filesaudit.com

9/6/2026

How to Check C2PA Content Credentials of an Image Online

C2PA Content Credentials are an open standard for documenting the origin and history of a digital asset, and checking them on an image is now a routine step for anyone who needs to understand provenance rather than just trust a caption. The Coalition for Content Provenance and Authenticity, a group that includes Adobe, Microsoft, BBC, The New York Times and others, designed C2PA so that cameras, editing tools and generative systems can embed a cryptographically signed manifest inside a file. That manifest is not a watermark you can see, it is structured metadata that travels with the image and records who created it, what tools were used, and which edits were made afterwards. Learning how to check C2PA Content Credentials of an image is therefore less about visual inspection and more about reading the embedded manifest and verifying the signatures that protect it.

A C2PA manifest is essentially a signed data structure that lives in the file’s metadata container, most commonly in JPEG, PNG, HEIC and RAW formats that support XMP. Inside the manifest you will find assertions about the asset creation, the software that rendered or edited it, and a chain of custody that links each step. The manifest includes a cryptographic hash of the image bytes, so any change to the pixels invalidates the binding unless the change was made by a C2PA-aware tool that re-signs the manifest. The signatures are issued by the creators or tools using private keys, and the public keys are referenced in the manifest so a verifier can check validity without contacting a central server. This is why verification is technical and evidence-based: you are not being told what is true in a legal sense, you are being shown whether the file contains a valid, intact manifest signed by identified parties and whether the image data matches that manifest.

Because the credentials are embedded, you can lose them easily. Exporting to a format that does not support C2PA, running the image through a social media compressor, screenshotting, or editing in an application that does not preserve the manifest will strip or break the credentials. That is an important practical reality when you check an image you received from a third party. A missing manifest does not prove manipulation, it only proves the provenance chain is no longer present. A present but invalid manifest does not prove malicious intent, it proves the file was altered in a way the signing workflow did not anticipate.

There are several ways to inspect C2PA credentials depending on your workflow and how much detail you need. Adobe Photoshop and Lightroom can display Content Credentials in the Properties panel when a file is opened, and Adobe’s open source tools such as the C2PA reference verifier let developers inspect manifests programmatically. Browser-based viewers are beginning to surface C2PA indicators for images published with credentials intact. For a quick, file-level check without installing software, uploading the image to a forensic metadata service is the most accessible approach. Services like FilesAudit extract the embedded metadata, compute cryptographic hashes such as SHA-256, MD5 and CRC32, and surface any C2PA provenance evidence found in the file alongside EXIF, XMP and IPTC fields. You can upload and analyze a file on FilesAudit from the FilesAudit homepage and receive a professional PDF report that documents what was found at the time of inspection, including timestamp documentation for your records.

When you review a C2PA report, focus on a few concrete fields rather than trying to interpret the whole manifest at once. First look for the presence of a valid C2PA manifest and whether the signature verification status is valid, invalid or missing. A valid signature means the manifest was signed and the image hash matches the signed hash. Next check the assertion list: creation assertion typically shows the originating device or application, such as a specific camera model or a generative AI model name and version. Editing assertions show a timeline of modifications, for example “cropped in Adobe Photoshop 26.0” with a timestamp. The provenance chain shows the sequence of actors, and the signing certificate information identifies who signed each step. If the image is claimed to be AI-generated, the manifest should contain a generation assertion with model details and the entity that produced it. This is the technical information C2PA provides. It does not by itself establish legal ownership, authorship disputes, or whether the depicted scene is real, it only documents the technical chain recorded at signing time.

It is also useful to compare what C2PA can show with what traditional metadata shows. EXIF data from a camera can tell you lens, exposure and GPS, but EXIF is easily edited and is not cryptographically bound to the pixels. C2PA binds the manifest to the image via hashing and signatures, so tampering with pixels without re-signing will break verification. That distinction matters in journalism, digital investigations and compliance workflows where you need evidence of integrity, not just descriptive tags. For a deeper forensic picture, you will typically want both: the descriptive metadata from EXIF/GPS/XMP/IPTC and the integrity evidence from hashes and C2PA signatures. This is why platforms that support 200+ file types are important, because the same provenance concepts apply across images, video, audio and documents, and the format support determines whether the manifest can even be read.

A common practical example is a journalist receiving an image from a source. The first step is to keep the original file untouched and create a working copy for inspection. Upload the original to a verifier and check whether a C2PA manifest is present and valid. If the manifest shows creation by a known camera with a consistent timestamp and no unexplained edits, you have technical documentation to support your handling of the asset. If the manifest is missing, note that in your records and rely on other verification steps such as reverse image search and source corroboration. If the manifest indicates AI generation, you can report that fact with the specific model name recorded in the assertion rather than speculating. The report you generate becomes part of your documentation trail, and the cryptographic hashes you obtain at ingestion let you prove later that the file you analyzed has not been changed.

Lawyers and rights holders use a similar workflow for copyright disputes and intellectual property audits. The presence of a valid C2PA chain does not prove ownership, but it does provide a timestamped technical record of who signed the manifest and when, and which tools were involved. Combined with

Ready to see what's hidden in your own files? Upload a file to FilesAudit and get a free forensic metadata report in seconds — no registration required.