Digital provenance, explained

Que sont les Content Credentials (C2PA) ?

Cryptographically signed provenance records—not universal truth certificates or AI detectors.

Check an image for embedded credentials

JPEG, PNG, or WebP · Processed locally · Block-level detection

  1. Asset

    The image or media file.

  2. Assertions

    Statements about creation, editing, tools, or context.

  3. Signed claim

    Cryptographically signed by a trusted signer.

  4. Content Credential

    A tamper-evident provenance record.

A credential records statements about an asset’s history

  1. Origin & capture

    May record when, where, and how the asset was created.

  2. Edit actions

    May record adjustments, crops, filters, or other edits.

  3. Tools & software

    May record apps, plugins, or versions used.

  4. Ingredients

    May record sources or materials used to create the asset.

  5. Signer context

    May record who signed and under what role.

  6. AI-related source types

    May record AI tools, models, or generation methods.

Tamper-evident provenance is not absolute truth

Validation can establish

  • Structure

    The manifest is well-formed.

  • Signature

    The signature cryptographically matches the manifest.

  • Asset binding

    The manifest is bound to this asset.

  • Alteration

    If content or manifest was changed, it can be detected.

Signed manifest (C2PA)
A signed C2PA manifest with a verification shield
The landscape asset bound to the signed manifest

Validation cannot establish

  • Factual truth

    It cannot verify the real-world events happened.

  • Non-AI status

    It cannot prove the asset was not AI-generated.

  • Complete neutrality

    It cannot guarantee no bias or intent.

  • Trust without context

    It cannot know your trust relationships or policies.

Credentials can be embedded, remote, or durable

  1. Embedded manifest

    An image with an embedded provenance manifest

    The manifest is stored inside JPEG or WebP metadata, such as a JUMBF/C2PA box.

  2. Remote manifest

    A remote provenance manifest hosted in cloud storage

    The asset points to a manifest hosted on a server or trusted repository.

  3. Durable credential

    A durable fingerprint linked to provenance information

    A fingerprint or invisible watermark can help rediscover it later.

Choose the right kind of inspection

Different tools, different jobs

MetaScrub — local block-level inspection

A laptop, privacy shield, and padlock representing local MetaScrub inspection
  • JPEG, PNG, WebP
  • Recognized C2PA/JUMBF blocks
  • Before/after summary
  • Local processing in your browser

Best for quick checks and removal of embedded blocks you can control.

No upload · Your files stay local

Full C2PA validator

A signed document, chain link, and magnifier representing full C2PA validation
  • Signature validation
  • Trust context (policies, keys)
  • Assertion details
  • Manifest history and lineage

Best for deep provenance analysis and verifying signer and trust context.

Requires external upload

Remove the embedded block without changing the image pixels

  1. Add image

    A landscape image ready to be added

    Choose a JPEG, PNG, or WebP file.

  2. Review detected blocks

    A checklist of detected metadata blocks

    See which recognized blocks are present in your file.

  3. Choose mode

    Privacy and provenance cleaning mode controls

    Pick the mode that matches your goal.

  4. Verify and download

    A laptop showing a verified download

    Confirm what will be removed and save your clean copy.

Broad privacy removal

Removes recognized EXIF, GPS, XMP, IPTC, comments, and C2PA/JUMBF blocks while keeping ICC.

AI-provenance only

Removes recognized C2PA/JUMBF blocks and AI-tagged text while keeping EXIF, GPS, IPTC, and ICC.

Check an image for embedded credentials

Local browser processing · JPEG, PNG, and WebP

Removing provenance is a tradeoff

Privacy benefit (cleaned copy)

Reduced embedded workflow and signer metadata.

A cleaned landscape image with fewer embedded metadata blocks
  • Fewer embedded blocks
  • Less workflow exposure
  • Less signer metadata
  • Better sharing control
A balance scale surrounded by seaside flowers

Provenance cost (cleaned copy)

The embedded verification chain is broken for this copy.

Two signed manifests separated by a broken verification chain
  • No embedded manifest
  • Breaks verification chain
  • Loses local tamper-evidence
  • Limits future proof of origin

Questions about Content Credentials?

Are Content Credentials the same as EXIF?

No. EXIF typically stores camera and capture data. Content Credentials use a signed provenance manifest that can describe creation, edits, ingredients, and signer context.

Do they prove an image is real?

No. Validation can show that a manifest is well-formed, signed, and bound to an asset. It cannot prove that the depicted event happened or that every assertion is factually true.

Does every AI-generated image have them?

No. Support depends on the generating tool and export workflow. Some tools add C2PA manifests, some use other signals, and some add no durable provenance at all.

Can a non-AI photograph have them?

Yes. Cameras, newsrooms, editing tools, and publishing workflows can add Content Credentials to conventional photographs and other non-AI media.

Is C2PA an invisible watermark?

No. A C2PA manifest is structured provenance data. Durable fingerprints or invisible watermarks are separate mechanisms that may be used alongside a manifest.

Can MetaScrub validate a signature?

No. MetaScrub detects and removes recognized embedded C2PA/JUMBF blocks. Use a full C2PA validator when you need signature, trust-chain, or assertion validation.

Does removal erase remote provenance?

Not necessarily. Removing an embedded block does not guarantee deletion of manifests stored in remote repositories or provenance rediscovered through durable fingerprints.

Will removal change image quality?

No. MetaScrub removes supported metadata blocks without changing the image pixels, so the visual image and its encoded pixel quality stay unchanged.

Does AI-only mode keep GPS?

Yes. AI-provenance-only mode keeps EXIF, including GPS, while removing recognized C2PA/JUMBF and AI-tagged metadata. Use broad privacy removal when you also want GPS removed.

Reviewed against C2PA specification 2.4 · July 21, 2026

A woman in a floral summer dress pointing toward the metadata inspection button

See whether your image contains an embedded credential

Inspect recognized C2PA/JUMBF blocks before deciding what to remove.

Check an image for embedded credentials

Local browser processing · JPEG, PNG, and WebP