Free tool

C2PA and Content Credentials checker

Read and verify the C2PA metadata inside a video or image: what it declares about AI involvement, who signed it, and whether anything has changed since. Your file never leaves your browser.

Auf Deutsch lesen

Check a file

MP4 and MOV video, JPEG, PNG and WebP images. The check runs entirely in your browser.

What a result actually tells you

A Content Credential is a signed statement a file makes about itself. That is a narrower thing than "was this made with AI", and the difference matters.

What the file declares
The manifest names the digital source type — fully AI-generated, contains AI-generated elements, camera capture, and so on — plus the tool that produced it. This is the file’s own account of how it was made.
Who signed it
Every manifest is signed by a certificate. The checker shows the signer, the issuer, and whether that certificate appears on the C2PA known-signer list, which is how you tell a claim from a credible claim.
Whether it is intact
The signature is verified against the manifest, so an edited declaration shows as invalid rather than passing silently. The media hash is recomputed too, which catches the other half: a file edited after signing, or a manifest copied across from a different file entirely.
What no credential means
Absence proves nothing. Most files carry no manifest at all, and a manifest can be stripped by any tool that re-encodes the file. "No Content Credentials" means the file makes no statement either way — not that it was made without AI.

What Content Credentials are

Content Credentials are the user-facing name for C2PA, an open provenance standard from the Coalition for Content Provenance and Authenticity. A C2PA manifest is a block of signed metadata embedded in the file itself, recording what produced it, what was done to it, and who vouches for that record.

The signature is what separates this from ordinary metadata. Anyone can write an EXIF tag; a C2PA manifest is signed by a certificate, so an altered claim fails verification instead of passing quietly. That is why platforms can act on it automatically — Meta, TikTok, LinkedIn and OpenAI all read these signals on upload.

What this tool checks

It runs the C2PA reference implementation in your browser, so the result is a full validation rather than a reading. It verifies that the manifest is intact and signed by the certificate it carries, recomputes the media hash for video and images alike, and checks whether that certificate chains to the C2PA trust list. The media hash is the check that matters most: it proves the manifest belongs to this particular file rather than having been copied onto it from another. A signature alone cannot tell you that, because it covers the declaration and never touches the pixels.

What none of it establishes is whether the declaration is *true*. A signer can sign an inaccurate claim; what these checks settle is who made the claim, and that nothing has changed since. Read a green result as verified provenance, not as proof that a file is what it says it is.

Can it tell whether an image is AI-generated?

Only when the file says so. A Content Credential is the file’s own signed declaration, so this checker answers a narrower question than AI-image detectors do: does this image or video declare that it was AI-generated, and who vouches for that? Generators such as Adobe Firefly and OpenAI’s image generation write that declaration at export. When it is present it is the strongest answer available, because it is signed rather than inferred from the pixels.

When it is absent, nothing follows. A screenshot, a re-encode or a platform that strips metadata on upload all remove the manifest, and many generators never write one. Detectors that judge the pixels return a probability rather than a record, and invisible watermarks such as Google’s SynthID are a separate mechanism this tool does not read.

Why advertisers are suddenly asked about this

Article 50(2) of the EU AI Act requires AI-generated audio, image, video and text to be marked in a machine-readable format. That duty falls on the provider of the AI tool rather than on the advertiser running the ad — but it is the advertiser who gets asked whether an asset carries the mark. A separate duty, Article 50(4), covers the visible label a viewer can see.

Read the Article 50 explainer

FAQs

Questions about Content Credentials

Is my file uploaded anywhere?

No. The whole check — including recomputing the media hash over the file — runs locally in your browser, and nothing is sent to our servers. That is also why the first file takes a moment: the validator itself has to load before it can run.

Which file types can carry Content Credentials?

This checker reads MP4 and MOV video and JPEG, PNG and WebP images. The C2PA specification covers more formats than that — including AVIF, HEIC, WAV, MP3, PDF and SVG — so a file this tool declines can still carry a manifest.

How do I check a file’s C2PA metadata?

Drop it on the checker at the top of this page. If the file carries a manifest you see what it declares about AI, who signed it and whether it is intact; if it carries none, you are told that instead. On the command line, the C2PA project’s own c2patool reads the same manifest.

Why does my exported ad have no Content Credentials?

Most editing and export pipelines do not write them, and any step that re-encodes a file without preserving the manifest strips whatever was there. Credentials have to be applied at export by a tool that signs them; they cannot be reconstructed afterwards, because the signature is over the content as it was at signing time.

Does a Content Credential mean AI was used?

Not by itself. A credential records how a file was made, which may be a plain camera capture. What matters is the digital source type it declares: this checker translates that token into plain language — fully AI-generated, contains AI-generated elements, camera capture, and the rest.

Can Content Credentials be faked or removed?

Removed, easily — re-encoding a file usually drops the manifest, and that is why absence proves nothing. Faked, not really: the manifest is signed, so altering it invalidates the signature. What a bad actor can do is sign a false claim with their own certificate, which is what the known-signer list is for.

What is the difference between a C2PA viewer and a checker?

A viewer displays what a manifest records. A checker also validates it: the signature, the signing certificate, and whether the media hash still matches the file. This tool does both — the summary gives the answer, and the full fields behind it show the producer, signer, issuer, signing time and author.

Does this satisfy the EU AI Act for me?

This is a reading tool, not a compliance record. It tells you what a given file declares. Applying the machine-readable mark is the AI tool provider’s duty under Article 50(2), and any visible label under Article 50(4) is the advertiser’s.

Provenance belongs in the export

Solid detects, declares and cryptographically signs AI provenance on every exported asset, and reads existing C2PA metadata on upload so generated material is recognised on the way in. Nobody has to check files by hand afterwards.

Solid is AI video ad production for performance teams. Brands including Waterdrop, Refurbed and HOLY use it to scale their best-performing ads.

Supported by

Google
ElevenLabs
OpenAI
Meta Business Partner
Epidemic Sound
Anthropic