No upload, 100% local, no account

Content Credentials (C2PA) reader

Drop a file to read its C2PA provenance manifest, if any. Everything stays on your device.

How Content Credentials (C2PA) reader works

C2PA reader parses the Content Credentials manifest embedded in an image or media file and displays what the manifest declares, in your browser, without uploading the file anywhere. When credentials are present, the tool shows the signing entity, the timestamp of signing, the tool or device used, and any declared editing actions such as crop, filter or generative fill. Validation confirms the manifest's cryptographic signature is intact at the time of reading.

Important limits: this tool reports only the signals that are actually in the file. If no C2PA manifest is found, it means the file does not carry Content Credentials; absence is not evidence of manipulation or AI generation. The tool does not detect AI-generated content. A valid signature confirms the manifest has not been altered since it was signed; it does not certify that the image content itself is authentic or accurate.

How to use Content Credentials (C2PA) reader, step by step

  1. Drop an image (JPEG, PNG, HEIC, WebP) or media file that may carry Content Credentials onto the upload area.
  2. The tool parses any embedded C2PA manifest and displays the signing entity, timestamp, declared tool and editing actions.
  3. Review the declared actions log to see what the manifest records about the file's history.
  4. Note whether the cryptographic signature validates correctly or shows a mismatch warning.

Common use cases

  • Journalism verification: check whether a source image carries Content Credentials from a known camera or wire service before publishing.
  • Photo agency workflow: verify that images submitted with C2PA assertions from partner photographers have intact signatures.
  • Content platform audit: inspect the declared editing history of an image before displaying it on a platform that surfaces provenance data.
  • Research: explore what data fields different cameras, phones and AI generators record in their C2PA manifests.

Frequently asked questions

What exactly is stored inside a C2PA manifest?

A C2PA manifest can include: the identity of the signing entity (camera manufacturer, software publisher or platform), a cryptographic hash of the asset at the time of signing, the signing timestamp, the tool or device that generated the credentials, and a log of declared editing actions (such as crop, colour adjustment or generative fill). The content of any manifest depends entirely on what the creator's tool chose to record and sign; there is no mandatory minimum.

If a file has no C2PA manifest, does that mean it was manipulated?

No. The vast majority of images on the internet were created or processed by tools that do not add C2PA credentials. Absence of a manifest says nothing about whether the image is authentic, altered or AI-generated. It simply means the file was not processed by a C2PA-enabled tool, or that the credentials were stripped during a later step.

Can the C2PA reader confirm whether an image was created by an AI generator?

Only if the AI generator added and signed a specific assertion to that effect in the manifest. Some generators do record an 'ai.generated' assertion in their C2PA manifest. But the absence of that assertion cannot be treated as proof that the image was not AI-generated. The tool reads and displays what is declared; it does not make independent judgements about content.

What does signature validation actually verify?

Validation checks that the cryptographic signature in the manifest is mathematically consistent with the content at the time of reading. A valid signature means the manifest has not been altered since it was signed. It does not guarantee the image content is accurate or that the declared editing actions are complete; the signing party controls what is recorded.

Does the C2PA reader send my file to a server to parse the manifest?

No. The manifest is parsed by a JavaScript library running in your browser tab. Your file is read into local memory, the C2PA data structure is decoded there, and nothing is transmitted to Sunasty's servers or any third party. The file does not leave your device at any point during inspection.

Which file formats can carry C2PA Content Credentials?

C2PA credentials can be embedded in JPEG, PNG, HEIC, WebP, MP4 and PDF files, among others. The standard is format-agnostic, but adoption varies: most consumer cameras and some AI image generators currently produce JPEG with embedded manifests. WebP and HEIC support is growing as platforms add it.