Video Verifier
All guides

How it works

Content Credentials (C2PA) explained simply

The hidden "made with AI" label inside some photos and videos: who adds it, what it proves, why most videos don't have one, and how to check for it.

Video Verifier team · · 3 min read

When people ask "is there a way to prove where a video came from?", the best answer today is Content Credentials: a tamper-evident record of a file's origin and edits, built on an open standard called C2PA.

What is C2PA?

C2PA stands for the Coalition for Content Provenance and Authenticity. It was founded in 2021 by Adobe, Arm, the BBC, Intel, Microsoft and Truepic, and companies including Google, OpenAI, Meta and Amazon have since joined. Together they publish a free, open standard for attaching provenance information to images, video and audio.

"Content Credentials" is the friendlier name for a C2PA record, often shown as a small "cr" icon.

What's inside a credential

A credential is a signed bundle of facts, called a manifest, attached to the file. It can say:

  • Which tool made it, for example a specific AI generator, editing app or camera.
  • What was done to it: generated, edited, cropped, combined with other media.
  • Who signed it: the company or device that vouches for those facts.

The signature uses the same kind of cryptography that secures websites. If someone changes the picture after it was signed, the signature no longer matches and checkers flag it as tampered.

Who adds Content Credentials today

  • AI tools: OpenAI attaches credentials to Sora videos and its image outputs, and Adobe Firefly adds them to its generations. Other generators are adopting the standard.
  • Cameras and phones: Leica, Sony and Nikon have released cameras that can sign photos, Google's Pixel 10 can sign photos taken with its camera app, and Samsung tags images edited with its AI tools.
  • Platforms: LinkedIn shows the "cr" icon on supported images, and TikTok uses credentials to automatically label AI-generated uploads.

What a credential proves, and what it doesn't

A valid credential saying "generated by Sora" is about the strongest evidence you can get that a video is AI-made. A valid credential from a camera is strong evidence the footage was captured, not generated.

But a credential is only as good as what's left of it. It doesn't help when:

  • It's been stripped. Many platforms and messaging apps remove metadata when you upload or forward. A screen recording or screenshot drops it completely.
  • It never existed. Most video in the world, real or fake, has no credential at all. Open-source AI models don't add them.
  • It's present but tells a partial story. A credential describes what the signing tool knew. It can't tell you whether the scene itself was staged.

No credential doesn't mean fake, and it doesn't mean real. It just means you need other evidence.

How to check a file for Content Credentials

  • Upload the file to Video Verifier. Every scan reads C2PA credentials and reports what they say, who signed them, and whether they're intact, alongside our other checks.
  • The Content Authenticity Initiative's free Verify tool also shows credential details for a file.

For the best chance of finding a credential, check the original file or the first upload, not a forwarded copy. Our reverse video search guide helps you find it.

Why it matters

As AI video gets harder to spot by eye, provenance flips the question from "can we prove this is fake?" to "can this prove where it came from?". The more cameras, apps and platforms sign and preserve credentials, the more useful that question becomes. Until then, credentials are one powerful signal among several, which is exactly how we treat them. Read more in how AI video detectors work.