Content Credentials Checker (C2PA)

See who made an image or video, with which app, whether generative AI was involved and whether its C2PA signature holds up, without uploading it.

Drop an image or video to check its Content CredentialsChoose an image or video to check its Content Credentialsor click to choose a file, or paste an imageTap here to pick one from your photos or files · JPEG, PNG, WebP, AVIF, HEIC, TIFF, GIF, MP4, MOV, MP3, WAV, PDF

How to check Content Credentials

  1. Drop a photo, AI image, video or audio file on the box above, click it to pick a file, or paste a copied image.
  2. The checker reads the C2PA manifest inside the file and verifies its signature on your device. The first check downloads the reader (about 3 MB) once; your file is never uploaded.
  3. Read the summary, then scroll for the full edit history, ingredients and AI-training preferences. Use Download manifest JSON if you need the raw data, or Share result for a link to a summary: whether credentials were found and valid, the signer, the AI use they declare, the kinds of edits and the number of ingredients (never the file, its name, dates, thumbnails or location).

How to read the result

  • Made with is the app or service that wrote the credentials (the “claim generator”), for example a camera, Photoshop, or an AI image generator.
  • Signed by is the organisation named on the signing certificate, and Signed on is the time confirmed by a time-stamping service, if one was used.
  • Validation has three outcomes. Valid and trusted: the signature is intact, the content matches what was signed, and the certificate is on the official C2PA Trust List (or the older interim list still used for earlier content). Valid, but the signer is not on a trust list: nothing was altered, but the signer's identity isn't vouched for. Invalid: the file or the credentials changed after signing, so the history may not describe this file.
  • What happened to this file lists the recorded actions (created, opened, edited, cropped, converted…). The digital source type is the key AI signal: trainedAlgorithmicMedia means “created using generative AI”, compositeWithTrainedAlgorithmicMedia means “edited using generative AI” (for example generative fill), and digitalCapture means a camera capture.
  • Ingredients are the files that went into this one, such as the original photo or a placed image, each with its own thumbnail and credentials when available.
  • AI training and data mining shows whether the owner allows the file to be used for training AI models.

What C2PA and Content Credentials are

C2PA (the Coalition for Content Provenance and Authenticity) is an open standard from Adobe, Microsoft, Google, OpenAI, the BBC, Sony and many others. A C2PA manifest is a cryptographically signed record embedded in the file that says who produced it, with which tool and what was done to it. “Content Credentials” is the consumer name for the same thing, often shown as a small “CR” icon. Cameras from Leica, Sony and Nikon, recent Google Pixel and Samsung Galaxy phones, Adobe apps, and AI generators including Adobe Firefly, ChatGPT and Google's Gemini image models can add them.

No credentials does not mean fake

Most images online carry no Content Credentials. Many social networks and messaging apps strip metadata on upload, screenshots never had any, and older software simply doesn't write it. So a missing manifest tells you nothing about whether a picture is real or AI-generated. The reverse is also true: credentials are the signer's own statement. A valid manifest proves who signed the file and that it hasn't changed since, not that the scene is true. When credentials are missing, check the AI image detector for other AI markers and the EXIF viewer for camera data, and search for the original upload.

Why AI labels matter in 2026

Since 2 August 2026, Article 50 of the EU AI Act requires providers of generative AI systems to mark synthetic images, video, audio and text in a machine-readable, detectable way (providers already on the market before then have until 2 December 2026), and people who publish deepfakes must disclose that the content was artificially generated or manipulated. In the United States, California's AI Transparency Act (SB 942, as amended by AB 853) has applied since the same date to generative AI services with more than one million monthly users: they must embed hidden “latent” disclosures such as the provider name, model version and creation time in AI images, video and audio, offer a visible label, and provide a free detection tool. C2PA manifests are the most common way to meet these machine-readable labelling rules, usually alongside invisible watermarks such as SynthID (used by Google and, since May 2026, OpenAI), which live in the pixels and can only be checked with the vendors' own tools.

Troubleshooting

  • “Invalid” after editing: editing or re-saving in an app that doesn't support C2PA changes the pixels, so the signed hash no longer matches. Check the original export instead.
  • “Credentials stored online”: some files only link to a cloud manifest. This tool doesn't fetch it, to keep your check private.
  • HEIC or video preview missing: your browser can't display that format, but the credentials are still read.

Content Credentials CheckerSomeone shared their result

Suggested