Skip to content

C2PA checker

Check a file for an embedded C2PA manifest.

Drag and drop, or select a file

JPEG, PNG, WebP, AVIF, HEIC — up to 4 MB

You can also paste an image from your clipboard.

About this check

What C2PA is

An open standard from the Coalition for Content Provenance and Authenticity. It attaches a signed manifest to a file recording how it was created and what was done to it since. Because the manifest is cryptographically signed, a valid one is genuinely strong evidence — unlike metadata, it cannot be quietly rewritten.

What we report

Whether a manifest store is embedded, and in which carrier — a JUMBF box in JPEG, a caBX chunk in PNG, a dedicated UUID box in MP4. Presence is established locally and reliably. Validating the signature chain against the C2PA trust list is a separate step, so a found manifest is labelled 'present, not validated' rather than overstated.

Reading the result

A manifest tells you what the file claims about itself, signed by whoever signed it. It does not by itself mean AI was involved: cameras and editing software issue credentials too, and disclosed AI use is an ordinary, often required, entry in the chain.