AyeCalc
All tools
Image tools

Content Credentials & Image Metadata Inspector

Check the evidence embedded in an image without uploading it. Validate C2PA Content Credentials, review recorded provenance actions and AI source disclosures, find attribution or licensing details, and search EXIF, IPTC, XMP, ICC, and GPS metadata in one readable report.

Official C2PA validationEXIF, IPTC & XMPImage stays local
Local provenance check

Inspect an image

Image stays on device
Drop one image here

JPEG, PNG, WebP, AVIF, HEIC, HEIF, TIFF, or GIF · up to 100 MB

Browser-onlyThe selected image is not uploaded.

Cryptographic checksUses the official C2PA browser SDK.

No automatic verdictProvenance evidence is not a truth guarantee.

Core formulaevidence report = C2PA validation + embedded image metadata

A valid credential confirms that signed provenance data remains bound to the file; it does not prove that every claim or visible scene is true.

01
Method

How the content credentials inspector works

After you select Inspect image, the official C2PA Web SDK reads the file in a browser worker and verifies its embedded manifest, content binding, signature, and available trust state. A separate local parser organizes EXIF, IPTC-IIM, XMP, ICC, TIFF, and format-header fields. Remote manifests and online certificate revocation requests are disabled so the selected file and its embedded URLs are not sent to another service.

Formulaevidence report = C2PA validation + embedded image metadata

A valid credential confirms that signed provenance data remains bound to the file; it does not prove that every claim or visible scene is true.

02
Worked example

Review an image that declares generative AI use

An image may contain a valid C2PA manifest with a Created action, a claim generator, a signer, and the IPTC digital source type Created using generative AI. The inspector shows the validation state separately from the AI disclosure, then lists rights, creator, camera, editing software, and GPS fields when those values are embedded.

03
Evidence

Reading the evidence report

Read credential validation, AI disclosures, attribution, rights, capture, and privacy fields as separate signals. Save the JSON report when a technical record is useful.

Read an embedded manifest
const reader = await c2pa.reader.fromBlob(file.type, file);
const store = reader ? await reader.manifestStore() : null;
await reader?.free();
Interpret validation separately
if (!store) return 'No credentials found';
if (store.validation_state === 'Trusted') return 'Trusted credentials';
if (store.validation_state === 'Valid') return 'Valid signature';
return 'Review validation failures';
04
Practical guidance

Using the result accurately

Start with the original file because screenshots, social platforms, recompression, and metadata-stripping exports can remove credentials and other fields. Read Trusted, Valid, and Invalid states carefully; compare the signer, actions, dates, source types, rights information, and known source context. Check the privacy result before sharing an image that may contain location data.

Important limitation

Content Credentials are tamper-evident provenance claims, not a truth detector. A trusted signature does not guarantee that the depicted scene or every assertion is accurate, while missing credentials or metadata do not prove that an image is fake, real, human-made, or AI-generated. This local mode does not fetch remote manifests or perform live OCSP revocation checks.

References: C2PA Technical Specification: validation states and process · IPTC Photo Metadata Standard 2025.1 · Google Search Central: image metadata in Google Images.

Common questions

Content Credentials Inspector FAQ

Answers about the method, assumptions, and practical use.

Are images uploaded when I inspect them?

No. The selected image is read by JavaScript and WebAssembly in your browser. The inspector disables remote-manifest fetching and online certificate revocation requests, and it does not send the image to AyeCalc or an analysis API.

What does Trusted Content Credentials mean?

It means the manifest is valid and the signing credential chains to a trust anchor recognized by the validator. It authenticates the signed provenance record and its binding to the file, not the truth of everything depicted or claimed.

Does no Content Credentials mean an image is fake?

No. Adding credentials is optional, and credentials can be removed by screenshots, social platforms, format conversion, or metadata-stripping exports. No credentials found is a neutral result.

Can this inspector tell whether an image was made with AI?

It can surface an explicit C2PA or IPTC disclosure such as Created using generative AI or Edited using generative AI. If no disclosure appears, the tool cannot conclude that the image is human-made because labels may never have been added or may have been removed.

Which image metadata can I view?

The report can organize readable EXIF and TIFF capture data, IPTC attribution and rights fields, XMP namespaces, ICC color-profile information, file headers, software details, AI fields from IPTC Photo Metadata 2025.1, and GPS coordinates when present.

Which image formats are supported?

You can select JPEG, PNG, WebP, AVIF, HEIC, HEIF, TIFF, or GIF files up to 100 MB. Browser preview and the exact metadata fields available vary by format and browser support.