Content Credentials, Explained in Plain English

September 30, 2026 · 6 min read

You may have started seeing a small "CR" badge on images online. It stands for Content Credentials, and it is the closest thing the internet has to a nutrition label for photos. Here is what it is and where its limits are.

The idea in one paragraph

Content Credentials are a tamper-evident record attached to a photo, video, or audio file. The record says who created the file or what tool made it, what edits happened along the way, and whether AI was involved. It is signed with cryptography, so if anyone changes the file or the record afterward, the signature breaks and you can see that something is off.

Who built this

Content Credentials is the consumer name for an open standard called C2PA. The standard was started in 2021 by Adobe, Microsoft, the BBC, Intel, Arm, and Truepic, companies and broadcasters that were worried about misinformation. It is now an open project. In early 2026 the coalition said more than 6,000 members and affiliates had live applications using the standard.

No single company owns it, which is what makes the standard worth trusting. Adobe pushes it hardest, Google and OpenAI have signed on, and camera makers are starting to add it. Because it is open, any app or website can read these credentials without asking anyone's permission.

What the record actually contains

A Content Credential is a small signed file, called a manifest, embedded in the media file itself. Depending on what the creating tool chose to record, it can include:

How much gets recorded is up to the tool. A camera might log only the capture. Photoshop logs every edit. An AI image generator is supposed to log that AI was involved.

Why the signature matters

Anyone can write "made by a human" in a file's metadata. That is why the signature is the whole point.

Content Credentials are signed with digital certificates, the same kind your browser uses to verify a banking site. The signature covers both the media and the record. Change a single pixel after signing, or edit the record itself, and verification fails. A reader will show you that the credential is broken rather than silently accepting it.

This does not mean the content of the record is true. A tool could in principle write a false record and sign it. What the signature proves is narrower: this exact record was written by whoever holds that certificate, and nothing changed afterward.

Where you will run into it

In Adobe's apps, a Content Credentials badge appears on files that carry the record. Google said in May 2026 that C2PA verification is coming to Search and Chrome, so you will start seeing provenance info where you already look at images. Camera makers including Leica and Sony have added capture-time signing to some models, which means the record can start at the shutter click, not just in editing software.

On the AI side, images from ChatGPT, Firefly, and Google's Imagen now carry these credentials. The EU's AI labeling rules, in force since August 2026, require AI-generated content to carry machine-readable marks, which is pushing more tools to adopt the standard.

What it cannot do

Three limits are worth knowing before you rely on it.

First, the record is fragile. It lives in the file's metadata, and everyday handling strips metadata constantly. Social platforms, messaging apps, and screenshots all create new files without the original record. A missing credential tells you nothing about whether the image is real.

Second, adoption is uneven. Most AI image generators still attach nothing at all. A credential only helps when the tool that made the file participated.

Third, it records claims, not truth. The system verifies that the logbook is intact. It does not verify that the logbook's story happened the way it says.

How to read one yourself

You do not need an account or special software. Upload the original file to any Content Credentials reader and the manifest opens up: tool, edits, timestamps. Our checker on the homepage does this in your browser, so the file never leaves your device, and it also reads the file's EXIF metadata for extra clues.

If the file has no credential, the honest answer is "cannot tell."

Want to check an image yourself? Upload it and read its provenance signals in seconds.

Try the free checker