Free tool

Content Credentials checker

Read the C2PA manifest inside a video or image: what it declares about AI involvement, who signed it, and whether anything has changed since. Your file never leaves your browser.

Auf Deutsch lesen

Check a file

MP4 and MOV video, JPEG, PNG and WebP images. Of a large video only a few kilobytes are read.

What a result actually tells you

A Content Credential is a signed statement a file makes about itself. That is a narrower thing than "was this made with AI", and the difference matters.

What the file declares
The manifest names the digital source type — fully AI-generated, contains AI-generated elements, camera capture, and so on — plus the tool that produced it. This is the file’s own account of how it was made.
Who signed it
Every manifest is signed by a certificate. The checker shows the signer, the issuer, and whether that certificate appears on the C2PA known-signer list, which is how you tell a claim from a credible claim.
Whether it is intact
The signature is verified against the manifest, so an edited declaration shows as invalid rather than passing silently.
What no credential means
Absence proves nothing. Most files carry no manifest at all, and a manifest can be stripped by any tool that re-encodes the file. "No Content Credentials" means the file makes no statement either way — not that it was made without AI.

What Content Credentials are

Content Credentials are the user-facing name for C2PA, an open provenance standard from the Coalition for Content Provenance and Authenticity. A C2PA manifest is a block of signed metadata embedded in the file itself, recording what produced it, what was done to it, and who vouches for that record.

The signature is what separates this from ordinary metadata. Anyone can write an EXIF tag; a C2PA manifest is signed by a certificate, so an altered claim fails verification instead of passing quietly. That is why platforms can act on it automatically — Meta, TikTok, LinkedIn and OpenAI all read these signals on upload.

What this tool does not check

It verifies that the manifest is internally intact and signed by the certificate it carries, and it looks that certificate up on the C2PA known-signer list. It does not verify the media hash — the check that proves the manifest belongs to this particular file rather than having been copied from another one.

So read a result as the file’s own declaration about itself, checked for tampering, rather than as proof of origin. For a full verification including the media binding, use the C2PA Verify tool.

Why advertisers are suddenly asked about this

Article 50(2) of the EU AI Act requires AI-generated audio, image, video and text to be marked in a machine-readable format. That duty falls on the provider of the AI tool rather than on the advertiser running the ad — but it is the advertiser who gets asked whether an asset carries the mark. A separate duty, Article 50(4), covers the visible label a viewer can see.

Read the Article 50 explainer

FAQs

Questions about Content Credentials

Is my file uploaded anywhere?

No. The file is read in your browser and never sent to our servers. For a large video only the few kilobytes holding the manifest are read at all, which is also why the check is near-instant on a file of any size.

Which file types can carry Content Credentials?

This checker reads MP4 and MOV video and JPEG, PNG and WebP images. The C2PA specification covers more formats than that — including AVIF, HEIC, WAV, MP3, PDF and SVG — so a file this tool declines can still carry a manifest.

Why does my exported ad have no Content Credentials?

Most editing and export pipelines do not write them, and any step that re-encodes a file without preserving the manifest strips whatever was there. Credentials have to be applied at export by a tool that signs them; they cannot be reconstructed afterwards, because the signature is over the content as it was at signing time.

Does a Content Credential mean AI was used?

Not by itself. A credential records how a file was made, which may be a plain camera capture. What matters is the digital source type it declares: this checker translates that token into plain language — fully AI-generated, contains AI-generated elements, camera capture, and the rest.

Can Content Credentials be faked or removed?

Removed, easily — re-encoding a file usually drops the manifest, and that is why absence proves nothing. Faked, not really: the manifest is signed, so altering it invalidates the signature. What a bad actor can do is sign a false claim with their own certificate, which is what the known-signer list is for.

Does this satisfy the EU AI Act for me?

This is a reading tool, not a compliance record. It tells you what a given file declares. Applying the machine-readable mark is the AI tool provider’s duty under Article 50(2), and any visible label under Article 50(4) is the advertiser’s.

Provenance belongs in the export

Solid detects, declares and cryptographically signs AI provenance on every exported asset, and reads existing C2PA metadata on upload so generated material is recognised on the way in. Nobody has to check files by hand afterwards.

Solid is AI video ad production for performance teams. Brands including Waterdrop, Refurbed and HOLY use it to scale their best-performing ads.