C2PA Content Credentials: What Claude Attaches to Your Files

Alex Halpin
10/7/2026

A screenshot of an image that Claude created may not carry as much proof of its origin as the original file did. That is not a bug. It is how Content Credentials works. Anthropic states so itself in its help article on how Claude marks AI-generated content.
This post explains what C2PA is, what Claude attaches to files, how to check a file for it and the difference between it and the text watermark. Every quote and figure of Claude comes from Anthropic's support article, which I read on 7 October 2026, as well as from the C2PA website at c2pa.org.
What C2PA and Content Credentials are
C2PA is the Coalition for Content Provenance and Authenticity. It describes its work as an open technical standard for publishers, creators and consumers to establish the origin and edits of digital content. Content Credentials are the visible side of that standard. C2PA likens them to a nutrition label for digital content, a peek at the content's history that anyone can access.
The coalition's steering committee includes companies like Adobe, Amazon, BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic. The version of the specification that is listed on the webpage is version 2.3. It does not go into the details of how the signing works, so I will not discuss that here.
What Claude attaches to files
Anthropic explains that Claude will include signed provenance metadata in files of supported file types, such as PNG or JPEG, following the C2PA standard. The article says this applies to output from supported Claude models across the Claude Platform API, Claude, Claude Code, Claude Cowork and Claude Tag.
Anthropic also says new models support marking from day one as of 2 August 2026. Earlier model versions are a different case, and the article lists them among the reasons content may not carry a detectable mark.
Text is marked differently
The same article describes a second mechanism for text. Anthropic says generated text carries an imperceptible watermark directly in the text itself, and because the watermark is part of the text, it travels with the text when it is copied and pasted elsewhere. I cover the text watermark separately in how Claude's watermark works.
| Files (PNG, JPEG) | Text | |
|---|---|---|
| Mechanism | Signed C2PA provenance metadata (Content Credentials) | Imperceptible watermark in the text itself |
| Where it lives | Attached to the file | In the wording |
| Survives copy and paste | Not applicable | Yes, according to Anthropic |
| Lost by | Format conversion, re-saving, screenshots, other metadata stripping | Heavy editing, paraphrasing, translation, mixing into other writing |
The difference matters when you try to reason about what survives. Metadata is a label stuck to a file, so anything that rebuilds the file can drop it. A watermark in the wording survives copying, but it fades as the wording changes. OpenAI chose the second route for text in its ChatGPT watermark announcement, publishing figures on how editing weakens the watermark.
How to check a file
Anthropic points to a free tool called the Claude Content Checker, at claude.com/check-content. It tells you whether a file contains a Claude-issued Content Credential, and it indicates that a file was processed by Claude when marks are found.
Separately, Anthropic describes a detection API in private preview for regulators, law enforcement, media, fact-checkers and independent researchers, with an access request form. The checker is the public route, and the API is not.
What a mark does and does not prove
Anthropic is careful here, and the wording is worth reading closely. A detected mark means the content may have been processed by Claude, and the article calls it not fully conclusive. It gives two reasons. Claude may not be the original author, because people often use Claude to proofread, translate, summarize or convert files. And the content may have changed after Claude processed it.
The absence of a mark proves even less. The article explains that content may not contain a mark if it originated from earlier versions of Claude, has been heavily edited, paraphrased, translated, is very short in length or was created on a platform that does not support Claude's mark. It also lists stripped metadata, through format conversion, re-saving, screenshots or other means.
So a file with no Content Credential is not evidence that a person made it. A file with one is not proof that Claude wrote it all. Treat both as a clue and a reason to ask a question.
What this means in practice
If you publish images made with Claude, the credential helps anyone who receives the original file see where it came from. If you post a screenshot of it, the label is gone, and that is expected under Anthropic's own description. If you are on the receiving end, check the original file instead of a re-saved copy, and do not read a missing mark as a clean bill.
I have not yet run a test against the Claude Content Checker, so what follows is an inference and not a measurement. Anthropic says text may not carry a detectable mark once it has been heavily edited, paraphrased or translated, and RewriteAI works by rewriting the wording of a text. On that basis we expect RewriteAI's Claude watermark remover to be effective on the text watermark. Content Credentials on files are a separate mechanism, and a text rewrite does not touch them. I will publish measured results with the date once I have run the test. For what search engines make of AI content and its marks, see will Google punish AI content.
The short version
Content Credentials are signed C2PA metadata that Claude attaches to supported files like PNG and JPEG. Text gets a different mechanism: a watermark in the wording. Anthropic offers a free Claude Content Checker for files, and says a mark is not fully conclusive while a missing mark proves little. Metadata is lost by re-saving, conversion and screenshots, so check original files where you can.
If you want the longer treatment:
- How Claude's watermark works — the text side in detail
- ChatGPT watermark: what textGrain does — OpenAI's approach for text
- Will Google punish AI content? — what marks mean for search
- How AI detectors work — watermarks next to classifiers
Keep reading
- ChatGPT Watermark: What OpenAI's textGrain Does and Doesn't Do
OpenAI will watermark eligible ChatGPT and Codex text in the EU, and almost nobody can check it yet. Here is what its own numbers say about textGrain.
- Does Turnitin Detect AI From ChatGPT, Claude and Gemini?
Turnitin's AI detection documentation names GPT-3.5, GPT-4, GPT-4o and GPT-4o-mini, and no Claude or Gemini model. What that does and does not tell you about your score.
- How AI Detectors Work: Perplexity, Classifiers and Watermarks
GPTZero stopped using perplexity and burstiness in autumn 2023, which is awkward, because that is still how almost every explainer says AI detectors work. Here are the three generations, and the one that actually scores your writing.
Humanize AI Text and Improve Your Writing Right Now
Rewrite for clarity, flow, and readability while keeping your original meaning and writing style.


