C2PA Content Credentials
Content Credentials are a signed record of how a file was made and what has been done to it since, carried inside the file itself. Cameras, editors and image generators all write them, and models that mark their output now write them too.
Content CredentialsC2PA manifestc2pa.actionsCAIprovenance manifest
The manifest read out, not just noticed
$ augur scan photo.jpg
photo.jpg (jpeg): 7 finding(s)
PROVENANCE
[notice] offset 772 — C2PA Content Credential (1.5 kB) — Aperture Studio 3.2, generated by a trained model
generated by=Aperture Studio 3.2
source=generated by a trained model
binding=matches — the file still hashes to what was signed (sha256)
software agent=Aperture Diffusion 2
actions=c2pa.created
asset title=holiday-photo.jpg
asset format=image/jpeg
signed by=Aperture Studio Signing (Aperture Studio), certificate issued by Aperture Studio Signing
signature=ES256
claim=version 1, 2 assertions
… and 1 moreExcerpt: the provenance section of a seven-finding scan. The row worth the whole page is the third one — and the second, which is where a file says it came out of a model rather than a camera.
The one part of a credential you can check yourself
A manifest carries a hash over the file it rides in, with its own bytes left out. Recomputing that hash needs the file and nothing else: no key, no network, no trust list. Either the bytes still hash to what was signed, or the file is not the file that was signed.
That is the whole reason it is worth doing here. Every other question a credential raises — is this signer real, is the certificate trustworthy, was the timestamp honest — needs something a file inspector does not have.
One byte of the picture changed, afterwards
$ augur scan photo-edited.jpg
photo-edited.jpg (jpeg): 8 finding(s)
PROVENANCE
* [concern] offset 772 — the Content Credential no longer matches this file
algorithm=sha256
claim says=1c2c331b51ef…
file hashes to=9e495df058a0…
[notice] offset 772 — C2PA Content Credential (1.5 kB) — Aperture Studio 3.2, generated by a trained model
generated by=Aperture Studio 3.2
source=generated by a trained model
binding=DOES NOT match — the file changed after it was signed (sha256)
* not removable — reported and left in placeExcerpt: the provenance section again. The same photo with one byte of the compressed picture flipped. Nothing about the edit is visible and no viewer would mention it; the credential stops matching and says so. It is reported as a concern rather than an alarm because an edit after signing is ordinary — a re-save, a resize, a metadata strip — and only sometimes a lie.
It is evidence, not a tracker
A provenance record says something about the file rather than about you, which is why it is a notice and not a warning. In most photographs it is the part you want to keep. It is removable like any other metadata block if you decide otherwise, and removing anything else from a signed file breaks the binding — which the next scan will tell you.
What augur does not tell you about it
It does not verify the signature and it does not check the certificate against any trust list, because it ships with none. "Signed by" means the file says so. It also does not fetch a manifest kept at a URL: the tool reads the bytes it was given and makes no network requests.
What it will say is which of those it did: the binding row reports "matches", "DOES NOT match", or "not checked" with the reason.
$curl -fsSL https://raw.githubusercontent.com/dejo1307/augur/main/install.sh | shRelated:A Content Credential in textWhat a photo carriesGPS coordinates in a photoeverything it looks for