Content Credentials Checker

Verify an image's Content Credentials (C2PA): who signed it, whether the signature validates, which app or camera created it, the recorded actions and ingredients, and whether it declares AI generation or camera capture.

✓ Free✓ No sign-up🔒 Deleted after readingC2PA · signer · actions
🔐

Drop or paste an image to verify its Content Credentials

Signer, validation, creating app, actions, ingredients and AI/camera declaration.

Choose an image →

Tip: use the original file. Most platforms strip Content Credentials on upload.

What Content Credentials are

Content Credentials are a signed provenance record defined by the C2PA standard (Coalition for Content Provenance and Authenticity). When a supporting camera or application saves an image, it embeds a manifest: which tool created the file, what actions were applied (created, edited, cropped, colour adjusted, placed), which source images were used as ingredients, and a digital signature from the tool's certificate.

Because the manifest is signed, any change to the image or the record breaks the signature. That is what makes Content Credentials different from ordinary EXIF: they can be stripped, but they cannot be quietly rewritten. OpenAI's image models, Adobe Firefly and Photoshop, Google, Microsoft, TikTok, and cameras from Leica, Nikon and Sony attach them today.

What the checker verifies

  • Signature: whether the embedded manifest validates against its certificate, and who the signer is.
  • Creator: the application or device that produced the file, from the claim generator.
  • Declaration: whether the credentials declare AI generation (trainedAlgorithmicMedia and similar) or a camera capture.
  • Actions and ingredients: the recorded edit actions, the software that performed them, and how many source images were combined.
  • Signing time and title, when the manifest records them.

Only credentials embedded in the file are read. Remote manifests are deliberately not fetched. When there are no credentials, the checker falls back to the file's EXIF and XMP and offers the AI image detector on the same upload.

How to read the result

  1. Verified, declares AI: the generator signed the file as AI-produced. This is the strongest provenance signal available.
  2. Verified, declares camera capture: a supporting camera signed the capture. Strong evidence of a real photo, though later edits may have been made in tools that do not update the manifest.
  3. Present but invalid: the image or the manifest was altered after signing. Treat with suspicion.
  4. No credentials: the most common case. It says nothing either way; use the EXIF viewer, the edited photo detector and the AI detector.

Frequently asked questions

What are Content Credentials?

A signed record of an image's origin and history under the C2PA standard: creating app or camera, actions, ingredients and a signature. OpenAI, Adobe, Google, Microsoft and newer cameras attach them.

How do I verify them?

Upload the image above. The checker parses the manifest, validates the signature and shows the signer, creator, actions, ingredients, signing time and the AI or camera declaration.

Why does my image have none?

Most images do not carry them yet, and most platforms strip them on upload. A missing manifest is not evidence either way; run the AI detector on the same upload.

Can they be faked?

Altering a signed manifest breaks the signature, which shows as invalid here. Credentials can be stripped, and a self-signed manifest proves little, so read the signer and the validation result, not just the presence of a manifest.

Is it free and private?

Yes. Free, no sign-up, image deleted after reading, and no remote manifests are fetched.

Related: image metadata checker · EXIF viewer · edited photo detector · AI image detector · for fact-checkers.