Credentials in every JPEG photo
Pixel Camera adds a C2PA manifest to every JPEG photo it takes. Google Photos shows it in the “About” panel and, if you edit the photo there, signs the edited copy again and records what was done, with AI or without.
Pixel 10 · C2PA Content Credentials
With a Pixel 10 you no longer have to take it on trust.
Its photos carry C2PA Content Credentials signed by the camera, which let you check whether the image was captured as a photograph and which recorded changes it received afterwards.
Sellat verifies the credentials in your browser and can add an independent proof of existence, so that evidence keeps over time.
What your photo carries
Pixel 10 is the first phone to add C2PA Content Credentials to every photo from its camera app, with nothing to switch on. This is what Google publishes about how it does it.
Pixel Camera adds a C2PA manifest to every JPEG photo it takes. Google Photos shows it in the “About” panel and, if you edit the photo there, signs the edited copy again and records what was done, with AI or without.
The signing key lives in the phone’s secure hardware (Tensor G5 and the Titan M2 chip). Google places Pixel Camera at Assurance Level 2 of the C2PA Conformance Program, the highest level defined today.
The manifest carries a timestamp generated on the device, meant to keep the credentials checkable once the signing certificate expires, even if the photo was taken with no connection.
Each photo is signed with a different certificate. According to Google, no two photos can be linked to each other or to the person who took them: the credentials say which device and which process, not who.
Source: Google, September 2025 and May 2026. Sellat reads what the manifest declares and whether its signature validates; it does not verify the device or the process.
How far it goes
Credentials answer one specific question. It helps to know which.
That the photo came out of Pixel Camera, when it was signed and which edits were recorded afterwards, as long as the file keeps the manifest and the signature validates. It is the best proof of origin a phone photo can carry today.
The manifest normally travels inside the file. WhatsApp recompresses the photo when you send it, a screenshot is a new file, and re-exporting usually drops the manifest. And it says the image was captured as a photograph, not that what it shows happened: a staged scene, or a screen displaying an AI image, is photographed and signed just the same.
Read: what Content Credentials are and why they can disappear →
C2PA + Sellat
This is not “Sellat improves C2PA”. They are different layers answering different questions, and they need each other.
Your Pixel signs how the photo was created and what was done to it afterwards. It lives inside the file, so it depends on nobody rewriting it along the way.
Sellat computes the SHA-256 fingerprint of the exact photo in your browser and anchors it publicly. The proof lives outside the file: no forward can erase it. Checking it needs that exact version, which is why the Sellat ZIP keeps it.
If you need it, a qualified timestamp issued by an authority on the EU trusted list. It enjoys a presumption of accuracy of the date and time and of integrity (art. 41.2 of Regulation (EU) 910/2014).
The Pixel’s credentials travel with the photo. Sellat’s proof stays outside, anchored, and is still there when the manifest is gone.
Not only Pixel
The same tool reads the credentials of any camera or phone that signs them. As of September 2026, according to the manufacturers:
On every JPEG photo from Pixel Camera, out of the box. Google has announced the extension to video and to other Pixels.
Signing built into the camera, in JPEG and DNG. The M11-P was the first camera with Content Credentials, in 2023.
Through a firmware update, since July 2025.
Through firmware, within a programme Sony offers to newsrooms and agencies rather than to any photographer.
Added it in 2025 and suspended its service the same year after a vulnerability. The credentials issued stopped validating.
Marks only edits made with Galaxy AI, not the capture.
The list changes every month. What counts is what your file carries: drop it above and you will know. Read the credentials of any image →
Who it is for
Photographs of damage, condition and measurements submitted months later. Knowing which credentials the photo carried when taken, and holding independent proof of when it existed.
Check-ins, check-outs, incidents and works. A photo forwarded over WhatsApp carries nothing any more; the Sellat proof survives.
Visual evidence that withstands a claim: which exact image, what it declared, and since when it has existed.
And if you are a creator who prefers a European proof layer independent of Adobe, the same tool serves you just as well.
Frequently asked questions
JPEG photos taken with Pixel Camera do. A screenshot, a received photo or an image created by another app do not, unless that app adds them.
Normally not: WhatsApp recompresses the image when you send it and the copy that arrives is a different file, with no manifest. If you want it to travel along, send the original file as a document.
No. It is read in your browser with the open-source implementation of the standard. To protect the photo, Sellat receives only its SHA-256 fingerprint, unless you switch custody on.
A proof that does not travel inside the file. The Pixel’s credentials say how the photo was made; Sellat’s proof records that this exact photo existed at a moment, publicly anchored and verifiable without trusting Sellat. If the manifest is lost, the proof is still there.
Google has announced that it is extending credentials to more Pixels and to video. The way to know is to drop the photo above: if it carries a manifest, you will see it.
Same tool. It reads any C2PA manifest, from a phone or a camera, and tells you who signed it, with which tool and whether it validates.
Your Pixel already signed the origin. Protect the exact photo today and its existence is anchored outside the file.
Protect a file