What C2PA and content credentials actually tell you
Signed metadata can show that a publisher attached an edit history. It does not prove a stranger's screenshot is real.
C2PA is a standard for content credentials: a signed record that can say who created a file and which tools touched it. Some cameras, newsrooms, and generators are starting to attach it. When the signature checks out and you trust the signer, it is useful. It tells you that a particular organization claims a particular history.
It does not travel well. Screenshots, recompression, and “save as” strips often drop the manifest. A missing credential therefore means nothing. A present credential from an unknown signer also means little, because anyone can attach a story to a file if verifiers are not checking the certificate.
For everyday spotting, credentials are a bonus you look up when the stakes are high and the file is intact. They are not a substitute for looking at the picture. This site strips metadata on its own quiz items on purpose, so the exercise cannot be solved by opening the file info. Read why metadata will not save you for that side of it.