C2PA checker
Inspect an image for C2PA records and readable provenance fields. A detected name or action is a declaration in the file, not a verified signature.
Drag images in, paste, or click to choose
A whole folder works too · Ctrl/Cmd+V pastes · on phone this opens your file picker · up to 40 MB per file
Read only. This page never changes a file and never uploads one. PNG, JPEG and WebP only — a photo straight off an iPhone is usually HEIC, which this does not read yet.
What a result here does and does not prove
A manifest is a claim the file makes about itself, and this page reads that claim without checking who signed it. Verifying the signature needs a trusted certificate list fetched over the network, and nothing here touches the network, so treat a named tool as “the file says so” rather than as proof. Adobe’s official Verify site does the signature check.
The reverse matters more: finding nothing is not evidence that an image is real. Metadata comes off with any stripping tool, survives no screenshot, and is dropped by most social platforms on upload. There is also a second kind of mark that lives in the pixels rather than the metadata, and no metadata reader reaches it.
How this C2PA checker reads a file
The checker looks for supported C2PA records and extracts recognised readable names and actions when available. It also reads selected XMP fields, including the IPTC digital source type, and a small set of EXIF camera fields. This is limited extraction rather than full manifest decoding: some files may contain records or fields it cannot read. The original file stays unchanged, and its contents are analysed locally.
Where this C2PA checker falls short
- Signatures are not verified. A readable name is a declaration found in the file, not proof that the named organisation signed it. Use a dedicated verifier to check credential validity.
- Finding no supported record does not establish whether an image was AI-generated. Records can be missing, removed during editing, or unreadable by this checker.
- A watermark encoded into the pixels themselves, such as SynthID, is not metadata and no metadata reader reaches it.
Questions about the C2PA checker
Is the C2PA checker free to use?
Yes. Reading a manifest costs nothing here and there is no limit on how many images you inspect, because the parsing happens in your own tab rather than on a server someone has to pay for.
What is C2PA, in one sentence?
It is a standard for attaching a signed record to a file describing what made it and what has been done to it since, published by the Coalition for Content Provenance and Authenticity and marketed to the public as Content Credentials. Adobe, OpenAI, Google and several camera makers write it into what they produce.
Why does this checker not say whether the credentials are genuine?
This checker extracts selected declarations; it does not perform cryptographic signature or certificate-chain validation. File contents stay in your browser. Use a dedicated Content Credentials verification service when you need to evaluate authenticity, and check its file-handling terms separately.
An AI tool made this image, so why does the checker find nothing?
A record may never have been attached, may have been removed during export or editing, or may be outside what this checker can recognise. An empty result cannot establish that the image was made without AI.