What Does C2PA Actually Prove (and What Can It Not Prove)?
Content Credentials are often described as proof of authenticity. Here is the technical reality of what C2PA cryptographic manifests establish and where their boundaries lie.
The 5 Distinct States of C2PA Validation
Many discussions confuse finding a C2PA header with establishing cryptographic trust. C2PA verification requires passing five distinct sequential levels:
The image container includes C2PA markers (such as a JPEG APP11 marker with a JP\0\0 signature or a PNG caDX chunk).
The ISO 19566-5 JUMBF boxes and CBOR-encoded claims, assertions, and signature structures can be extracted without syntax errors.
The manifest adheres to standard schema definitions, including valid assertion labels (c2pa.actions, c2pa.hash.data).
Two mathematical proofs pass: (a) the computed SHA-256 asset byte hash matches the manifest's content binding assertion, and (b) the digital signature (ECDSA P-256) verifies against the certificate's public key.
The signing certificate chains up to a recognized, unrevoked root authority (such as Adobe CAI or a recognized camera manufacturer trust list). Anyone can generate a valid cryptographic signature using a self-signed key; trust requires an anchor.
What C2PA Actually Establishes
When a manifest is fully valid and trusted, it provides mathematical assurance of:
- Tamper-Evidence: If a single pixel or byte of image data was changed after signing, the content binding hash check fails.
- Signer Identity: You can verify which application, AI service (e.g., OpenAI DALL-E 3), or camera hardware signed the manifest.
- Self-Declared Lineage: Software agents record actions taken (e.g.,
c2pa.created,c2pa.cropped,c2pa.filtered).
What C2PA Cannot Prove
It is equally important to understand what C2PA technology cannot do:
- It Does Not Prove Real-World Truth: A person can photograph a staged scene or an AI printout with a C2PA-equipped camera; the resulting manifest will be cryptographically valid despite the deception.
- Absence Does Not Mean Fake: Over 99% of images on the web lack C2PA manifests. Social media platforms, messaging apps, and image editors routinely strip metadata during re-compression.
- Fragile Against Analog Re-Capture: If someone takes a screenshot or snaps a photo of a screen displaying a signed image, the original cryptographic manifest is lost.
Auditing and Managing C2PA Manifests
If you need to inspect the cryptographic status, signer certificates, or editing lineage of an image, use our C2PA Checker. If you need to strip manifests before publication, our C2PA Remover removes the JUMBF data containers losslessly directly in your browser.
Inspect C2PA Manifests Privately
Verify digital signatures, asset hashes, and certificate trust anchors in your browser.