Adobe Firefly Image Detector: Content Credentials, Tells, and What Survives a Re-save
Sana Bano
·September 26, 2026
·8 min read
How to detect Adobe Firefly images: read the Content Credentials Firefly attaches to every generation, what strips them, and what to check when they are gone.
The fastest way to detect an Adobe Firefly image is to check its Content Credentials. Adobe attaches them automatically to every Firefly generation, they cannot be switched off inside Adobe's tools, and a valid credential names Adobe as issuer and lists the AI tool used. When the credential is gone, which a screenshot or a plain re-save can cause, you fall back to a pixel-level AI image detector and the visual tells.
Firefly is the best-behaved generator on the provenance side, and that is exactly why the missing-credential case matters more here than anywhere else.
Key Takeaways
- Firefly attaches Content Credentials to every generation. Adobe applies them to Text to Image, Text Effects, Generative Fill and Generative Recolor output, free and paid, with no off switch.
- The credential records five things: issuer (Adobe Inc.), date issued, the app or device, the AI tool used, and the actions taken, listed as Created or Other edits.
- Adobe's approach is metadata, not a pixel watermark. Unlike Google's SynthID, Adobe has not documented an invisible watermark inside the pixels for Firefly images.
- A re-save can strip it. Converting formats or exporting from some apps drops the credential, and platforms that do not preserve metadata drop it on upload.
- Instagram already reads it. Meta labels images carrying Firefly credentials as AI on upload, so a credential is also how a Firefly image gets caught in the wild.
Why Firefly is the easy case, most of the time
Adobe co-founded the Content Authenticity Initiative and built Content Credentials as its implementation of the C2PA standard. Firefly was designed to carry them from day one. According to Adobe's Firefly documentation, credentials are applied automatically to assets generated with Text to Image, Text Effects, Generative Fill and Generative Recolor, and they may also be stored in Adobe's public Content Credentials cloud, which is what lets the Verify site sometimes recover a record after a file's own metadata has been stripped.
That makes the first check trivial when the file is intact. Drag it into a verifier and read the answer. The credential also travels through Adobe's own apps: an image generated in Firefly, opened in Photoshop and exported with credentials enabled carries a chain of two signed entries, the generation and the edit, each with its own timestamp. That chain is what a journalist or a marketplace moderator wants to see, because it shows not only that AI was involved but what happened afterwards. We walk through the tools, what a manifest contains, and what a failed signature means in how to verify C2PA Content Credentials.
How to detect a Firefly image, step by step
1. Get the original file. Not a screenshot, not a copy from a chat app. Both strip the credential.
2. Open a Content Credentials verifier. The official Verify site at contentcredentials.org, an in-browser C2PA viewer, or the Content Credentials browser extension. Drop the image in.
3. Read the manifest. For a Firefly image you should see Adobe Inc. as the issuer, a date, the app (Firefly web, Photoshop, Express), the AI tool named, and an action of Created. If the image was then edited in Photoshop, the edit steps appear as further actions with their own signatures.
4. Check the signature status. Valid means the record is intact. Invalid means the file was changed after signing. Missing means the metadata was stripped or never attached.
5. If missing, read the pixels. Upload the image to the Adobe Firefly image detector at GPTOne. It returns a confidence score plus a region heatmap showing which parts of the image look generated, and it reads C2PA credentials in the same pass, so you get both signals from one upload. A new free account includes one image scan on its starting credits, with no card required.
What strips a Firefly credential
This is the part Adobe's documentation understates and forum threads are full of.
Format conversion. PNG to JPG to WebP round-trips in tools that do not support C2PA drop the manifest. Even Photoshop users report that re-saving as JPG without the credentials option enabled loses it.
Screenshots. Always. A screenshot is a new image with no history.
Platforms that do not preserve metadata. Many social networks and messaging apps strip metadata on upload for size and privacy. Instagram is the exception that reads it and labels the post. LinkedIn also displays credentials where present.
Deliberate removal. Metadata strippers exist and are advertised for exactly this. Adobe's generative AI terms say users must not remove or alter Content Authenticity Initiative metadata, but a term of service does not stop a file from being edited.
The consequence is simple: a missing credential tells you nothing about whether Firefly made the image. We tested what happens to detection when provenance is removed in does removing C2PA make an AI image undetectable.
Visual tells that survive the re-save
When the metadata is gone, the pixels are what you have. Firefly's output has a recognisable character, partly because of what it was trained on. Adobe trained Firefly on Adobe Stock, openly licensed content and public domain material, and the results look like stock photography: clean, evenly lit, commercially composed, rarely gritty.
Look for:
- Stock-photo lighting and framing. Soft, uniform light, centred subjects, no lens artefacts, no motion blur where a real photo would have some.
- Over-smooth textures. Skin, fabric and foliage that lack fine grain, especially at the edges of the frame.
- Rendered text. Firefly has improved, but signage, labels and packaging still show letter shapes that almost spell a word.
- Repeated micro-patterns. Tiles, bricks, crowds and leaves that repeat more regularly than the real world does.
- Generative Fill seams. For edited photos, a region whose noise, sharpness or colour temperature does not match the rest of the frame. This is where a heatmap earns its place, because it points at the region rather than the whole image.
None of these is proof on its own. A real stock photo can be evenly lit and over-retouched, and a Firefly image of a rainy street can look gritty if the prompt asked for it. Together with a detector score they build a case, and we describe the general method in how to tell if an image is AI-generated.
Firefly versus the other generators on provenance
| Generator | Provenance | Survives a screenshot |
|---|---|---|
| Adobe Firefly | C2PA Content Credentials, automatic, no off switch | No |
| OpenAI (ChatGPT, DALL-E) | C2PA Content Credentials | No |
| Google (Imagen, ImageFX, Gemini) | SynthID pixel watermark plus metadata | Watermark can survive |
| Midjourney | None | Nothing to survive |
| Grok | None | Nothing to survive |
Firefly and OpenAI sit in the same box: honest metadata that a re-save removes. Google's approach is covered in our Imagen and ImageFX detector guide, and the OpenAI case in the DALL-E image detector guide. For the metadata that real cameras write, and how AI images lack it, see how to check photo metadata for AI.
FAQ
Does Adobe Firefly watermark its images?
Firefly attaches Content Credentials, which are signed metadata, to every generation. Adobe has not documented an invisible pixel watermark for Firefly images. A visible watermark appeared on free-tier output during the beta and was later removed for paid users.
How can I tell if an image was made with Adobe Firefly?
Drop the original file into a Content Credentials verifier. A Firefly image shows Adobe Inc. as issuer and names the AI tool. If the credential is missing, run the image through an AI image detector and check the visual tells.
Can Content Credentials be removed from a Firefly image?
Yes. Screenshots, format conversion and many upload pipelines strip them, and dedicated tools exist to do it. Adobe's terms prohibit removal, but the file does not enforce that.
Does Instagram detect Firefly images?
Instagram reads Content Credentials and labels images that carry AI-generation metadata, so an intact Firefly image is labelled on upload. Strip the credential and the label does not appear.
Is a missing credential proof that an image is real?
No. Most images online have no credential because something in the pipeline removed it. Absence means "no provenance", not "not AI".
Check the credential first, then the pixels. The GPTOne AI image detector does both in one upload, with a region heatmap and C2PA reading included on the free tier.