Content Credentials

Free C2PA & Content Credentials Checker

Drop an image to inspect C2PA provenance, signing details, edit actions, AI generation signals, and cryptographic claim status in your browser.

Drag and drop an image

JPEG, PNG, and other C2PA-supported images can be checked locally. Images are not uploaded to a server.

How to read the checker

Read the active manifest, validation state, signer, and declared actions together. Any one field can be incomplete, unavailable, or misunderstood without the others.

1. Check validation
A failure can indicate a damaged binding, malformed manifest, or other validation issue. Valid and trusted are not interchangeable.
2. Review the signer
A signer name describes the credential issuer when declared. Independently assess whether that identity and certificate are relevant to your use case.
3. Read declared actions
Actions describe what the signing workflow recorded, such as creation or editing. They are claims in the manifest, not a complete pixel-level history.

Common outcomes and next checks

ResultWhat it meansWhat to do next
Trusted or validThe available checks did not report a failed claim; trust-list treatment can still differ.Review signer, actions, asset context, and source.
Invalid or validation issuesThe reader found one or more failed validation checks.Preserve the file and inspect each issue before drawing a conclusion.
No credentials foundNo readable C2PA manifest was available to this checker.Check the source file and ordinary metadata; do not infer authenticity.
Read errorThe format, manifest, browser, or file may be unsupported or malformed.Try the unmodified original in a current desktop browser and compare with another standards-aware verifier.
Privacy and file handling

The checker loads the selected file into a browser-based C2PA reader. It does not need to upload the image to EXIFDataView for analysis.

For sensitive evidence, keep the original unchanged and avoid sharing its filename, visible content, or metadata unless disclosure is necessary.

Test the limitations yourself

Our reproducible C2PA verification lab includes synthetic signed, edited, unsigned, screenshot, and re-encoded samples with recorded results.

Use the sample set to see why missing credentials and an untrusted development signer require cautious interpretation.

Frequently asked questions

Does no C2PA result mean an image is authentic?
No. A camera or app may never have added Content Credentials, or a screenshot, export, platform, or re-encode may have removed them. Absence is not proof that an image is human-made, unedited, or true.
Does a valid C2PA claim prove the pictured scene is true?
No. Validation can show that a signed manifest is bound to the file and has not failed the checks available to this reader. It cannot prove that the scene, caption, or surrounding context is accurate.
What is the difference between valid and trusted?
A claim can be structurally valid while its signing certificate is not anchored to a trust list recognized by the reader. Review the validation state, signing organization, and any issues together instead of treating one badge as a verdict.
Why can a screenshot or edited copy have no credentials?
Many capture, editing, export, messaging, and social workflows create a new file without carrying the original manifest forward. Our controlled C2PA lab demonstrates both screenshot and JPEG re-encode cases.
Which image formats can I check?
The file picker accepts browser-recognized images, while successful C2PA reading depends on the file format, embedded manifest, browser, and the bundled C2PA library. A readable picture can still have no readable credential.
Are images uploaded to EXIFDataView?
The checker reads the selected image with the C2PA WebAssembly library in your browser. EXIFDataView analytics must not receive image bytes, filenames, hashes, GPS coordinates, or manifest contents.

Continue the provenance review

Read the C2PA explainer, compare ordinary fields in the EXIF viewer, and use the metadata signal checker only as supporting evidence—not a definitive AI verdict.