EvidPicRUImage checker

File provenance check

Check C2PA Content Credentials

Does this image carry Content Credentials? Check its signature, connection to the file, and signer.

Check an image

Selecting an image starts a server check. Privacy policy.

01 / The useful bit

What is C2PA, in plain English?

C2PA stands for Coalition for Content Provenance and Authenticity. It develops a standard for recording the history of digital content. Content Credentials are provenance records built on that standard. The signed record is called a manifest.

The comments are arguing: real photo or AI? C2PA cannot answer that from a missing mark. Content Credentials are signed information embedded in a file, recording actions, software, and signer details.

Think of it as a signed receipt attached to the file: it helps trace a record, but does not independently verify the event in the image. A screenshot, export, or forwarded copy can lose credentials.

02 / Read the separate checks

A valid signature is not the whole story

Manifest state

This is the summary result for structure and integrity. An invalid manifest matters even when a separate signature check looks good; the asset itself may not match the recorded binding.

Signature and asset binding

The signature covers a claim. The binding checks whether that claim belongs with this file. They are deliberately not rolled into one reassuring badge.

Certificate trust

A signing certificate can be outside the pinned trust list. In that case the signature may still be readable, while trust in the signing chain remains a separate result.

03 / Boundaries

What this checker does not do

It reads only an embedded manifest. The C2PA SDK does not fetch remote manifests and network OCSP checks are disabled; certificate trust uses a pinned trust list.

A signer is not necessarily the image creator: they sign a claim. The certificate issuer is the organization that issued that certificate, not the author. A valid manifest does not prove the event, authorship, or rights.

04 / FAQ

Common questions

Why is “not found” not an AI verdict?

C2PA is an optional embedded record. It may never have been added, may be removed while sharing, or may not be supported by the tool that produced the image.

Why can a signature be valid while the manifest is invalid?

Manifest validation includes more than the signature: asset binding, assertion integrity, time conditions, and other results. One passing check does not erase the others.

What happens to my upload?

The temporary check file is deleted after processing. Read the privacy terms before uploading.

Upload processing

The image is uploaded to the server for checking. The service processes the original file, filename, metadata and technical request details. See the privacy policy for details.

For more detail: C2PA FAQ, the specification explainer, and the official Verify tool.