C2PA Content Credentials Inspector — Check Media Provenance
Inspect images and videos for C2PA Content Credentials, provenance markers and editing metadata. Local structural check; not a cryptographic certification.
Files stay in your browser. Structural inspection only.
Content Credentials help people understand where digital media came from and how it was edited. This guide explains C2PA, what this browser inspector can detect, how to interpret the result, and why missing metadata does not prove that a file is fake.
What is C2PA?
C2PA is an open technical standard for establishing the origin and edit history of digital content. A C2PA manifest can be attached to an image, video or other media and can describe the creator, tools, actions and assertions associated with that asset. The idea is similar to a nutrition label for media: it gives viewers more context without claiming that every fact about the world can be proven by one file.
What are Content Credentials?
Content Credentials are the user-facing concept built around C2PA manifests. When a compatible camera, editing application or publishing service signs an asset, it can preserve a record of provenance. A viewer can inspect that record and see whether the credential is present, whether the signature is intact and which actions are described. Credentials are not a magic “real or fake” button. They are evidence about a file’s declared history.
How to use this inspector
Choose an image or video and let the browser perform a local structural inspection. The MVP looks for readable C2PA, Content Credentials, manifest, XMP, Adobe and provenance markers, then displays the file type, size and detected strings. It does not upload the media. It also does not claim to perform a full cryptographic trust-chain validation. Use the result as a fast triage step, then use a full C2PA verifier when a legal, editorial or forensic decision depends on authenticity.
What FOUND means
FOUND means that the file contains readable markers associated with provenance or Content Credentials. It is a useful signal that the file may carry a manifest or related metadata. It is not proof that every assertion is valid, that the signer is trusted, or that the content was not copied into another file. A full verifier should validate signatures, certificates, timestamps and the chain of trust.
What NONE means
NONE means that this lightweight scan did not find readable markers in the inspected bytes. Metadata may have been stripped by a social platform, the manifest may be stored in a format this MVP does not parse, or the file may genuinely have no Content Credentials. NONE does not prove manipulation, and FOUND does not prove truth. Always consider the source, context and independent evidence.
Privacy and limitations
The tool is intentionally local and privacy-first. It is suitable for quick inspection of public or personal media, but do not treat it as a forensic laboratory. Some containers compress, encrypt or store metadata in structures that require specialized parsers. A screenshot may preserve visual appearance while removing provenance. Conversely, a valid credential describes the signed asset and its declared history; it does not certify every real-world claim made by the image.
A practical editorial workflow
Keep the original file and record its hash when chain of custody matters. Inspect the credential, compare the declared actions with the visual result, check the signer and verify the trust chain with a dedicated implementation. Ask who supplied the file, when it was received and whether a platform recompressed it. Use C2PA as one evidence layer alongside source verification, reverse-image research and human review.
How provenance fits into a media workflow
Provenance is most useful when it is captured early and preserved through the workflow. If a photographer or creator exports a file without credentials, a publisher may be unable to reconstruct the complete history later. Teams should decide which applications sign content, who is trusted to make assertions, and how credentials are checked before publication. A newsroom can record the original delivery, inspect the manifest, compare the declared edit actions with the final image and retain a copy of the verification result. A brand can use provenance to document approved campaign assets and reduce confusion when a file is resized or republished.
Remember that provenance and truth are related but different. A signed file can honestly describe that an application made an edit, while the underlying caption or real-world claim may still be wrong. Likewise, an unsigned file may be authentic but may have lost its metadata during export. The right practice is layered verification: inspect credentials, confirm the source, look for independent evidence and document uncertainty.
Interpreting provenance with confidence
When a file is moved between applications, exported for the web or uploaded to a platform, metadata can be transformed or removed. That is why a provenance review should always record the exact file that was inspected, the tool version used and the time of the check. If a platform creates a new derivative, inspect that derivative separately rather than assuming that the original credential survives. For sensitive work, retain the original delivery and avoid editing it before verification. Creators can also use Content Credentials proactively. Add a clear description of the editing steps, identify the tools that made material changes and avoid adding assertions that cannot be supported. Publishers should show readers where the credential was found and explain the difference between a declared action and an independently verified fact. This transparency makes provenance useful without presenting it as an infallible truth machine.
Frequently Asked Questions
Does missing C2PA prove a file is fake?
No. It only means that this scan did not find readable provenance markers. Metadata may have been removed or stored in an unsupported structure.
Does FOUND prove the content is true?
No. It indicates markers were detected. A full verifier must validate signatures and trust, and people must still evaluate the claims.
Are my files uploaded?
No. This MVP reads the selected file in your browser.
Can it verify a legal dispute?
No. Use a dedicated cryptographic verifier and qualified forensic or legal review for high-stakes decisions.
What formats are supported?
The browser can inspect common image and video files, but the depth of metadata detection depends on the container and how it was exported.
Content Credentials help people understand where digital media came from and how it was edited. This guide explains C2PA, what this browser inspector can detect, how to interpret the result, and why missing metadata does not prove that a file is fake.
What is C2PA?
C2PA is an open technical standard for establishing the origin and edit history of digital content. A C2PA manifest can be attached to an image, video or other media and can describe the creator, tools, actions and assertions associated with that asset. The idea is similar to a nutrition label for media: it gives viewers more context without claiming that every fact about the world can be proven by one file.
What are Content Credentials?
Content Credentials are the user-facing concept built around C2PA manifests. When a compatible camera, editing application or publishing service signs an asset, it can preserve a record of provenance. A viewer can inspect that record and see whether the credential is present, whether the signature is intact and which actions are described. Credentials are not a magic “real or fake” button. They are evidence about a file’s declared history.
How to use this inspector
Choose an image or video and let the browser perform a local structural inspection. The MVP looks for readable C2PA, Content Credentials, manifest, XMP, Adobe and provenance markers, then displays the file type, size and detected strings. It does not upload the media. It also does not claim to perform a full cryptographic trust-chain validation. Use the result as a fast triage step, then use a full C2PA verifier when a legal, editorial or forensic decision depends on authenticity.
What FOUND means
FOUND means that the file contains readable markers associated with provenance or Content Credentials. It is a useful signal that the file may carry a manifest or related metadata. It is not proof that every assertion is valid, that the signer is trusted, or that the content was not copied into another file. A full verifier should validate signatures, certificates, timestamps and the chain of trust.
What NONE means
NONE means that this lightweight scan did not find readable markers in the inspected bytes. Metadata may have been stripped by a social platform, the manifest may be stored in a format this MVP does not parse, or the file may genuinely have no Content Credentials. NONE does not prove manipulation, and FOUND does not prove truth. Always consider the source, context and independent evidence.
Privacy and limitations
The tool is intentionally local and privacy-first. It is suitable for quick inspection of public or personal media, but do not treat it as a forensic laboratory. Some containers compress, encrypt or store metadata in structures that require specialized parsers. A screenshot may preserve visual appearance while removing provenance. Conversely, a valid credential describes the signed asset and its declared history; it does not certify every real-world claim made by the image.
A practical editorial workflow
Keep the original file and record its hash when chain of custody matters. Inspect the credential, compare the declared actions with the visual result, check the signer and verify the trust chain with a dedicated implementation. Ask who supplied the file, when it was received and whether a platform recompressed it. Use C2PA as one evidence layer alongside source verification, reverse-image research and human review.
Frequently Asked Questions
Does missing C2PA prove a file is fake?
No. It only means that this scan did not find readable provenance markers. Metadata may have been removed or stored in an unsupported structure.
Does FOUND prove the content is true?
No. It indicates markers were detected. A full verifier must validate signatures and trust, and people must still evaluate the claims.
Are my files uploaded?
No. This MVP reads the selected file in your browser.
Can it verify a legal dispute?
No. Use a dedicated cryptographic verifier and qualified forensic or legal review for high-stakes decisions.
What formats are supported?
The browser can inspect common image and video files, but the depth of metadata detection depends on the container and how it was exported.