Free C2PA viewer and Content Credentials checker
Drop in a file and read its Content Credentials: what made it, what was done to it, whether generative AI was declared, who sealed it. No sign up, and nothing leaves the browser.
What C2PA is
C2PA is an open technical standard for content provenance, written by the Coalition for Content Provenance and Authenticity, a joint effort of Adobe, the BBC, Google, Intel, Microsoft, OpenAI, Sony, Truepic and others. It answers one question: where does this file come from, and what happened to it along the way.
When a camera, an editing tool or a generative model supports the standard, it writes a manifest inside the file. The manifest records who produced the content, which software was used, which edits were applied, which earlier files were reused as ingredients, and whether generative AI was involved. That manifest is then sealed with a certificate, so any later change to the file can be detected. The user facing name of this data is Content Credentials.
The standard is spreading fast because it answers a practical need: telling apart a photograph, an edited image and a synthetic one, at scale and without guesswork. C2PA is also one of the technical routes the market is taking towards the transparency duties introduced by the EU AI Act for AI generated content.
How to check the Content Credentials of a file
Choose a file, of any type the standard covers, and the whole analysis runs inside the browser: no upload, no queue, no account. When a manifest is there, the viewer lists the declared title and format, the tool that produced the file, the edit history, the source files it was built from, any declared use of generative AI, the certificate holder, the algorithm and the timestamp, plus every assertion carried in the manifest. It also recomputes the signature over the manifest, so a manifest that no longer matches its own seal is reported as invalid.
What it does not do
- It does not decide whether the signer deserves trust: it reads the certificate inside the file, it does not look it up in any trust list and it does not check revocation.
- It does not verify the pixels: C2PA covers the declared history of a file, not whether what the image shows really happened.
- A file with no Content Credentials is not a suspicious file. Most platforms strip this data on upload, and most devices never write it.
Is this C2PA viewer really free?
Yes. There is no account, no upload, no quota and no watermark on the result. The page runs entirely in the browser, which is also why it costs nothing to run.
Are my files uploaded anywhere?
No. The file is read in the browser with the local file APIs. It is never sent to a server, ours or anyone else's, so confidential material can be inspected safely.
Which file types are supported?
Every container the standard defines for an embedded manifest: images (JPEG, PNG, WebP, GIF, TIFF and DNG, JPEG XL, SVG), video (MP4, MOV, HEIC, AVIF), audio (MP3, WAV, FLAC, Ogg), documents (PDF, and the ZIP based formats such as EPUB, DOCX, XLSX, PPTX, ODF and OpenXPS), OpenType and TrueType fonts, HTML pages, plus standalone .c2pa manifest files.
What is the difference between C2PA and Content Credentials?
C2PA is the technical standard, and also the name of the coalition that maintains it. Content Credentials is the name the same data takes when it is shown to a reader: the small icon on a picture, the panel that opens when the icon is clicked. A file carrying Content Credentials is a file carrying a C2PA manifest, so a C2PA viewer and a Content Credentials checker are the same tool under two names.
Can Content Credentials be removed from a file?
Yes, and without any special effort. The manifest lives inside the file, so anything that rewrites the file can drop it: a screenshot, an export from another program, a recompression, or an upload to a platform that strips metadata. Nothing in the standard prevents this, and nothing in the file records that it happened. That is why provenance carried by the file alone cannot be the last word when the file has to be relied on.
Can this tell whether an image was generated by AI?
Only when the file says so itself. Several generative tools write a C2PA manifest declaring that the content was produced or altered by a model, and the viewer shows that declaration whenever it is present. The reverse does not hold: no Content Credentials means no declaration was found in the file, not that the image is a photograph. This reads what a file declares about itself, it is not an AI image detector.
Which cameras, phones and apps write Content Credentials?
On the capture side, Leica, Sony, Nikon, Canon and Fujifilm ship or have announced bodies that seal an image at the shutter, and the same capability has reached mobile chipsets. On the software side, Adobe Photoshop, Lightroom and Firefly, Microsoft Designer, the image models of OpenAI and of Google, plus a growing set of newsroom, stock and publishing platforms. Support is still uneven and often off by default, which is why most files in circulation carry nothing at all.
Why does a photo I know is genuine show no Content Credentials?
Because provenance data has to be written at capture or at export, and then survive every step afterwards. Social platforms and messaging apps usually strip it when a file is uploaded or recompressed.
Does a valid C2PA manifest prove the image is true?
No. It proves the file carries a declaration that has not been altered since it was sealed. Whether that declaration is accurate depends on who made it, which is why the identity behind the certificate matters as much as the manifest.
Read further
When the file has to hold up as evidence
C2PA travels with the file and is easily stripped along the way, and it says nothing about the device, the moment and the context of capture. When a file has to stand up in a dispute, an audit or a courtroom, that is not enough. TrueScreen supports C2PA and goes further: forensic acquisition, device and network data, qualified timestamp and a complete chain of custody, on any digital content.
Discover TrueScreen