
A coalition specification for provenance metadata
The Coalition for Content Provenance and Authenticity (C2PA), a Joint Development Foundation project formed through an alliance between Adobe, Arm, Intel, Microsoft and Truepic, published its first technical specification as version 1.0. A GitHub release record for that specification's website is dated 24 December 2021. The specification defines a manifest: a record, attached to an image, video or document, that states how the content was produced or edited and which tool made each recorded change, intended to be inspected later to establish the file's provenance.
What the specification and its plain-language explainer describe
The technical specification site describes C2PA's purpose as developing standards 'for certifying the source and history, or provenance, of media content'. Since version 1.0, the specification has been revised repeatedly, with the hosted site, retrieved 16 September 2026, now listing versions up to 2.4 alongside separate Explainer, Guidance for Implementers and Security Considerations documents. The plain-language site Content Credentials describes what the resulting record is for in consumer terms: it lets a viewer 'determine the method of creation and see a record of editing history' for a piece of content.
What a manifest proves, and what it does not
A manifest is evidence about what a piece of software recorded, not an independent check on whether that recording is accurate. Content Credentials states this limit directly: the system exists to let 'good actors' demonstrate how content was made, and it documents what a creation tool asserted about its own output, not whether that assertion is true. A capture or editing tool that is compromised, misconfigured, or operated in bad faith can produce a manifest that misrepresents what happened, and a manifest attached at export can also simply be absent from a file that never passed through a supporting tool, or that was stripped of it afterward. Reading a present manifest as proof of authenticity, or an absent one as proof of manipulation, both go beyond what the primary documents describe.
Questions to carry into your own evaluation
- Which specification version produced a given manifest, and has the underlying standard's guidance for implementers been updated since?
- Is the tool that produced the manifest one whose claims about its own process a given audience actually has reason to trust?
- Does the absence of a manifest indicate the content came from a generator that does not support C2PA, or that a manifest was removed?
C2PA gives publishers and platforms a shared format for recording provenance claims, which is a narrower and more checkable property than a general authenticity guarantee. Generators that support it are documenting their own tool's claims about origin and editing, not certifying the truth of what the media depicts, and the coalition's growth from five founding organisations to a much longer list of steering-committee members today has not changed that basic limit.
Sources & reading trail
States C2PA's purpose of certifying source and history of media content and shows the version history from 1.0 through 2.4.
Source published: Not established · Retrieved: 16 September 2026
Dates the publication of the specification's version 1.0 website.
Source published: 24 December 2021 · Retrieved: 16 September 2026
Identifies the coalition's founding alliance and, as retrieved, its current steering-committee membership.
Source published: Not established · Retrieved: 16 September 2026
States in plain language that a Content Credential records how content was made rather than verifying the truth of that record.
Source published: Not established · Retrieved: 16 September 2026
Papers and official documents establish the record; the reading and the questions are Model Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.