Skip to content
AI Origin CheckRun a free check

Signed provenance inspection

Free C2PA Checker for Images

Open an image locally to check whether it carries a C2PA manifest, whether that credential validates, and which creation or editing actions it declares. Nothing is uploaded — the C2PA WebAssembly validator runs inside this tab.

Updated

Drop an image here

JPEG, PNG or WebP • up to 25 MB

Your file stays on your device. Analysis runs locally in your browser.

After the check

How to use this check

  1. Choose an image

    Select or drag a JPEG, PNG, or WebP file up to 25 MB. The file is read through browser APIs and never sent to a server.

  2. Wait for local validation

    The official C2PA WebAssembly validator loads on demand and checks the manifest store, signature, and hard binding inside your browser.

  3. Read the headline verdict

    The result is grouped as verified credential, validation problem, metadata hint, or no verified signal — never as an AI percentage.

  4. Open the evidence panel

    Expand the technical details to see the signer, claim generator, recorded actions, ingredient chain, and any validation issue codes.

  5. Interpret it in context

    Compare the declared actions and digital source types against what the image claims to show. Treat a missing credential as missing information, not as evidence of human authorship.

What a C2PA credential actually contains

C2PA — the Coalition for Content Provenance and Authenticity — defines a way to attach a signed, tamper-evident record to a media file. That record is called a manifest, and a file can carry several of them chained together in a manifest store.

Each manifest holds a claim, and the claim gathers a set of assertions: statements about how the asset came to exist. Typical assertions name the claim generator (the software that produced the file), the actions performed (created, edited, colour-adjusted, resized), the digital source type (captured with a camera, produced by a generative model, composited from several sources), timestamps, and the ingredients that were used as inputs.

The claim is then signed with a certificate, and bound to the actual bytes of the asset through what the specification calls a hard binding — a cryptographic hash of the asset content. That binding is what makes the record tamper-evident: change a pixel, and the hash no longer matches.

  • Claim generator — the tool that wrote the credential, such as a camera firmware or an editing application.
  • Actions — the declared operations, in order, including which ingredient each one consumed.
  • Digital source type — a controlled vocabulary term describing capture, generative output, or composite origin.
  • Ingredients — earlier assets that fed into this one, each of which may carry its own provenance.
  • Signature and timestamp — who vouched for the claim, and when.

How to read each validation state

Validation is not a single yes-or-no answer. The validator checks several independent things — that the manifest parses, that the signature verifies against the certificate, that the hard binding matches the asset bytes, and that the signing certificate chains to a recognised trust list. Any of these can succeed or fail on its own.

This is why the result is expressed as one of four evidence classes instead of a score. Each class tells you something different about what you are allowed to conclude.

  • Verified credential — the manifest parses, the signature verifies, and the binding matches. Provenance statements can be attributed to the signer.
  • Validation problem — a manifest exists but something failed. This can mean tampering, but it also commonly means re-encoding, an expired certificate, or a signer outside the configured trust list.
  • Metadata hint — no signed credential, but editable EXIF or XMP strings mention a tool or provider. Treat these as leads, not proof.
  • No verified signal — nothing inspectable was found. This is the most common result on the open web and carries almost no information.

Why a validation problem is not automatically a forgery

The most frequent cause of a failed check is ordinary processing rather than deception. A social platform that re-encodes an upload will break the hard binding even though nobody intended to mislead. A screenshot produces a genuinely new file with no relationship to the original manifest. A signing certificate that has since expired will fail a trust check on a record that was perfectly valid when it was created.

The useful move when you see a validation problem is to look at which specific check failed. A hash mismatch on an otherwise well-formed manifest points to the asset being modified after signing. A signature that will not verify at all points to a malformed or substituted manifest. A trust-list failure often points to nothing more than an unfamiliar signer.

The issue codes shown in the evidence panel come from the validator itself, not from our interpretation, so you can look them up in the specification and reason about them directly.

Why real AI images so often show nothing at all

Coverage is the honest weakness of provenance right now. Only some generators write C2PA data, only some platforms preserve it, and only some formats carry it reliably. An image can be entirely synthetic and still arrive with a completely empty manifest store.

Anything that re-encodes pixels tends to strip provenance: messaging apps, screenshot tools, format conversion, image compression services, and most social networks. Some of these are beginning to preserve credentials, but you cannot assume it.

This is the single most important thing to internalise about the tool. Absence of evidence is not evidence of human authorship, and any site that converts a missing credential into a confident verdict is guessing. When a scan comes back empty, the wider verification method matters more than the scan did.

What a valid credential still cannot tell you

A verified credential establishes integrity and attribution: these statements came from this signer, and the file has not changed since. It does not establish that the statements are accurate, that the signer is honest, or that the scene depicted actually happened.

A camera manufacturer can sign a photograph of a screen showing a fabricated image. The credential will validate perfectly. Everything it says — captured with a camera, at this time, by this device — will be technically true, and the resulting picture will still be misleading.

Provenance narrows the questions you have to ask. It does not answer them. Use it alongside source verification, reverse image search, and ordinary editorial judgement.

Frequently asked questions

Which file formats can this C2PA checker read?

JPEG, PNG, and WebP up to 25 MB. These are the formats where embedded manifest support is most consistent in the browser SDK. Video, audio, and PDF provenance exist in the specification but are not enabled here yet.

Is my image uploaded anywhere during validation?

No. There is no upload endpoint on this site. The file is opened through the browser's file API and passed to a WebAssembly validator running in a worker inside your tab. The bytes never cross the network.

What does 'validation problem' mean if I trust the source?

It usually means the file was re-encoded or edited after signing, or that the signing certificate is not on the trust list this validator uses. Check the specific issue code in the evidence panel before treating it as evidence of tampering.

Can a C2PA credential be faked?

A signature cannot be forged without the private key, and altered bytes break the hard binding. But someone can legitimately sign a claim containing false statements, and a credential can be stripped entirely. Validation proves integrity and attribution, not truthfulness.

Why does my camera photo have no credential?

Most cameras still do not write C2PA data, and those that do often require it to be switched on. Editing software, exports, and sharing platforms then remove what is there. A missing credential is unremarkable.

Does a credential prove the image is not AI-generated?

No. It reports what the signer declared. If the declared digital source type indicates generative output, that is a positive signal that AI was involved. If the credential is absent, you have learned nothing either way.

Primary sources

The technical claims on this page follow the published specifications below rather than our own assertions.

Keep going