GateTrue

What each generator documents about marking its output

Content credentials: a record attached to the file

Content credentials are a structured record travelling with a file rather than inside its picture. Ordinary tools can read them, which is the point, and ordinary handling can drop them, which is the cost. As of 2026-09-22.

What a credential check can and cannot establishFinding an attached record establishes what the record says, because the record is structured and signed. Not finding one establishes nothing: the file may never have carried one, may have lost it in an ordinary re-encode, or may come from a vendor that publishes nothing about credentials at all.A file is dropped into a credential readerA record is foundSomething is establishedThe record says what it says: on one entryhere, the model and the platform used.Nothing is foundNothing is establishedNever carried one, stripped by handling,or from a vendor that publishes nothing.Why a failed check is not evidence a file is genuine
Fig. 1 One vendor in this register publishes that caveat about its own mechanism. No other vendor publishes a durability limit of any kind.
How this register uses the term, and what it excludes. Written 2026-09-22.
The termContent credentials
What it namesA structured record of how a file was produced, attached to it
What it is notA signal carried by the picture itself
Where the register uses itThe file-contents column, where a vendor names the standard

Inclusion rule. Words this site uses in a narrow sense, where the ordinary sense would lead a reader to misread a cell. No vendor statement appears on this page. Order. Fixed order: what the word names, what it excludes, then where it is used here.

1Readable is the whole design goal

The reason to attach a record rather than embed a signal is that anybody can read it without a scheme-specific detector. A recipient drops a file into a tool and gets back what the record says. That is a genuinely different proposition from a signal only the originating vendor can interrogate.

It also allows detail. A record can name the model, the platform, the date and a chain of edits, where an embedded signal usually conveys existence and little else. The cells in this register that name a credential standard are the ones that can, in principle, tell a reader which model made a file.

2Removable is the matching cost

Because the record is attached rather than embedded, an ordinary re-encode through an editor can leave it behind. That is not an attack; it is what re-encoding does, and it happens to nearly every delivered file at least once. One vendor in this register publishes exactly that caveat about its own credentials.

So a credential check has an asymmetric meaning. Finding a record establishes something; not finding one establishes nothing at all, because the file may never have carried one, may have carried one that was stripped, or may come from a vendor that publishes nothing about credentials.

3What fills a cell, and what does not

Naming the standard fills the file-contents column, because a named standard is something a reader can look up and check. A page that tells publishers to preserve whatever credentials a tool writes, without naming one, does not: an instruction to keep an unnamed layer gives a reader nothing to do with a file in hand.

That bar is set deliberately high. Several pricing pages in this register mention metadata in passing, and if a passing mention filled the cell the column would stop distinguishing a specification from a gesture, which is the only thing it is for.

Nothing on this page is a vendor statement; the values it helps read are on the support table, with the page and the date each one was read from. See also the free tier column, metadata against watermark. Nearby terms: provenance manifest, generation metadata, platform label.