Content Credentials · C2PA

C2PA Content Credentials: What They Are and How MetaRemover Handles Them

AI tools like ChatGPT and Adobe Firefly embed hidden provenance data in images. MetaRemover detects, reads and removes these Content Credentials — fully in your browser, without uploads.

Check your file for C2PA

What is C2PA?

C2PA (Coalition for Content Authenticity and Integrity) is an open technical standard developed by Adobe, Microsoft, Intel, BBC, and others. It defines a way to embed a cryptographically signed manifest directly inside a media file — an image, video or document.

The manifest records the complete provenance chain: who created the file, with which software, when it was created or edited, and what transformations were applied. Each entry is signed with a digital certificate, making it tamper-evident.

C2PA is often described as a “nutrition label” for digital media — it tells you where the content came from.

C2PA vs EXIF — Key Differences

FeatureEXIF / XMP / IPTCC2PA
PurposeCamera & editing metadataContent provenance & authenticity
Cryptographic signature✗ None✓ Required
Tamper-evident✗ No — anyone can edit✓ Yes — changes invalidate signature
AI generation info✗ Not standardized✓ Explicit AI source type
Who embeds itCamera, photo editorsAI generators, certified tools
Readable byAny EXIF toolC2PA-aware tools (MetaRemover, c2pa.org)
Removable✓ Easy✓ Yes — MetaRemover removes it

Which Tools Embed C2PA?

ChatGPT (gpt-image)🤖 AI

Signs all generated images. Signed by OpenAI Media Service, algorithm Es256.

Adobe Firefly🎨 AI

Full C2PA support with trusted certificate. Provenance includes generation and edit history.

Adobe Photoshop✏️ Editor

Content Credentials added on save since version 24. Records all applied edits.

Microsoft Designer / Bing🤖 AI

Embeds C2PA in AI-generated images. Certificate from Microsoft.

Leica cameras📷 Camera

Hardware-level signing. Content Credentials embedded at capture time.

Sony cameras📷 Camera

Authenticity verified via C2PA in select professional models.

What MetaRemover Shows for C2PA Files

When you upload a file with a C2PA manifest, MetaRemover parses the full manifest using the official @contentauth/c2pa-web SDK — entirely in your browser via WebAssembly. No file is uploaded to any server.

🛡
Signed by
Organization name from the certificate (e.g. OpenAI Media Service)
🏢
Issuer
Certificate authority (e.g. OpenAI OpCo, LLC)
🔐
Algorithm
Cryptographic algorithm used (Es256, Ps256)
🕐
Signed at
Date and time the manifest was signed
💻
Software
Tool that created or processed the file (e.g. gpt-image)
🤖
AI Generated
Whether the IPTC CV marks this as algorithmically generated media
📋
Actions
Full history: created, converted, watermarked, edited
alidation
Trusted / Untrusted signer / Invalid — based on certificate chain

What Happens After Removing C2PA?

  • The image content is preserved exactly — pixels, colors, resolution unchanged
  • The C2PA manifest is completely removed — no provenance data remains
  • The file will no longer show as AI-generated in C2PA-aware tools
  • The provenance chain is broken — the image can no longer be verified as authentic
  • Standard EXIF and GPS data are also removed in the same operation

Supported Formats

FormatC2PA locationDetectRemove
JPEGAPP11 segment (0xFFEB)
PNGcaBX / C2PA chunk
WebPC2PA RIFF chunk
HEICNot yet
MP4 / MOVuuid box
PDFXMP / attachment

Frequently Asked Questions

Check your files for C2PA now

Drop any JPEG, PNG or WebP — MetaRemover will detect and parse the full manifest in seconds. No account, no upload, no tracking.

Try MetaRemover →

Related guides