Research/Field note

Credentials: hardware got serious this year

In short

  • Signing at capture is shipping in phones, cameras and camcorders, with keys held in hardware.
  • Most platforms still strip metadata on upload, and the manifest goes with it.
  • A watermark that points back to a published manifest is how the credential gets across.

Cameras sign at capture now

Content Credentials stopped being a software-only story. Google's Pixel 10 signs every photo by default using keys held in its Titan M2 security chip, with timestamps from the device itself. Sony announced the PXW-Z300 at IBC 2025, the first camcorder that signs footage natively. Leica, Nikon and Canon ship or have announced signing bodies.2,3

On the software side, every Creative Cloud app writes credentials automatically, Google's Imagen attaches them to generated images, and verification is rolling out across Gemini, Search and Chrome.1,2

Then a platform throws it away

The gap is at the point of distribution. Platforms still strip metadata on upload, and the C2PA manifest goes with it. TikTok attaches credentials to its own uploads; most others do not. Midjourney, one of the most-used generators, still embeds nothing.2,4

For a photographer this means the credential you signed in-camera reaches almost no one unless something else carries it across.

So the watermark points back

C2PA's answer is the Durable Content Credential. Alongside the manifest's hard binding, a hash of the pixels, the file carries one or more soft bindings: an invisible watermark and a perceptual fingerprint. When a platform strips the manifest, the watermark still carries an identifier that can be looked up in a manifest repository, and the credential is recovered.5,6

The Content Authenticity Initiative uses Adobe's open-source TrustMark as the interoperable layer that signals which company's watermark is present, so the right decoder can be run.7

This is the architecture deprint uses, with one difference in who holds the pointer. Rather than a vendor's repository, the maker's identifier resolves to a manifest the maker published and can revoke.

Sources

  1. C2PA FAQ, Linux Foundation
  2. C2PA adoption in 2026: hardware, platforms and verification, SoftwareSeni
  3. C2PA supported devices, C2PA Viewer
  4. How provenance survives metadata stripping, SoftwareSeni
  5. Durable Content Credentials, Content Authenticity Initiative
  6. Digital watermarking for interoperable Content Credentials, Content Authenticity Initiative
  7. TrustMark and C2PA, CAI open source docs