Every image
can carry a receipt.
Content Credentials are signed records that say who made a file and how — cameras add them, AI generators add them, and most people have never heard of them. Here's the plain-words version.
Short answer: Content Credentials (the C2PA standard) are a signed record inside a file that names its origin — camera or AI tool, plus edits since. Our AI image checker reads them locally in seconds; for full cryptographic verification, contentcredentials.org/verify. The catch: they're easy to strip, so absence proves nothing — only presence is a signal.
By the Tool Pantry team, October 2026. Tested with our own checker on a Stable-Diffusion-style PNG, a camera JPEG, and a stripped screenshot — results below.
What exactly is inside a Content Credential
A C2PA manifest is a small, cryptographically signed block of metadata — usually embedded in the file itself (a JUMBF box in a JPEG, a chunk in a PNG). It can record: the device or tool that created the file, the date, whether generative AI was involved, and a chain of edits if the software supports it. The signature is the point: anyone can write metadata, but only the holder of the signing key can write a credential that verifies.
Two flavors show up in the wild. Content Credentials (C2PA) are the signed manifests — cameras from Leica and Sony write them at capture, and most major AI generators attach them to output. IPTC labels are a lighter cousin: a plain metadata field, most notably trainedAlgorithmicMedia, that tools like Adobe Firefly and Google's image models set to declare AI generation.
What our tests showed
We ran three files through the checker. A Stable-Diffusion-style PNG carrying the Automatic1111 "parameters" chunk — the full generation recipe — was flagged instantly as a strong AI signal. A camera JPEG with ordinary Canon EXIF came back clean, with camera metadata listed as context. And a screenshot of an AI image? Nothing — no metadata, no verdict, because the screenshot never had any.
That spread is the whole story in three files: when the receipt is there, it's conclusive; when it's gone, the file is simply silent.
How to check any image (30 seconds)
- Open toolpantry.app/ai-image-checker and add the original file — not a screenshot of it.
- Read the verdict: AI markers found, Content Credentials present, or nothing to report.
- For a C2PA manifest, take the extra step to contentcredentials.org/verify — that's the official validator that checks the cryptographic signature itself. Our checker reports presence; the validator confirms authenticity.
Why this matters in 2026
Two forces are pushing credentials into the mainstream. Regulators: the EU AI Act's transparency provisions expect AI-generated content to be labeled, and platforms are starting to surface labels in their UIs. And toolmakers: since late 2025, new cameras and image models ship with provenance "baked in" by default — the metadata is becoming automatic, which makes checking it worthwhile. If you run a newsletter, a marketplace, or a classroom, "check the receipt" is the practical habit; the full walkthrough is in our guide Is this image AI?.
The honest limits
Three caveats worth internalizing. Credentials are stripped by most social platforms, all screenshots, and many re-saves — so a missing receipt means nothing either way. Our checker detects and reports; it doesn't cryptographically validate signatures (the official validator does). And credentials describe a file's history, not its truth: a real photo with a real credential can still be staged, and an AI image with no credential can still be AI. They're evidence, not verdicts.
What are Content Credentials?
Content Credentials are a signed record — the C2PA standard — embedded in a file that describes its origin: which camera or AI tool made it, when, and what edits happened since. Think of it as a nutrition label for media.
Can Content Credentials be removed?
Yes, easily — any re-save, screenshot, or social platform upload can strip them. That's why their absence proves nothing; only their presence is informative.
Are AI labels legally required now?
The direction of travel is yes: the EU AI Act's transparency rules expect AI-generated content to be marked, and major generators now add labels and credentials by default. Enforcement is still unfolding through 2026.
How do I check an image for Content Credentials?
Use the AI image checker — it reads the file locally and reports whether a C2PA manifest or IPTC AI label is present. For full cryptographic verification of a manifest, upload it at contentcredentials.org/verify.