Content credentials do not survive a social re-export
Instagram strips C2PA on upload. Re-export from CapCut often drops it. The platform then guesses.
A Content Credentials manifest is a claim about one exact file. A social app does not publish your exact file. It transcodes for delivery, and a hash over the old bytes no longer matches. Download the post, upload it somewhere else, and you are not moving provenance. You are moving a guess.
Why C2PA manifests die on upload is the technical half: hard binding, re-encode, screenshot, non-aware edit. This post is the path people actually take. Export → CapCut → Instagram → "save video" → YouTube or TikTok. Each hop is allowed. Together they are how a signed generate becomes an unsigned social file, after which the destination guesses with a classifier, a toggle, or nothing.
The path, named
Hop 1: the generator signed the export. Many current image and video tools write a C2PA manifest on the file they give you. That file, and only that file, is what the manifest describes.
Hop 2: CapCut, or any NLE that is not C2PA-aware. A re-export is a new bitstream. Captions, a recrop, a 3-second trim, "export for TikTok" — all of it rewrites bytes. Most consumer editors do not rewrite a valid manifest to match. The credential dies here more often than at the platform, which is why a bisect of your pipeline matters. If the file is already unsigned before upload, Instagram did not strip it. You did.
Hop 3: Instagram ingest. Instagram (and Facebook, and Reels) re-encode on the way in. A hard-bound manifest does not survive that transcode. Meta has said it reads C2PA and IPTC when those signals arrive. A re-encode is how they stop arriving. How Meta decides to show an AI Info label is the remaining machinery: IPTC if it survived, self-disclosure, and for photoreal video the toggle may still be required. The credential is not in the published file.
Hop 4: the social re-export. "Save video," a screen record, a third-party downloader, a colleague forwarding the Reel. That file never had your manifest. It is a delivery encode. Upload it to YouTube and YouTube's C2PA path has nothing to read. YouTube then uses its other inputs: its own GenAI tools (not you), internal detection, and the upload toggle. The cooperative signal is gone. The platform is guessing.
TikTok can still read Content Credentials at ingest if you send the signed original. That is the useful version of the standard: the platform looks, labels, then transcodes. A save-and-reupload from Instagram never gets that look, because there is nothing left to look at.
What to do instead of re-exporting
Post from the signed master, once per destination. Do not use Instagram as a transcode farm. Keep the generator export (or a conforming editor's re-signed export) and upload that file to YouTube, TikTok, LinkedIn, Meta. Cross-posting a watermarked download is a different sin; cross-posting an unsigned delivery encode is this one.
If you must edit after generate, re-sign or accept the drop. A conforming editor writes a new manifest that includes the edit. CapCut, most of the time, does not. If the cut happens in a non-aware tool, treat the output as unsigned and use the platform toggle. Do not pretend the original QR code on the generator site still covers the recut.
Do not strip on purpose to "keep the label off." A stripped file looks like a file that was never signed. Pixel-level watermarks, if the provider applied them, survive. You have removed the signal platforms are built to read and kept the one you cannot see. YouTube has said disclosing AI content does not limit audience or eligibility to earn. The policies that actually hurt distribution are inauthentic, unoriginal and spam — a different document.
Disclose for the destination, not for the metadata. Photoreal video on Meta may still require the AI disclosure after the manifest is gone. YouTube's altered-content toggle still exists for a reason. A dead credential is not a permission to stay silent.
How to prove which hop killed it
Take one asset. Inspect the generator export. Inspect the CapCut export. Inspect a download of the published Instagram post. Record three columns each time: manifest present, binding valid, signer recognised. The first column that flips is the hop. In most social pipelines it is hop 2 or hop 3. Hop 4 is always dead if hop 3 already was.
If hop 1 never had a manifest, nothing downstream can invent a trustworthy one. Check the tool, not the feed.
Article 50's machine-readable marking duty sits on providers and deployers. It is not discharged by Instagram's transcode, and stripping a re-export does not cancel it. The platform label is a separate system. They are not substitutes. C2PA is still the technical path platforms already know how to read — when you give them the file that still carries it.
FAQ
If Instagram strips C2PA, why sign at all?
Because TikTok, YouTube and others still read a manifest that arrives intact, and because "unchanged since signing" is the claim you want for the master. Instagram's transcode is a distribution constraint. It is not an argument for shipping unsigned masters. Sign the keep. Upload the keep. Do not launder it through a Reel download.
Does a CapCut recrop always drop the credential?
If the export is a re-encode through a non-C2PA-aware path, yes in practice. Confirm on your version: inspect the CapCut file, not a blog post. Some tools are starting to preserve or rewrite manifests. Most social-first editors are not there yet. Until you have seen a valid binding on the export, assume it died.
Will YouTube still auto-label a video I pulled from Instagram?
Not via C2PA, because that signal is gone. It may still label from internal detection, or you may owe the toggle for realistic altered content. Plan for the toggle. Do not plan for the Instagram file to speak for you.
Is a screenshot of Content Credentials on the generator site enough for a client?
No. A screenshot is not a binding. Hand over the signed master, plus a note of which destinations were uploaded from that master. A published Instagram encode is not evidence that the credential survived, because it did not.