Claude · The explainer
C2PA content credentials, explained simply
Provenance metadata in plain terms: what it keeps track of, what it can’t track, and who checks it.
C2PA is the open standard for content provenance. It runs as a project of the Joint Development Foundation. Content Credentials is the consumer name for what the standard attaches to files. That is a manifest: a signed record of who or what processed a file and how. Manifests are embedded in common formats, including JPEG, PNG, WebP, and PDF. The credentials are tamper-evident. A changed manifest is detectable. They prove the record is intact, not that a named author is the real one. Claude implements the standard on generated files such as .svg, .png, and .jpg. Anthropic uses the standard. It is not a C2PA coalition member. The first independent audit, submitted in April 2026, found the specifications fail to achieve their claimed security goals. Its conclusion was that C2PA should not yet be relied upon for high-stakes uses.
Why this page exists
Definitional searches like "c2pa content credentials explained" and "what is c2pa" land on c2pa.org and vendor pages. Those pages skip the 2026 audit and the removal reality. An honest explainer covers both the marketing and the audit.
The tells that show up here
Not every AI tell appears everywhere. These are the ones that cluster on this surface, and what it is about the format that produces them.
- not-x-its-y
- The structure this page must use carefully to say what C2PA is and is not.
- vague-attribution
- Unattributed claims about what C2PA promises.
- testament-family
- 'Stands as a testament to trust' is the copula-avoidance habit of explainer slop.
Before and after
A generic AI draft on the left. On the right, the real output of running that draft through underslop, checked so it adds no name or number the draft did not already carry. The voice is The Steady Hand.
In today's ever-evolving digital landscape, C2PA stands as a testament to the power of transparency! These credentials serve as a cornerstone of trust, a beacon guiding us through the complexities of AI-generated content. As research consistently shows, embracing provenance is the key to navigating the challenges that lie ahead!
C2PA gives digital content a clear record of where it came from. These credentials help people verify what they're looking at, which matters more as AI-generated content spreads. Provenance is a practical tool for staying oriented online. Research supports the idea that knowing a file's history helps with what comes next.
How to do it by hand
- Check the file type first Credentials attach only to formats that support metadata. JPEG, PNG, WebP, and PDF can carry them. Plain text cannot.
- Run the file through a verifier Use a verification tool that reads C2PA. It reports whether the credentials are present.
- Read a blank result correctly No credentials found simply means none are present. It is not a tamper warning, and it says nothing about the true author.
- Read the claims, then check them A manifest names who or what processed the file. Compare that record with what you know before trusting it.
Questions
What is C2PA?
C2PA is the open standard for content provenance. It runs as a project of the Joint Development Foundation. Adobe, Arm, BBC, Intel, Microsoft, and Truepic co-founded it.
What are content credentials?
Content Credentials are the standard's signed metadata. They record who or what processed a file, and how. The standard calls them tamper-evident metadata, not DRM.
How do content credentials get into files?
The manifest is embedded in the file itself. Supported formats are JPEG, PNG, WebP, and PDF. Plain text has no container, so credentials can't attach to it.
Can content credentials be removed?
Anthropic lists format conversion, re-saving, and screenshots as ways to strip file metadata. Providers say metadata can be removed easily, either accidentally or on purpose.
Is C2PA proof a file is authentic?
No. Credentials are tamper-evident, so a changed manifest shows up. They prove the record is intact, not who actually wrote it. The first independent audit found the standard isn't ready for high-stakes use yet.
Claude marks are real and the coverage is still settling. underslop is the edit, not a remover: it edits an AI draft so it reads like you wrote it, and it makes no promise about what any detector will report. Your text is held for 0 seconds.