is present, you'll see the source and any recorded edits. If the file has been stripped of its manifest — which many social platforms do on upload — there's nothing to read, which is why a server-backed verify link is a useful backup.

Is Trustamp C2PA certified?

Trustamp is built on the open C2PA standard and is a member of the Content Authenticity Initiative, but we do not claim to be "C2PA certified." Our Trust List certification is in progress (T1 → T3). Today you can verify any Trustamp photo through its public verify link; as certification completes, the same credential also validates natively in Adobe and Chrome.

Keep reading

How to prove a photo is real in the AI era →
Trustamp vs Timemark: proof vs a timestamp overlay →

Get a verifiable credential on every shot

Free to download, no account required.