Test a Photo's C2PA Content Credentials

Drop in a photo to test it for C2PA Content Credentials: who signed it, which software touched it, whether AI was involved, and whether the credentials are still intact. No signed photo at hand? Grab our C2PA test image below.

Your photo is analyzed entirely in your browser, it is never uploaded.

C2PA test photos

Inspect a prepared test image in one click, or download it to test your own validator, plugin or workflow.

Download

How to test a photo for C2PA

  1. 1

    Drop the photo into the tester above. It is analyzed locally in your browser with the official C2PA library, nothing is uploaded.

  2. 2

    Read the verdict: whether a manifest was found, who signed it, which edits were recorded, whether generative AI was involved, and whether the signature is still intact.

  3. 3

    No signed photo of your own? Use the C2PA test image in the gallery above, or download it to run a known-good file through any other validator.

Testing at scale? The same checks run headless with the open-source c2patool CLI, and the Lumethic API adds forensic verification for photos that carry no credentials at all.

What the test photo should show

Use this table to check any C2PA validator against our test file. A correct implementation reports the following:

Test fileCredentialsExpected result
c2pa-sample.jpgValid, intact signatureSigned by "C2PA Test Signing Cert", one ingredient, and a recorded edit history (opened, colour adjustments). Verdict: signed, but edited after capture.

This is a standard test image produced with the official c2pa-rs toolchain. Further test cases, AI-generated, tampered after signing, and credential-free control files, will be added to this set.

How the inspector works

1

Drop a photo

Pick any image file from your device. Nothing is uploaded, the analysis runs locally in your browser using the official C2PA library.

2

We read the manifest

The inspector decodes the embedded C2PA manifest, checks the cryptographic signature and validates that the image still matches what was signed.

3

Get the full report

See the signer, capture and edit history, AI involvement, source ingredients and any validation problems, in plain language.

Your camera can't write Content Credentials?

Most cameras can't. Lumethic verifies your RAW originals and gives any photo a tamper-evident, shareable authenticity report, no special hardware required.

What are Content Credentials?

Content Credentials are cryptographically signed metadata based on the open C2PA standard (Coalition for Content Provenance and Authenticity), backed by Adobe, the BBC, Google, Microsoft, Sony and many others. They record who created an image, with which hardware or software, and what edits were applied, and they make any later tampering detectable.

This free tool tests any photo for those credentials and validates them, the same data that tools like Adobe's Verify site display. Learn more in our C2PA guide.

Private by design: nothing is uploaded

The inspector runs the official C2PA WebAssembly toolkit directly in your browser. Your photo never leaves your device, is never sent to our servers and is never stored anywhere. You can even use the tool offline once the page has loaded.

Why does my photo have no Content Credentials?

Don't be surprised if your photo comes back empty: the vast majority of images have no C2PA data. Credentials are only written by a handful of recent cameras and by software that explicitly supports the standard, and platforms like Instagram, WhatsApp or Facebook usually strip them during re-compression.

Want to know if your camera can sign photos at capture? Check our C2PA camera database.

Frequently asked questions

This tool validates C2PA manifests with the official Content Authenticity Initiative library. A valid signature confirms the data was not altered after signing; it does not by itself prove how a photo was originally captured.