Trusted
The signature is valid, the image still matches what was signed, and the certificate chains to the official C2PA trust list (for example Google LLC or OpenAI).
Free C2PA verification
Content Credentials are the C2PA standard’s signed “nutrition label” for media: who made a file, with which tool, and what was done to it. This checker reads the manifest with the official c2pa-rs library, validates its signature against the C2PA trust list and highlights any generative AI step — including a declared SynthID watermark.
Strictly Prohibits Adult/NSFW ContentJPEG, PNG, WebP, AVIF or HEIC · up to 20 MB · use the original download, not a screenshot
The free check reads the file on our server and discards it. Nothing is stored.
Reading the result
The signature is valid, the image still matches what was signed, and the certificate chains to the official C2PA trust list (for example Google LLC or OpenAI).
The signature and content hashes check out, but the signer is not on the C2PA trust list. The claim is intact; who made it needs your judgement.
The manifest is present but the image or the manifest changed after signing — a hash mismatch or a broken signature. Treat every claim in it as unverified.
The file has no C2PA manifest. That is normal for screenshots, most social media downloads and cameras without Content Credentials support.
C2PA basics
Content Credentials are a manifest embedded in the file and signed with an X.509 certificate. The manifest lists assertions — for example c2pa.created with the IPTC source type trainedAlgorithmicMedia for an AI image, or c2pa.edited for later changes — plus hashes that bind those assertions to the exact pixels. If one byte of the image changes without a new signature, validation fails.
Google, OpenAI, Adobe, Microsoft, Leica, Nikon, Sony and many platforms now sign Content Credentials. Google’s manifests also state when an imperceptible SynthID watermark was applied, which is why the SynthID Detector reads them first.
Credentials live next to the pixels, not inside them. Screenshots, many photo editors, messaging apps and most social networks re-encode images and drop the manifest. When nothing is found, check the pixel watermark with Google’s official detector or run an AI visual analysis from the report above. Learn more in What is SynthID?