Provenance

C2PA & Content Credentials viewer

Content Credentials are signed records of how a file was made and edited. Drop any image, video or audio file to read its manifest — the signer, the tools, every recorded action and whether generative AI was involved.

Free · no sign-up · your file never leaves your device

Drop a file to read its Content Credentials

JPEG · PNG · WebP · HEIC · AVIF · MP4 · MOV · WAV · MP3 · .c2pa

What the viewer shows

Signed by
The organisation and certificate name from the signer’s X.509 certificate — for example Adobe, OpenAI, Microsoft, Google, Leica or Truepic — and the certificate’s validity dates.
Claim generator
The software that wrote the manifest, such as a version of Photoshop, ChatGPT or a camera’s firmware.
Actions
What was done to the content: created, opened, edited, cropped, color_adjustments, placed and so on, each with the tool that did it and, where recorded, the IPTC digital source type that says whether a camera, a person or a generative model produced it.
Assertions
The labelled statements bundled with the manifest: hashes that bind it to the file, thumbnails, creative-work metadata, ingredients and training-and-mining preferences.
History
Earlier manifests carried as ingredients, newest first, so you can follow the chain of edits.

How it reads the file — locally

The viewer is written from scratch to run in your browser. It finds the JUMBF box structure that holds the manifest store in each container format, walks the boxes, decodes the CBOR-encoded claim and assertions, and extracts the signer’s certificate from the COSE signature. Nothing is uploaded, which matters for unpublished photos and confidential documents.

Because it does not validate signatures, treat a manifest as a claim about the file rather than a guarantee. A manifest that names a trusted signer and matches the file’s visible history is strong evidence; a manifest signed by an unfamiliar certificate deserves the same scepticism as any other unverified metadata.

Credentials and AI detection

When a manifest records generation by a trained model, GPTTrace’s image, video and audio detectors use it as proof of AI origin. When it records a camera capture, they treat it as strong evidence of authenticity. Most files you encounter still have no credentials at all — that is normal, and it is why the detectors also examine metadata and content. Learn more in What is C2PA?

When you’ll see Content Credentials

Credentials appear most often in images straight from ChatGPT, Adobe Firefly, Photoshop exports with credentials enabled, Microsoft Designer, and photos from cameras and phones that support them, such as recent Leica, Sony, Nikon and Google Pixel models. News organisations that sign their photos are another source. You are unlikely to find them in images saved from social networks or messaging apps.

Frequently asked questions

Which file types can carry Content Credentials?
The C2PA specification defines where the manifest goes in JPEG (APP11 segments), PNG (a caBX chunk), WebP, AVIF and HEIC, MP4 and MOV video, WAV and MP3 audio, PDF and others. A manifest can also be stored in a separate .c2pa sidecar file or in the cloud, referenced from the file.
Does this viewer verify the signature?
No. It parses the manifest structure and reads the signing certificate to show who signed it, but it does not cryptographically validate the signature or recompute the file hash. For a fully validated report use the official Content Credentials Verify site.
Why does my photo from a C2PA camera show nothing?
The credential may have been removed by editing or exporting software, by a messaging app, or by the camera’s transfer app. Check the original file from the memory card or the camera’s own download option.
What does “ingredient” mean?
When a credentialed file is edited, the new manifest lists the previous version as an ingredient and carries its manifest along. Reading the chain tells you the history: for example, captured by a camera, then cropped in Lightroom, then extended with Generative Fill.
Can Content Credentials be faked?
Anyone can create a manifest and sign it with their own certificate. What can’t easily be faked is a valid signature from a trusted certificate such as Adobe’s or OpenAI’s. That is why the signer matters — and why full validation is worth doing for important files.