CONTENT CREDENTIALS · PROVENANCE

C2PA Checker — find Content Credentials

C2PA is the open standard behind Content Credentials: cryptographically signed provenance that records how a media file was created and edited. Upload a file and PictureMatters detects C2PA markers and shows what they reveal — alongside the rest of the forensic report.

What C2PA is, in one minute

The Coalition for Content Provenance and Authenticity (C2PA) defines a way to bind a signed manifest to a file: which device or software created it, what edits were applied, and by whom. Each step can add to the chain, and signatures are designed to be tamper-evident — change the pixels, break the claim. "Content Credentials" is the public-facing name for this provenance record; you may have seen the crisscross pin icon in Photoshop or on some news sites.

Where C2PA data lives depends on the format: a JUMBF box inside JPEG and PNG containers, an XMP extension elsewhere. That is why the checker walks the file's structure first — the same structure map shown in every PictureMatters report.

What this checker detects

  • C2PA markers and Content Credentials signals in the file's metadata payload and structure.
  • Readable credential context — creation/edit claims embedded in the manifest.
  • Related declarations: IPTC digital-source-type and XMP identity fields that often accompany signed media.
  • The flip side: evidence that metadata was stripped or the file was re-encoded (which destroys credential chains).

What C2PA can and cannot establish

  • Can: tamper-evident history if the credential is present, intact, and you trust the signer. Stronger than any ordinary metadata.
  • Cannot: survive aggressive platforms that strip metadata on upload; vouch for pixels when the credential is missing; replace judgment about the signer's trustworthiness.
  • Important: PictureMatters detects and displays — it does not perform full cryptographic signature validation. Treat a detected marker as a lead, and validate critical files with dedicated C2PA verification tools.

Frequently asked questions

Does PictureMatters verify C2PA signatures?

No. It detects C2PA / Content Credentials markers and reports their presence and readable contents. Full cryptographic validation of the signature chain is a specialized task beyond this tool.

Is a C2PA marker proof the image is authentic?

A valid credential is strong evidence about the file's history — but credentials can be absent (stripped), and claims inside are still assertions by the signer. "Authenticity" always depends on how much you trust the signer.

Which files can carry C2PA?

JPEG, PNG, WebP and several video formats support embedded C2PA manifests. Support is growing across cameras, editors and generators.

Why do most images have no Content Credentials?

Adoption is early. Most cameras, apps and platforms do not yet embed or preserve C2PA data — and any metadata-stripping step in the chain removes it.

Use the tool

Want to inspect an image? The PictureMatters analyzer reads metadata, structure, entropy and provenance signals in seconds — free, without an account.

Analyze an Image

Related pages