Back to Guides
Provenance & Cryptography Guide

What Does C2PA Actually Prove (and What Can It Not Prove)?

Content Credentials are often described as proof of authenticity. Here is the technical reality of what C2PA cryptographic manifests establish and where their boundaries lie.

What Does C2PA Cryptographically Prove?C2PA Content Credentials prove that a specific digital asset matches the cryptographic hash signed by a specific digital certificate, and that the image bytes have not been altered since that signature was created. C2PA does NOT prove that an image represents real-world truth, that the scene was not staged, or that an unsigned image is fake. C2PA certifies origin claims, not objective reality.

The 5 Distinct States of C2PA Validation

Many discussions confuse finding a C2PA header with establishing cryptographic trust. C2PA verification requires passing five distinct sequential levels:

1. Detected

The image container includes C2PA markers (such as a JPEG APP11 marker with a JP\0\0 signature or a PNG caDX chunk).

2. Parsed

The ISO 19566-5 JUMBF boxes and CBOR-encoded claims, assertions, and signature structures can be extracted without syntax errors.

3. Structurally Well-Formed

The manifest adheres to standard schema definitions, including valid assertion labels (c2pa.actions, c2pa.hash.data).

4. Cryptographically Valid

Two mathematical proofs pass: (a) the computed SHA-256 asset byte hash matches the manifest's content binding assertion, and (b) the digital signature (ECDSA P-256) verifies against the certificate's public key.

5. Signer Trusted

The signing certificate chains up to a recognized, unrevoked root authority (such as Adobe CAI or a recognized camera manufacturer trust list). Anyone can generate a valid cryptographic signature using a self-signed key; trust requires an anchor.

What C2PA Actually Establishes

When a manifest is fully valid and trusted, it provides mathematical assurance of:

  • Tamper-Evidence: If a single pixel or byte of image data was changed after signing, the content binding hash check fails.
  • Signer Identity: You can verify which application, AI service (e.g., OpenAI DALL-E 3), or camera hardware signed the manifest.
  • Self-Declared Lineage: Software agents record actions taken (e.g., c2pa.created, c2pa.cropped, c2pa.filtered).

What C2PA Cannot Prove

It is equally important to understand what C2PA technology cannot do:

  • It Does Not Prove Real-World Truth: A person can photograph a staged scene or an AI printout with a C2PA-equipped camera; the resulting manifest will be cryptographically valid despite the deception.
  • Absence Does Not Mean Fake: Over 99% of images on the web lack C2PA manifests. Social media platforms, messaging apps, and image editors routinely strip metadata during re-compression.
  • Fragile Against Analog Re-Capture: If someone takes a screenshot or snaps a photo of a screen displaying a signed image, the original cryptographic manifest is lost.

Auditing and Managing C2PA Manifests

If you need to inspect the cryptographic status, signer certificates, or editing lineage of an image, use our C2PA Checker. If you need to strip manifests before publication, our C2PA Remover removes the JUMBF data containers losslessly directly in your browser.

Inspect C2PA Manifests Privately

Verify digital signatures, asset hashes, and certificate trust anchors in your browser.

Open C2PA Checker