How the content credentials inspector works
After you select Inspect image, the official C2PA Web SDK reads the file in a browser worker and verifies its embedded manifest, content binding, signature, and available trust state. A separate local parser organizes EXIF, IPTC-IIM, XMP, ICC, TIFF, and format-header fields. Remote manifests and online certificate revocation requests are disabled so the selected file and its embedded URLs are not sent to another service.
evidence report = C2PA validation + embedded image metadataA valid credential confirms that signed provenance data remains bound to the file; it does not prove that every claim or visible scene is true.
Review an image that declares generative AI use
An image may contain a valid C2PA manifest with a Created action, a claim generator, a signer, and the IPTC digital source type Created using generative AI. The inspector shows the validation state separately from the AI disclosure, then lists rights, creator, camera, editing software, and GPS fields when those values are embedded.
Reading the evidence report
Read credential validation, AI disclosures, attribution, rights, capture, and privacy fields as separate signals. Save the JSON report when a technical record is useful.
const reader = await c2pa.reader.fromBlob(file.type, file);
const store = reader ? await reader.manifestStore() : null;
await reader?.free();if (!store) return 'No credentials found';
if (store.validation_state === 'Trusted') return 'Trusted credentials';
if (store.validation_state === 'Valid') return 'Valid signature';
return 'Review validation failures';Using the result accurately
Start with the original file because screenshots, social platforms, recompression, and metadata-stripping exports can remove credentials and other fields. Read Trusted, Valid, and Invalid states carefully; compare the signer, actions, dates, source types, rights information, and known source context. Check the privacy result before sharing an image that may contain location data.
Content Credentials are tamper-evident provenance claims, not a truth detector. A trusted signature does not guarantee that the depicted scene or every assertion is accurate, while missing credentials or metadata do not prove that an image is fake, real, human-made, or AI-generated. This local mode does not fetch remote manifests or perform live OCSP revocation checks.
References: C2PA Technical Specification: validation states and process · IPTC Photo Metadata Standard 2025.1 · Google Search Central: image metadata in Google Images.