Content Credentials

How you know who made a photograph, and whether anything’s changed since — the open standard, and how The Block uses it.

What a Content Credential actually is

A Content Credential is a record signed into the photograph itself — not a caption anyone could type, but data cryptographically bound to the file at the moment it was made. It states what made the image, what touched it afterwards, and whether anything changed after signing. Break the seal, and the credential says so.

It runs on C2PA — the Coalition for Content Provenance and Authenticity — an open standard, not a feature any one company owns. In 2025 it became a formal ISO standard, the same tier of standardisation that underpins the certificates securing the rest of the web. That matters here specifically: a credential’s proof doesn’t depend on The Block. Open a signed file in a C2PA-aware tool that recognises the signer, and the record holds on its own — see Honest limits below for where that currently depends on trust-listing status.

Two ways a story arrives here with proof

If it’s already signed.

Some cameras and editing tools now sign at the point of capture or export. If a photograph you upload already carries a Content Credential, The Block doesn’t strip it. What arrives signed, stays signed.

If it isn’t yet — Professional signs it for you.

Most cameras still don’t sign at capture. If yours doesn’t, or you want The Block’s own signature on the record too, Professional stories are signed with C2PA content credentials when you publish — a cryptographic statement that the file left this platform exactly as you published it.

Why we built this in, not bolted it on

Generative tools now produce images indistinguishable from photographs at a glance. Detecting fakes after the fact is a losing race — the tools improve faster than the detectors. C2PA takes the other side of that problem: instead of asking “can we catch the fake,” it asks “can the real thing prove itself,” at the moment it’s made.

That’s the same fight The Block exists for. The gatekeeper stops a phone snap becoming a story. C2PA is how a real story keeps its receipt after it leaves here — to a viewer, a publication, a court, a future you can’t predict yet. It’s not “trust me.” It’s “here’s the proof, and you don’t have to take our word for how to check it.”

Honest limits

A Content Credential proves a signer made specific claims about a file at a specific time — that’s strong, checkable evidence. It isn’t proof the camera was pointed at what it claims, and it isn’t a guarantee no clever attack will ever exist. We’d rather you understand exactly what the proof does and doesn’t cover than oversell it.

Today, verifiers report The Block’s signature as valid from an issuer not yet on the official C2PA trust list — trust-listing is in progress. The cryptography itself doesn’t change either way, but until it lands, older or stricter C2PA tools may not recognise our issuer even though the credential is intact.

Content CredentialsC2PA