Content Credentials: what they are, and what removing them costs
Guide · 14 August 2026
Where you will meet them
Content Credentials are the public name for C2PA, a specification published by the Coalition for Content Provenance and Authenticity and standardised as ISO/IEC 22144. You will find these credentials attached to images from generative tools, from Microsoft 365, from Adobe applications, and from cameras made by Sony, Nikon and Leica. Since the specification became a standard, the number of files carrying one has grown quickly, and most people who have them do not know they are there.
They are invisible in normal use. Your image viewer will not show them, your operating system will not list them, and sending the file to someone else carries them along unchanged.
What is inside one
A manifest is made of three things that work together:
- Assertions — the claims themselves. Typically: which device or application produced the file, when, what edits were applied, and whether generative AI was involved. Optionally the author's name and a copyright notice.
- A binding to the content — a cryptographic hash of the actual pixels. This is what stops someone lifting a credential from one file and pasting it onto another. Change the image, and the binding no longer matches.
- A signature — issued by a certificate that identifies who vouches for the assertions.
Three questions, three separate answers
Most tools collapse this into a single green tick, which is where the confusion starts. There are three independent questions, and they can have different answers:
- Is a manifest present? Yes or no. Absence tells you nothing at all.
- Is it intact? Does the signature verify, and does the binding still match the file? A manifest can be perfectly genuine and yet broken, simply because the file was resized somewhere along the way.
- Is the signer recognised? Whether the certificate appears in the trust list being used. An unrecognised signer does not mean a forgery; it often means a small vendor, or a trust list that has not caught up.
QuietMeta reports these three separately, and names the trust list and date it used, because a single verdict would be hiding the interesting part.
What a Content Credential does not prove
It does not prove a photograph is honest. A camera with impeccable credentials can photograph a staged scene, and the credential will faithfully record that a real camera took a real picture. Provenance describes the production chain, not the truth of what was produced.
The reverse matters just as much: a file with no credential tells you nothing. Most files in the world have none. Every social platform that re-encodes uploads destroys them by accident. Treating absence as a signal is the single most common mistake made with this technology, and it is why QuietMeta will never present an absence of provenance as evidence of anything.
The trade-off nobody mentions
There are good reasons to strip a credential. It can record which software you use, when you worked, and sometimes your name — details you may not want attached to a file you are about to publish.
This is why QuietMeta keeps provenance by default. Removing it is a separate switch, and when the manifest carries an author or a copyright notice, the warning gets louder before anything happens. The tool does not decide for you, but it refuses to let you find out afterwards.
What the law says, briefly
Article 50 of the European AI Act has applied since 2 August 2026 and requires providers of generative systems to mark synthetic output in a machine-readable way. It places that obligation on the provider. It does not make it unlawful to remove a marking from a file you hold, and it does not prohibit tools that do so. Other rules — copyright, contracts, platform terms — may still apply to what you do with a given file. This is a description of a regulation, not legal advice.
Seeing yours
QuietMeta reads Content Credentials in JPEG, PNG, WebP, GIF, TIFF, AVIF, HEIC, SVG and PDF. Drop a file on the home page and you will see whether a manifest is there, whether it is intact, whether its signer is recognised, and what it says — alongside the ordinary metadata: location, camera, software, author, timestamps.
Nothing is stored. The file is held in memory for the length of one request and released. If you would rather it never left your machine at all, the desktop application does the same work with the network switched off.
Inspect a file Get the desktop app