Cryptographic provenance check

C2PA Viewer

Drop one image, video, audio file, or PDF. Get a clear credential result and the evidence behind it.

SupportedImages · Video · Audio · PDF
File bytes stay in this tab.
Waiting for a file
Official verifier · local runDrop a file with Content Credentials

Images · Video · Audio · PDF · images and RAW up to 50 MB · everything else up to 100 MB

No image handy? Try a sample.

Adobe · CC BY-SA 4.0 · Source and license

How to act on this result

  • Understand a valid result

    A valid binding connects a signed claim to these file bytes; it does not prove the scene is true. This local verifier makes no external trust-list or revocation request, so those checks can remain not checked.

  • Interpret missing credentials

    No readable credential may mean the file was never signed, lost its credential on export or uses an unsupported structure. Keep those cases separate from a failed signature check.

01 / OPEN STANDARD

What is C2PA?

C2PA is an open technical standard for recording where digital content came from and how it changed. A credential can name the tool that created a file, the edits that followed, and the source material used along the way.

The history lives in a signed manifest embedded in, or associated with, the asset. This page reads embedded credentials only. It does not contact a remote manifest service, trust list, or certificate revocation service.

Plenty of genuine files have no C2PA data. “Nothing found” means exactly that—not “fake,” “AI,” or “untrustworthy.”

02 / CONTENT CREDENTIALS

Content Credentials and C2PA

Content Credentials are the public-facing name for C2PA provenance—think of them as a nutrition label for a digital file. They can list creation and editing actions, ingredients, software, dates, and the signer responsible for the claim.

Unlike ordinary EXIF or XMP labels, the claim is cryptographically signed and bound to a specific asset. Change protected bytes or the credential and validation should fail. Remove the credential and this local verifier can no longer inspect it.

A valid result proves that the credential still binds to this file. It does not prove that every statement, sound, or visible scene is true.

03 / INPUTS

Supported files

Real file signatures are checked before the official browser verifier starts.

Images
JPEG, PNG, WebP, GIF, TIFF, HEIC, HEIF, AVIF, JXL, DNG, ARW, NEF, SVG
Video
MP4, MOV, AVI
Audio
MP3, M4A, WAV
Document
PDF
KEEP THE CAVEAT

Frequently asked questions

What does Valid mean?

The manifest is well formed, its signature validates, and its signed content binding matches this exact file. Publisher trust is a separate result.

Why is publisher trust Not checked?

This privacy-first page makes no external trust-list, remote-manifest, or OCSP request. Use another conforming validator when you need a current online publisher-trust decision.

What does No Content Credentials mean?

No embedded C2PA manifest was detected. Many genuine files have no credential, so absence is not a fake-content verdict.

Which file formats can I check?

JPEG, PNG, WebP, GIF, TIFF, HEIC, HEIF, AVIF, JXL, DNG, ARW, NEF, SVG, MP4, MOV, AVI, MP3, M4A, WAV, and PDF are accepted after their real file signatures are checked.

Is my file uploaded?

No. The official verifier runs in a browser Worker. The source bytes, filename, fingerprint, and manifest values are not posted to a server or stored in a history.

Can C2PA prove that content is true?

No. A valid result proves that a signed credential still binds to this file. It cannot prove that every claim, sound, or visible scene is factually true.