Milkglass

Free photo toolsView and remove photo metadata

What are content credentials (C2PA) in a photo?

Content credentials are a signed record inside a photo file that says how the picture was made and what was done to it afterward. The C2PA standard defines them. They are metadata: they sit next to the picture, you can check whether a file has them, and you can remove them.

By Paul Bădărău, maker of Milkglass. Written on 7 October 2026.

What C2PA is

C2PA is the Coalition for Content Provenance and Authenticity. It publishes an open standard with the same name. "Provenance" is the word that explains its purpose. The coalition defines it as "the recorded history of a piece of digital content", from the moment it is created through all later changes (C2PA, frequently asked questions).

A content credential is that history, written into the file and signed with cryptography. The signature lets an app check that the record was not changed after it was made.

What a content credential can hold

According to the coalition, the record can capture details about the creation of the content, the tools that were used, the time, the location, and the changes over time. For a photo, read that as a log:

About people, the coalition says that the core specification "does not support attribution of content to individuals or organizations, so that it can remain maximally privacy-preserving". Extensions for creators who want their name on their work exist outside that core. So what a given file says depends on the camera or the app that wrote the record.

How to see whether a photo has content credentials

  1. Open the photo metadata tool and choose the photo.
  2. Look at the group Other data. A file with a credential shows the row Content credentials (C2PA) with its size.

The tool tells you that the record is there and how large it is. It finds the record in JPEG, PNG, WebP, and HEIC files. To read the record itself and to check its signature, use a viewer made for content credentials.

Can content credentials be removed?

Yes. They are a block of data in the file, and a block can be taken out. The coalition says so itself, and it adds that a credential can be linked to the picture in a second way, through "invisible watermarking or fingerprinting", which can help to find the credential again "even if it's removed from the file".

So there are two layers to keep apart:

The other tool on this site, Remove the location from a photo, keeps the content credential and lists it under Kept. A credential can hold a location of its own. When no place may stay anywhere in the file, use Remove all metadata.

When to keep them

A content credential is useful when you want to show where a picture comes from:

A copy that goes through a tool or a website that rewrites the file can arrive without its credential, like any other metadata. If the record matters to you, send the original file, and check the copy at the other end.

When to remove them

When the history of the file is more than the receiver needs. A record that names the phone, the editing app, the time of every edit, and perhaps a place is a detailed log. For a private photo that goes to a stranger, a clean copy, made with Remove all metadata, is the simple choice. You keep the original, with its record, for yourself.

Content credentials and the other metadata

A file with a content credential usually holds the older kinds of metadata too: EXIF from the camera, and often XMP from an editing app. They are separate blocks. Removing the location from EXIF leaves the credential in place, and removing the credential leaves EXIF in place. The guide What is EXIF data in a photo? explains the older kinds.

Check whether a photo holds content credentials, and remove them with the rest of the metadata. The photo stays on your device.

Open the metadata tool

And for the photos you keep to yourself

I'm Paul, and I make Milkglass. It keeps private photos, videos, and files in Drawers on your iPhone. Draw a pattern, and the Drawer of that pattern opens.

See how Milkglass works Milkglass is coming to the App Store for iPhone and iPad, and the date is still open.