C2PA Explained: Verify Media Provenance, Not Truth (2026)
C2PA records where a media file came from, which tools handled it and which organization signed those claims. It can verify provenance and tamper-evident history. It cannot prove that the scene shown in the file happened in the real world.
What C2PA can verify
A C2PA-enabled file can carry a signed manifest containing claims about its creator, editing actions, ingredients and signing certificate. A verifier checks the signature, asset binding and validation status. If those checks pass, the verifier has evidence that the signed claims have not changed since signing.
The official C2PA explainer describes this as a provenance system. It does not turn a signed claim into a fact-check of the depicted event.
What C2PA cannot prove
- A valid signature is not proof of truth. A correctly signed photo can still be staged, mislabeled or presented with a false caption.
- No manifest is not proof of a fake. Platforms can strip credentials, and many cameras and editing tools do not add them.
- A trusted signer is not the same as a trusted story. Trust lists help validate who issued a certificate; the viewer still has to assess the signer and the claim.
- A detector score does not replace provenance. Pixel or model signals estimate manipulation risk. They do not reconstruct a missing chain of custody.
Start with the task you need to perform
Check a file without reading the specification
Use the Content Credentials verification workflow for a step-by-step review, or open the public Content Credentials verifier. Record whether a manifest exists, whether validation passed and who signed it.
Understand the visible history
Read the practical Content Credentials guide and the guide to C2PA action assertions. Actions may document editing steps, but they do not explain the intent behind an edit.
Check the signer and trust chain
Use the C2PA trust-list and signer guide before relying on an organization name shown by a verifier. Certificate validation and publisher reputation are separate judgments.
Review tamper and validation signals
The guides to tamper evidence, validation status and claim-signature validation explain the main failure states without treating every warning as malicious alteration.
Understand ingredients and asset binding
Use the ingredient assertions guide to see how source assets can be referenced. For deeper technical checks, continue to data-hash asset binding and hashed-URI validation.
C2PA and deepfake detection answer different questions
C2PA asks: who signed these claims, what history was recorded and does the file still match the signed manifest?
A deepfake detector asks: does the available media contain signals associated with AI generation or manipulation?
Use both when the stakes justify it. Start with provenance because a valid disclosure can directly identify AI generation or editing. If credentials are missing, stripped or inconclusive, review the media with the relevant image detector, video detector or audio detector. Neither path authenticates the real-world event on its own.
A five-step review record
- 1. Save the original file rather than a screenshot when possible.
- 2. Record whether a C2PA manifest is present.
- 3. Record signature, trust and asset-binding results separately.
- 4. Read the actions and ingredients without inferring facts they do not state.
- 5. Compare the provenance record with the publisher, caption and external reporting.
That record is more useful than a binary “real” or “fake” label because another reviewer can reproduce each check.
Need to check a suspicious file?
Open the matching detector and interpret the result alongside the source and context.
Open Detector