C2PA Content Credentials Check
Check whether and by whom an image was signed with C2PA Content Credentials, locally in your browser without external services.
Your inputs are processed in your browser and are not transmitted to our servers. Note: third-party resources (e.g. advertising and analytics from Google/Cloudflare) and an optional PayPal donation link may transfer data when loading or when clicked. Browser extensions or plugins may be able to read content that is visible in the input fields.
The result will appear here …
How to use this tool (video)
This video is hosted on YouTube. When you play it, data may be sent to Google.
C2PA Content Credentials Check: verify an image signature
The content credentials checker reads the C2PA manifest of an image and shows whether and by whom it was signed. C2PA (Coalition for Content Provenance and Authenticity) is an open standard that makes the provenance and editing of an image cryptographically traceable. The tool rates the result in four states: trusted, valid but not trusted, not verifiable, or no manifest present.
What the checker shows
- Signature status: "Trusted", "Valid, but not trusted", "Not verifiable" or "No Content Credentials".
- Software: what created or edited the image (the generator claim).
- Signature details: signer, certificate issuer, signing algorithm and signing time.
- Edit history: input and parent files when the manifest contains ingredients.
- Validation notes from the C2PA verifier as technical detail.
Note: "Valid, but not trusted" does not automatically mean forgery. It only means the signer is not on the C2PA trust list, for example for self-signed manifests or manifests from unrecognised sources. "Not verifiable" can also result from a harmless later edit such as cropping, because C2PA binds the signature tightly to the image data.
The check runs entirely in your browser using the official C2PA web library. The image file is not sent to any server and is never stored. The tool only reads and verifies, it does not create or sign content credentials.
Frequently asked questions
What is C2PA?
C2PA stands for Coalition for Content Provenance and Authenticity. It is an open industry standard that appends a cryptographically signed provenance and editing history to images. Adobe calls this "Content Credentials".
Are my images uploaded?
No. The check runs entirely in your browser using the official C2PA web library. The image file never leaves your device.
What does "Valid, but not trusted" mean?
The signature is cryptographically correct and the file has not been altered since signing. However, the issuer is not on the C2PA trust list, for example because the certificate is not from an accredited provider. This is not proof of forgery.
Why is an image "Not verifiable"?
The signature is then invalid or the file was altered after signing. Because C2PA binds the signature tightly to pixels and metadata, even a small edit such as cropping or recompressing breaks it. That can be tampering, but also a harmless later change.
Can the tool detect AI images?
No. C2PA verifies provenance and editing but does not detect generative AI content. A missing manifest does not mean an image is AI-generated, and a present manifest does not prove an image has no AI parts.