Content Credentials logo
Content Authenticity Detection · Media Journalism

Content Credentials

Content Credentials is an open, royalty-free standard that attaches tamper-evident, cryptographically signed provenance to images, video, audio and documents. It is stewarded by the C2PA, a Joint Development Foundation project backed by more than 500 companies.

Active Free plan Free No public API Verified by Guidaio
Overview

What is Content Credentials?

Content Credentials is an open technical specification for the provenance of digital content, described on the site as a nutrition label for digital media. It is produced by the Coalition for Content Provenance and Authenticity (C2PA), a project of the Joint Development Foundation, a Washington-based 501c6 non-profit. The coalition was founded on 22 February 2021 by Adobe, Arm, BBC, Intel, Microsoft and Truepic, merging the efforts of the Content Authenticity Initiative and Project Origin. Its steering committee now brings together Adobe, Amazon, BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic, alongside more than 500 companies spread across three membership tiers.

Technically, a Content Credential — also called a C2PA Manifest — holds cryptographic hashes of the asset together with its provenance data. Any alteration breaks that link, which is what makes the record tamper-evident. The foundations are ordinary and well tested: SHA-256 hashes, X.509 certificates and digital signatures. Signing certificates are issued by certificate authorities listed on the C2PA Trust List, and each certificate carries an assurance level. Existing metadata standards — IPTC, XMP and EXIF — can be wrapped as tamper-evident assertions, so the format sits alongside what photographers and newsrooms already use.

Three mechanisms work together. Embedded provenance attaches the signed data to the content. Invisible watermarking and digital fingerprinting act as soft bindings, letting a credential be found again once metadata has been stripped. Photos, video, audio files and documents are all covered, and signing works offline: a camera can sign with locally stored keys, no connection required. The size overhead is modest, on the order of a kilobyte per asset.

The official Content Credentials icon, unveiled on 10 October 2023 after two years of research and design and presented as an icon of transparency, marks a file that carries provenance information and opens an interactive panel showing it.

The specification is released under a royalty-free licence: no licence fee, and no obligation to join the organisation in order to implement it. The 1.x series is treated as legacy, while the 2.x series — 2.1, then 2.3 — is the recommended one.

What it does

  • Attach a signed record of origin to an image, a video, an audio file or a document
  • Add a fresh signature at every edit, recording the editing method, the place, the date and the time
  • Open the Content Credentials icon to read a file's provenance log
  • Check whether a file is authentic through the online Verify tool
  • Signal that a piece of content was generated or retouched by an AI model
  • Recover a lost provenance record through invisible watermarking or digital fingerprinting
  • Submit a generator product for assessment under the C2PA conformance programme
Audience

When to use Content Credentials / When not to

A quick filter to help you decide if Content Credentials is the right fit.

When to use Content Credentials

  • Photographers and journalists who need to prove where their images and footage came from
  • Newsrooms and publishers that have to document the full editing history of a media file
  • Software vendors and device manufacturers that want to sign the content their products create
  • Platforms that want to show their users where a piece of content originated
  • Generative AI teams that must disclose when content has been created or retouched by a model

When not to use Content Credentials

  • Anyone shopping for digital rights management: Content Credentials never restricts access to or use of a file
  • Teams hoping for a deepfake detector: the standard reads a signed, declared provenance instead of analysing the content itself
  • Users who need to tie a file to a named author: the core specification deliberately avoids attributing content to individuals or organisations
  • Anyone expecting missing credentials to prove a forgery: a great deal of authentic content carries none at all
  • Investigators who need a fully verified chain: without access to the ingredient data, only a prior validation can be confirmed
Get started

How to use Content Credentials

A typical end-to-end flow, from setup to results.

  1. Spot the Content Credentials icon on a piece of media and open it to read the history, from origin through to the version in front of you
  2. Drop the file on the online Verify tool, linked from the site menu, to check its credentials for yourself
  3. Consult the glossary on the site if the vocabulary of provenance is new to you
  4. As a creator or software vendor, connect provenance information to the content your tool produces
  5. Sign again at every update, so that the editing method, the place, the date and the time are added to the credential
  6. As an implementer, read the specification, choosing the recommended 2.x series over the legacy 1.x one
  7. Test your implementation against the public test files published by the C2PA on GitHub
  8. Express interest in the conformance programme through the form linked from the conformance page
  9. Pass the conformance assessment, obtain a Claim Signing Certificate from a Trust List certificate authority, and get listed on the Conforming Products List
  10. Browse the live trust and product lists in the C2PA Conformance Explorer, and join the open source community on the Content Authenticity Initiative Discord
Quick read

Pros & Cons

Pros

  • Open, royalty-free standard: implementable with no membership and no licence fee
  • Adopted by the largest platforms and vendors, from Adobe, Google and Microsoft to OpenAI, Meta, Amazon, TikTok, Sony and the BBC
  • Proven cryptographic foundations — SHA-256, X.509, digital signatures — that make any alteration detectable
  • Durable by design: watermarking and fingerprinting can restore provenance after metadata has been stripped
  • Interoperable with existing IPTC, XMP and EXIF metadata, and usable offline, including inside a camera
  • Public governance: certificate policy, security requirements and conformance lists are all published on GitHub
  • Privacy-preserving and lightweight: no mandatory attribution to a person, and roughly a kilobyte added per asset

Cons

  • Metadata can be stripped, deliberately or not; soft bindings soften the loss without guaranteeing recovery
  • Missing credentials prove nothing, so coverage depends entirely on adoption by tools and platforms
  • Certificate fees are set by each certificate authority and are not published by the C2PA
  • Conformance assessment and legal onboarding are heavy prerequisites for reaching the Conforming Products List
  • 1.x implementations are declared legacy, and the Interim Trust List was frozen on 1 January 2026, leaving existing certificates to expire
  • The core specification does not attribute content to an identified author; attribution relies on community extensions
  • Nothing on the organisation's side about the GDPR, no data processing agreement, no sub-processor list, and no hosted API or SDK in the c2pa-org GitHub organisation
Pricing

Pricing & Plans

Content Credentials is free of charge. The specification is released as an open standard under a royalty-free licence, so no licence fee applies, and there is no paid plan, no subscription and no trial to speak of; C2PA members have undertaken to make their contributions freely available on those terms, and membership is not required in order to implement the standard. Two optional costs sit outside the specification itself. An organisation seeking formal recognition must obtain a Claim Signing Certificate from a certificate authority on the C2PA Trust List, and those fees are set by each authority under its own commercial terms rather than published by the C2PA. Joining the coalition is likewise possible, through an application form and a membership agreement, but no membership fee is disclosed on the site.

No commercial plan
  • the specification is free for everyone
  • and the tiers below govern participation in the coalition
  • not access to the standard
General Members
  • around thirty-eight organisations
  • among them Ad-ID
  • Arm
  • Bloomberg
  • Canon
  • Deloitte
  • DigiCert
  • ElevenLabs
Contributor Members
  • several hundred organisations
Plan 5
  • No price is attached to any of these tiers on the site
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Content Credentials handles your data.

GDPR overview

There is no mention of the GDPR anywhere. A search across the 34 pages collected — contentcredentials.org, c2pa.org and the Joint Development Foundation policy that governs both — returns zero occurrences of GDPR or General Data Protection Regulation. No Article 27 EU representative is named, no data protection officer is appointed, no data processing agreement is offered, no sub-processor list is published and no data hosting country or region is declared. The governing law is stated as that of the State of Washington, United States, and the legal entity is registered in Wilmington, Delaware. The privacy policy does set out seven general data protection principles, but attaches them to no European instrument. European readers should weigh that against the nature of the tool: the standard involves no account and collects nothing, so the gap concerns the organisation's website, not the technology.

Who owns the data?

There is no user account and no hosted service on contentcredentials.org: the site is informational. Content Credentials are attached to the file itself rather than stored with a third party, so a signed asset and its provenance record stay with whoever holds the file, and the site makes no claim over user content. Personal data collected through the site falls under the Joint Development Foundation's generic policy, shared by all its projects, which states that it will “collect and use of personal information solely with the objective of fulfilling those purposes specified by us and for other compatible purposes, unless we obtain the consent of the individual concerned or as required by law.”

Reuse rights

The specification itself is published as an open standard under a royalty-free licence, so anyone may read it, implement it and build on it without asking permission and without paying a fee; C2PA members have undertaken to make their contributions freely available on those terms. For personal data, the Joint Development Foundation policy sets out general principles rather than reuse rights: purposes are identified “before or at the time of collecting personal information”, data is gathered by lawful and fair means with the knowledge or consent of the individual where appropriate, kept relevant, accurate, complete and up to date, and protected by reasonable security safeguards against loss, theft, unauthorised access, disclosure, copying, use or modification. No advertising use, no resale and no training of models on customer data is mentioned anywhere.

Data retention & training

Retention summary
The applicable policy is the Joint Development Foundation's, and it says only that personal information is kept “as long as necessary for the fulfillment of those purposes” for which it was collected. No duration is quantified, no purge schedule is published, and no deletion or portability procedure is described. The policy shows neither an effective date nor a last-updated date, only a 2025 copyright line. One distinction matters here: Content Credentials themselves are meant to stay attached to the content indefinitely — that permanence is the whole point of the standard — while the retention question above concerns nothing more than the personal data the organisation's websites may collect. There is no user account and no hosted service on contentcredentials.org.

Hosting summary

No hosting country or region is declared for user data anywhere on the site — and here that is mostly because there is no user data to host. Content Credentials are embedded in the file itself, so the model needs no central database: a signed asset carries its own provenance wherever it travels. Cloud retrieval is mentioned as a complementary mechanism for finding a credential again, without naming any host. What can be established concerns the website rather than the technology. A network probe places contentcredentials.org behind Fastly (AS54113) at 23.185.0.4, an anycast node resolving to San Francisco, United States. The legal entity, Joint Development Foundation Projects, LLC, is registered in Wilmington, Delaware, United States, and the terms name the law of the State of Washington as governing. For a European organisation that means an American jurisdiction, with no declared EU hosting, no data processing agreement and no sub-processor list — a gap on the organisation's side, not in the standard.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Content Credentials.

  • Treating the presence of a credential as proof that the content is true: it records origin and edits, never truthfulness
  • Reading missing credentials as evidence of a fake — most authentic media still carries none, and the reflex breeds unwarranted suspicion
  • Using it as proof of identity: the core specification does not attribute content to a named author, and community extensions are not the same thing
  • Assuming the chain is complete: without the ingredient data, only a prior validation can be confirmed, not the whole history
  • Relying on metadata that a single upload can strip; soft binding recovery is a mitigation, not a guarantee
  • Overlooking the 2026 transition: the Interim Trust List was frozen on 1 January 2026, 1.x implementations are legacy, and certificate costs are set, unpublished, by each authority
  • Expecting privacy paperwork that does not exist: the applicable policy is the generic Joint Development Foundation one, with no GDPR mention, no DPA, no sub-processor list, and the site publishes no email address of its own
Setup

Setup & Integrations

Technical difficulty

Difficulty depends entirely on your role. To consult a credential, nothing is required: the icon and the online Verify tool are enough, with no account to create. To implement the standard, expect real engineering — reading the 2.x specification, handling X.509 certificates, signing cryptographically. To be recognised as conforming, add a technical and security assessment, legal onboarding and a certificate from a Trust List authority, with hardware-backed attestation sometimes required at enrolment. Public test files, the Certificate Policy, the Generator Product Security Requirements, the Conformance Explorer and a community Discord support that work.

Deployment

Web app

Integrations

Adobe Microsoft Google OpenAI Meta Amazon BBC Sony TikTok Truepic Intel Arm Publicis Groupe IPTC XMP EXIF
Company

Behind Content Credentials

Company name
Joint Development Foundation Projects, LLC
Founded
22/02/2021
Country of origin
🇺🇸 United States
Headquarters
2810 N Church St PMB 57274, Wilmington, Delaware 19802-4447 US
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇩 Germany

Fundraising

No fundraising: the structure is non-profit — the Coalition for Content Provenance and Authenticity Series of Joint Development Foundation Projects, LLC — and is funded by its members' dues
The Joint Development Foundation is a 501c6 non-profit attached to the Linux Foundation family of projects
Neither membership dues nor any budget figure is published on the site

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Is Content Credentials free to use?
Yes. It is released as an open standard under a royalty-free licence, so no licence fee applies, for open source and proprietary products alike.
Do I have to join the C2PA to implement the specification?
No. Membership is required neither to read the specification nor to implement it. It only becomes relevant if you want a Claim Signing Certificate and a place on the Conforming Products List.
Is this a form of DRM?
No. Content Credentials restrict neither access to nor use of a file. The point is transparency and integrity, not control.
What happens if the C2PA metadata is removed from a file?
Soft bindings — invisible watermarking and digital fingerprinting — can be used to find the associated Content Credential again, although recovery is not guaranteed.
Can a Content Credential be forged?
It would mean breaking SHA-256 and X.509 signatures. Any alteration invalidates the hash and becomes detectable.
Does it work offline?
Yes. A device can sign with locally stored keys, its certificates having been provisioned in advance. It also adds only a few kilobytes to a file.
Does a Content Credential identify the author of a file?
No. The core specification makes no attribution to individuals or organisations, a deliberate choice so that it remains maximally privacy-preserving.
How much does a signing certificate cost?
The C2PA does not publish that. Fees are set by each certificate authority on the Trust List, under its own commercial terms, after a conformance and security assessment.
Are 1.x implementations still accepted?
Yes, but they are treated as legacy and migration to the 2.x series is strongly encouraged. The Interim Trust List was frozen on 1 January 2026, with no further additions or updates.
Who governs the standard?
The C2PA, a project of the Joint Development Foundation, a Washington-based 501c6 non-profit. Its specification also encapsulates IPTC, XMP and EXIF metadata as tamper-evident assertions.
Conclusion

Should you pick Content Credentials?

Content Credentials has become the de facto reference for media provenance. Its adoption by Adobe, Google, Microsoft, OpenAI, Meta, Amazon, TikTok, Sony and the BBC, alongside more than 500 companies, gives it a reach nothing else matches, and because it is free and open there is no barrier to implementation: no licence fee, no obligation to join the coalition.

What it delivers is narrow and well defined. A signed, tamper-evident record travels with the file, saying where the content came from and how it was edited — including whether an AI was involved. It does not tell you whether an image is true, and it does not name an author: the core specification avoids attribution on purpose, to stay privacy-preserving.

Its value therefore rests on two things outside the standard. The first is adoption: a credential is only useful if the tools and platforms along the chain write it and display it. The second is metadata survival — stripping is trivial, and the soft bindings that recover a credential from a watermark or a fingerprint help without promising anything. In practice, the absence of Content Credentials tells you nothing at all.

Governance is public and documented, with the certificate policy, the security requirements and the conformance lists all published, but the ecosystem is mid-transition. The 1.x series is legacy, the Interim Trust List was frozen on 1 January 2026, and any organisation wanting formal recognition faces a conformance assessment, legal onboarding and certificate fees set by individual authorities and never published.

The honest summary is that this is not a product. It is a standard and a compliance ecosystem, free to read and free to implement, valuable to anyone who needs to show where their content came from, and worth nothing if no one along the chain looks.