Content Credentials are the C2PA standard's tamper-evident record of where a photo, video or audio file came from and how it was changed, signed by the camera, app or service that did each step. For creators they do two jobs. Platforms including YouTube, TikTok, LinkedIn and Meta read them to show labels or icons such as “AI-generated” or “Captured with a camera”, and they give you a way to show which version of your work is the original. They do not prove that content is true, and they can be lost when a file passes through tools that drop metadata.
This guide covers provenance itself: what is inside a credential, which services read it, how to attach it to your own work and how to check a file. Each platform's full labelling rules live in separate guides to the Instagram AI label, TikTok's AI-generated content label and YouTube's AI disclosure rules.
What a Content Credential actually records
The Coalition for Content Provenance and Authenticity publishes the open standard, and Content Credentials is the name for its output. The C2PA explainer describes a credential, technically a manifest, as a set of statements called assertions that are bundled together and cryptographically signed. Typical assertions say which device or app created the file, what actions were taken on it, which other files were combined into it, whether generative AI was used, and optional extras such as who made it or whether the maker objects to AI training.
Each signer can only vouch for the statements it made itself. A hash ties the credential to the exact file, so editing the image without updating the credential shows up as tampering. Because embedded data can be removed, the standard also allows durable credentials that add an invisible watermark or a fingerprint lookup, so a stripped copy can still be matched back to its record.
The explainer is blunt about the limit: credentials make no judgement about whether the content is true. They show only that the record is well formed, unaltered and signed by a known signer. Identity is optional too. The standard does not require a creator's name, and Google's Pixel Camera help page says its credentials record device, model and edits but not your location or account details.
Which platforms read credentials, and what they show
Support varies by platform and changes often. This table reflects each company's own help or announcement pages when we read them in early October 2026.
| Platform | Reads C2PA? | Label it can show | How to check |
|---|---|---|---|
| YouTube | Yes, credentials at version 2.1 or higher, per its How this content was made page | “Made with AI” when the credential says the whole video was AI-made; “Captured with a camera” for unedited camera footage; an “Info from” line naming the signer | Open the expanded description and look for the How this content was made section |
| TikTok | Yes, according to its AI-generated content help page | An automatic “AI-generated” label for uploads whose credentials show AI, which the creator cannot remove | The label appears on the post; in 2024 TikTok also said it would start attaching credentials to TikTok content so AI posts made there can be verified after download |
| Instagram, Facebook, Threads | Yes, the “AI generated” signals in C2PA and IPTC metadata, per Meta's labelling announcement | AI info: on the post for files generated by AI, and in the post menu for files only edited with AI, per Meta's updated labelling post | Tap the label or the post menu; details are in our Instagram label guide |
| Yes, being rolled out gradually, per its Content credentials help page | A C2PA icon on signed images and videos, visible to everyone who sees the post | Click the icon to see the AI assertion, app or device, creator, issuer and signing date | |
| Google Photos | Yes, versions 2.1 and 2.2, but not credentials stored remotely, per its help page | A “How this was made” summary such as captured with a camera, edited with AI tools or edited with non-AI tools | The About panel in the Android or iOS app; the web version does not show credentials |
Two platform notes are worth knowing before you rely on a label. YouTube's Captured with a camera page says the disclosure needs footage with no edits to sound or visuals, that saving a capture through a photo album without C2PA 2.1 support can break the chain, and that a missing label does not mean a video was altered. TikTok's announcement of its C2PA partnership warned that automatic labelling would grow gradually, because it only works on files that still carry the metadata.
How to attach credentials to your own work
There are three points where a credential can be created: at capture, during editing and after the fact.
- At capture. Google's Pixel announcement says Pixel Camera on the Pixel 10 line attaches credentials to every JPEG photo capture. The Pixel help page adds the catch: only some photo modes are supported, video is not, credentials cannot be added later if they were missed at capture, and the phone needs an up-to-date Android version and an internet connection within the last two weeks. Some dedicated cameras and capture apps also sign files; check the maker's documentation before a shoot rather than assuming.
- During editing. Google Photos adds to the record when you edit a file that already has credentials, and creates one when you save an AI edit to a file without them. Other editors vary, and a round trip through an app that ignores the standard can leave the file without a valid record.
- After the fact. Adobe's Content Authenticity app, in public beta since April 2025, lets you apply credentials to batches of up to 50 JPG or PNG files whether or not they were made in Adobe software, attach a name verified through LinkedIn plus links to your social accounts, and set a preference against generative AI training. Adobe describes these credentials as durable, so they can be recovered from a screenshot.
An after-the-fact credential proves less than one made at capture. It shows that you signed the file on a certain date, which helps with attribution, but it cannot show the image came straight off a camera.
How to check a file before you post it
The quickest check is the free Content Credentials verify tool: upload the exported file to see whether it carries a credential and what that credential says. On a phone, Google Photos shows the same kind of summary in the About panel. Read the result like this:
- No credential found. Common and not suspicious in itself. It means you cannot use provenance to prove anything about this file.
- Valid credential, capture only. The strongest result for an original shoot. Keep this file as your master.
- Valid credential with an AI action. Expect platforms that read C2PA to label the upload, and write your caption with that label in mind.
- “May have been edited by AI tools”. Google Photos shows this when a third-party app recorded an edit without saying whether AI was involved.
- Invalid or incorrectly modified. The file changed without the record being updated, or the tool that wrote it had a bug. Go back to your master file rather than uploading this copy.
Credentials checklist for an original shoot
Use this for any shoot where you may later need to show what is real: brand deliverables, content you expect to be copied, or footage you want to qualify for a camera-capture label.
- Decide per deliverable whether you are proving original capture or simply claiming authorship, because the two need different workflows.
- Confirm before the shoot that your capture device or app signs credentials in the mode you plan to use, and that its software and network conditions meet the maker's requirements.
- Copy the untouched originals to dated archival storage before any editing, and never overwrite them.
- Edit only in tools that preserve and extend credentials, and check one test export through the full workflow before the real edit.
- Let AI steps show honestly in the record. Never strip provenance data to avoid a platform label; where AI was used, the label is accurate and removing the evidence leaves you breaching the platform's disclosure rules.
- Add a name or social links only if you are comfortable with anyone who downloads the file reading them.
- Set an AI training preference if your tool offers one, understanding that it is a signal to AI companies rather than something they are forced to obey.
- Run every final export through the verify tool and note the result.
- After posting, check which label the platform applied; if it is wrong, use the platform's review route instead of re-uploading a stripped copy.
- Keep a simple log: file name, capture device, credential present, verify result, platform and label shown. It turns into evidence quickly if your work is copied or faked.
Where provenance helps and where it does not
A clean credential chain is useful evidence when someone passes off a fake as you, alongside a likeness tool such as YouTube's likeness detection and the legal routes in our guide to the NO FAKES Act and state likeness laws. It can also let genuine footage earn a capture label instead of being doubted.
It does not stop anyone copying your work, it does not make a platform display anything, and it is exposed to what YouTube calls air-gapping, where someone films a screen showing synthetic content with a signing camera, a trick camera makers are still working to detect. For EU audiences, AI providers and deployers have their own marking and labelling duties, covered in our guide to the EU AI Act for creators; a credential can support those duties but is not the whole answer.
Limitations of this guide
Platform support for C2PA changes quickly, and the table describes what each company said on its own pages when we read them, not tests of how every upload is handled. We did not review every camera, phone or editing app, so confirm support with the maker. Credentials are a technical record, not legal proof, and whether one would be accepted as evidence depends on the dispute and the jurisdiction. If a provenance record matters to a legal claim, ask a lawyer how to preserve it.