In short
- A credential is legible and cryptographically strong, but it travels in metadata, and metadata gets thrown away.
- A watermark survives almost any handling, but carries a few bits and cannot explain itself.
- The 2026 consensus is to use both: a credential for meaning, a watermark to find the credential again.
It's always one of two things
Everything in this field is one of two things. Either you attach a statement to the file, or you hide a signal in the pixels. The first is legible and strong, but it travels in metadata and metadata gets thrown away. The second survives almost anything, but it can only carry a few bits and can never explain itself.
Here they are, side by side
Credentials · metadata
C2PA Content Credentials
- A signed manifest inside the file: creator, device, software, every edit.
- Cryptographic. Tampering is detectable, authorship is attributable.
- Stripped by nearly every social platform on upload.
- Open standard under the Linux Foundation. Used by Adobe, Google, OpenAI, Sony, Nikon, Leica, Canon.
Watermarks · pixels
Invisible watermarks
- A pattern spread across the image that a matching detector can read.
- Survives crop, compression, screenshots, mild edits. Carries a short payload or a yes/no.
- Cannot say who or why on its own. Needs a lookup.
- SynthID, TrustMark, Stable Signature, Tree-Ring, StegaStamp.
A credential answers the questions a person actually asks: who made this, with what, and what was done to it since. It does so with a signature, so the answer can be checked rather than trusted.1 A watermark answers one narrower question, which is whether this particular pattern is present, and it keeps answering after the file has been screenshotted, cropped and re-compressed.
What survives being passed around?
The table below is qualitative and drawn from the literature. It describes ordinary handling, not a determined attacker. Regeneration, where an image is passed through a generative model and re-synthesised, is the case that separates the methods.4
| Method | Type | Survives JPEG | Survives crop | Survives screenshot | Survives regeneration |
|---|---|---|---|---|---|
| C2PA manifest alone | Signed metadata | stripped | lost | lost | lost |
| Durable Credential | Manifest + soft bindings | yes | yes | yes | partial |
| SynthID-Image | Learned, post-hoc | yes | yes | yes | partial |
| TrustMark | Learned, post-hoc | yes | yes | yes | partial |
| Tree-Ring | In-model, initial noise | yes | yes | yes | mostly |
| Visible proof overlay | Typeset | yes | if uncropped | yes | lost |
Table 1Qualitative survival under ordinary handling. Words in every cell, so colour is never the only channel.
Six small charts share one x and one y. The eye compares shapes, which a grouped bar of 24 columns would hide.
So you need both
C2PA's answer to stripped metadata is the Durable Content Credential. Alongside the manifest's hard binding, a hash of the pixels, the file carries one or more soft bindings: an invisible watermark and a perceptual fingerprint. When a platform strips the manifest, the watermark still carries an identifier that can be looked up, and the credential is recovered.2,3
- 03Your credentialwho, when, with what · signed
- 02Your markin the pixels · invisible · points to 03
- 01The photographuntouched
The 2026 consensus, written into both the C2PA specification and the EU's Code of Practice, is that you need both. A credential for meaning, a watermark to find the credential again.5 deprint is that pairing, with the maker holding the key.
One difference in how deprint does it is who holds the pointer. Rather than a vendor's repository, the maker's identifier resolves to a manifest the maker published and can revoke.
Sources
- C2PA FAQ, Linux Foundation
- Durable Content Credentials, Content Authenticity Initiative
- Digital watermarking for interoperable Content Credentials, Content Authenticity Initiative
- Invisible Watermarks: Attacks and Robustness, arXiv, Dec 2024
- Code of Practice on Transparency of AI-Generated Content, Cuatrecasas