Image Tools
C2PA Checker
Drop an image to read its Content Credentials — the signed manifest that records which app created the file, when, and whether AI generation was declared. Free, in-browser, no sign-in.
What the viewer shows
Signer and issuer
Who signed the manifest — e.g. Google LLC for Gemini and Imagen output. A valid signature ties the claim to a real organisation.
Claim generator (app)
The software that wrote the claim — Google's manifests say 'Google Media Processing Services'; other tools name their own app.
Actions and AI declarations
What happened to the file — created, edited, or AI-generated via a digitalSourceType like trainedAlgorithmicMedia or compositeWithTrainedAlgorithmicMedia.
Ingredients
The source files folded into this one — useful when an AI edit of a real photo declares the original as an ingredient.
Validation state
Whether the signature checks out — valid, invalid signature, untrusted signer, or manifest removed after it was stripped.
How to check Content Credentials
Get the original file
Use the downloaded original — screenshots and most social re-uploads have the manifest stripped, leaving nothing to read.
Drop it into the checker
JPG, PNG or WebP up to 10 MB — the manifest is read locally in your browser and never uploaded.
Read the credential row
The report shows whether a manifest exists and, when connected, its signer, app, actions and validation state.
No credential ≠ no AI
Most AI generators don't write credentials at all. For pixel-level evidence, use the AI Image Detector — and confirm Google output in Google's SynthID Detector.
Who writes C2PA today
Gemini, Imagen and Veo outputs sign C2PA manifests; Pixel camera photos can carry credentials too.
OpenAI
ChatGPT and API-generated images ship with Content Credentials.
Adobe
Firefly outputs and Photoshop files saved with Content Credentials enabled.
Microsoft
Bing Image Creator and Designer outputs.
Cameras
Some Leica, Sony and Nikon models sign photos in-camera — credentials work for real photos too.
C2PA vs SynthID
| Content Credentials (C2PA) | SynthID watermark | |
|---|---|---|
| What it is | Signed metadata manifest | Invisible pixel-level watermark |
| Survives screenshots and re-uploads | No — metadata is stripped | Often — it lives in the pixels |
| Who can read it | Anyone — open standard | Only Google's detector |
| This site checks it | Yes — free, in your browser | No — we link to Google's detector |
Where it helps
Verifying a source's file
A signed manifest from a camera or a known AI tool is evidence either way — check before you publish.
Auditing your own exports
Confirm the tool you used actually embedded credentials before distributing the file.
Reading AI declarations
See exactly which action a manifest declared — fully AI-generated or a composite edit.
Limits
No manifest means nothing to read
Generators that don't write C2PA — and files stripped of it — show no credential. Use the pixel scan on the AI Image Detector instead.
Credentials can lie by omission
A manifest is a claim made by its signer. A valid signature proves who signed, not that the claim is complete.
Removed manifests leave a trace
If a file was signed and the manifest was later stripped, validators can report 'manifest removed' — a different signal than 'never signed'.
C2PA Checker FAQ
Is the C2PA checker free?
Yes — it runs entirely in your browser with no sign-in. The file is never uploaded.
What's the difference between C2PA and SynthID?
C2PA is a signed metadata manifest anyone can read — but it strips off in screenshots and re-uploads. SynthID is an invisible watermark in the pixels that often survives — but only Google's detector can read it.
Why does my image show no credentials?
The generator may not write C2PA, or the manifest was stripped by a screenshot, re-save or social upload. 'Not found' doesn't mean the image is human-made.
What does digitalSourceType tell me?
It records how the content was made — trainedAlgorithmicMedia means AI-generated, compositeWithTrainedAlgorithmicMedia means a mix of real and AI content.
Can a fake credential fool the checker?
A signature that doesn't validate or comes from an untrusted signer is flagged in the validation state — that's the point of signed manifests.