Content Credentials (C2PA) — FAQ
What are Content Credentials?
Content Credentials are a form of metadata embedded directly into a file using the C2PA open standard. They record information about how a piece of content was created, such as whether it was generated by an AI model, who published it, and when it was signed. They're intended to provide tamper-evident information about a file's provenance, without altering the content itself.
Which Stability AI outputs include Content Credentials?
Image, video, and audio outputs generated through our APIs and first-party products are signed with a C2PA manifest before delivery. This includes:
|
Media type |
Formats |
|
Image |
PNG, JPEG, WebP |
|
Audio |
WAV, MP3 |
|
Video |
MP4 |
The credential is embedded in the file you download — no extra step is required.
What information is in the credential?
When you inspect a signed file, you should see:
- Action: c2pa.created — indicating the file was generated, not captured from the real world.
- Digital source type: trainedAlgorithmicMedia (IPTC vocabulary) — indicating the content was produced by a trained AI model.
- Publisher: Stability AI.
- Timestamp: The UTC date and time the file was signed (via DigiCert).
- Claim generator: Stability_ContentCredentials_Service.
If the generation involved an input image you supplied (e.g., inpainting, upscaling, or similar editing workflows on our image APIs), the credential may also list that input as a parent ingredient.
Does Stability AI apply watermarks to outputs?
No. Stability AI does not apply visible or invisible watermarks to generated content. Our AI-labeling approach relies on C2PA Content Credentials metadata, not watermarking.
Can Content Credentials be removed or lost?
C2PA metadata is embedded in the file, but it is not indestructible. Actions that may strip or invalidate it include:
- Re-encoding or converting the file to a different format.
- Taking a screenshot instead of downloading the original file.
- Editing the file in software that does not preserve C2PA metadata.
- Uploading to platforms that re-compress or re-process media.
Our updated Terms of Service prohibit the intentional removal of Content Credentials from outputs generated through our platform. Our Acceptable Use Policy continues to apply to all use of generated content.
How do I verify a file's Content Credentials?
Several Content Credentials validators are publicly available, we suggest this one maintained by the Content Authenticity Initiative:
verify.contentauthenticity.org
Drop or upload any supported file. For a Stability AI output, you should see the claim generator Stability_ContentCredentials_Service, the action c2pa.created, source type trainedAlgorithmicMedia, and publisher Stability AI.
Stability AI does not host its own verification tool.
Do Content Credentials affect how I can use the output?
No. Content Credentials are metadata — they describe provenance, not permissions. Your rights to use generated outputs are governed by your agreement with Stability AI and our Acceptable Use Policy, not by the credential itself.
I'm building an application on top of Stability AI's API. Do I need to do anything special?
The credential is already embedded in the file bytes returned by the API. If your application serves the file to end users, the simplest way to preserve the credential is to serve the original file as-is, without re-encoding it.
If your pipeline does re-encode or post-process outputs, be aware that some image and audio processing libraries may discard C2PA metadata. Preserving credentials through a processing pipeline requires C2PA-aware tooling (see the C2PA open-source SDKs).
If I self-host an open-weight model, will outputs include Content Credentials?
Open-weight models from Stability AI do not automatically embed C2PA metadata in outputs. If you are self-hosting one of our models and require Content Credentials, we recommend working with the C2PA organization to implement their spec and incorporate credentials into your outputs.
Where can I learn more about C2PA?