Browser-based image privacy tool
Check C2PA Content Credentials in an Image
Inspect an image for embedded C2PA provenance data and understand what it means.
This browser check reports supported embedded C2PA/JUMBF markers. It does not currently validate signatures or issuer trust.
Processed locally in your browser · Up to 20 files · 25 MB each · 150 MB total
Use the C2PA Content Credentials Checker to inspect supported images for provenance information defined by the Coalition for Content Provenance and Authenticity. C2PA is designed to carry signed claims and assertions about an asset and its history.
This is an inspection tool, not a generic AI detector. It should report what the credential says, whether validation succeeds under the implemented trust rules, and what limitations apply.
What the Checker Looks For
A C2PA manifest can contain assertions about asset creation, actions or edits, ingredients, device or software information, and other provenance statements. Those assertions are assembled into claims and signed so a verifier can evaluate integrity and trust.
The checker should present a human-readable summary first, with an advanced raw view for users who need technical detail.
How C2PA Differs From EXIF
EXIF primarily describes capture and image-related information. It is not inherently signed and can be edited or removed. C2PA is a provenance framework built around signed claims, assertions, cryptographic bindings, and trust information.
An image can have EXIF without C2PA, C2PA without meaningful camera EXIF, both, or neither.
What a Valid Credential Does and Does Not Prove
A successfully validated credential can tell you that the signed manifest and its bindings satisfy the verifier's checks and can expose statements made by the credential issuer or signing workflow. It does not mean that every statement should be interpreted without context, nor does it make the image immune to misleading presentation outside the credentialed asset.
Users should inspect who or what signed the credential, what actions are asserted, and whether the asset is the one the credential actually binds to.
Why Credentials Can Disappear
Metadata can be removed by exports, optimization, screenshots, format conversions, platform processing, or deliberate cleaning. C2PA also supports mechanisms intended to improve provenance resilience, but an embedded manifest may not survive every distribution path.
The Content Authenticity Initiative's public Verify service is a useful reference implementation for inspecting supported files.
FAQ
Does “no Content Credentials found” mean the image is fake?
No. Content Credentials are still not present in every camera, editor, generator, or distribution path. Absence is not an authenticity verdict.
Is C2PA an AI watermark?
No. C2PA is a provenance standard. It can communicate AI-related assertions, but it is not the same as an imperceptible watermark such as SynthID.
Can editing invalidate a Content Credential?
A workflow that changes the asset without creating an appropriate new credential can break the relationship between an embedded manifest and the resulting file. C2PA-aware editors can instead add new provenance information.