C2PA Validator

Upload an original image or video to inspect Content Credentials, signature validity, digital source type, claim generator, assertions, ingredient chain, certificate details, and validation issues.

Upload a file to validate C2PA

How to use

  1. Use the closest available copy to the platform export.
  2. Read signature state first, then digitalSourceType, claim_generator, and validation issues.
  3. Copy or export raw JSON when you need an audit trail.

Field meanings

Signature and trustSeparates trusted, valid, invalid, and unsigned states.
ManifestShows title, format, claim generator, digital source type, and assertions.
Certificate and ingredientsDisplays issuer, signing time, algorithm, and upstream assets.

Scope and limits

  • No C2PA does not prove that a file is camera-made.
  • Exports, compression, screenshots, and transcoding can remove credentials.
  • A valid signature may still use a signer that is not in this engine’s trust list.

FAQ

Does no manifest mean the image is real?

No. It only means this copy has no readable C2PA manifest.

What is the difference between valid and trusted?

Both may be cryptographically valid; trusted additionally means the signer is in the active trust list.

Is the file uploaded?

No. Verification runs locally with WebAssembly.

Related tools and guides