Etoolio

Content Credentials Inspector

Free Content Credentials inspector. Upload an image, video or audio file to read its C2PA provenance, whether it was AI-generated or edited, which tool made it, and who signed it. 100% in your browser.

Drop an image, video or audio file here

or click to choose a file — it never leaves your device

What the Content Credentials Inspector does

This tool reads the C2PA Content Credentials embedded in an image, video or audio file and tells you what they say: whether the content was created or edited with generative AI, which software or model made it, who cryptographically signed the data, and the chain of edits along the way. Everything happens locally in your browser through WebAssembly, so the file you check never leaves your device.

Why this matters now

As AI-generated media becomes indistinguishable from real photos, provenance is the practical way to answer "was this made by AI?". Content Credentials are the industry answer, an open standard from the C2PA (backed by Adobe, Microsoft, OpenAI, Google, the BBC, Sony, Nikon and others). OpenAI's image tools, Adobe Firefly and Photoshop, Google's AI edits and a growing list of cameras now attach them. New transparency rules, including the EU AI Act, are pushing adoption further.

How to use it

  • Drop a file (or click to choose) — an image, short video or audio clip.
  • Read the verdict. The tool shows whether Content Credentials were found and, if so, whether the file declares AI generation or AI editing.
  • Review the provenance — the tool that made it, the signer, the signing date, and the edit history.

How to read the result

  • AI-generated: the credentials explicitly declare the content was created with generative AI.
  • Edited with AI: the file started elsewhere but had generative-AI edits applied.
  • Content Credentials found: signed provenance exists, describing a non-AI capture or edit.
  • No Content Credentials: there is simply nothing embedded to read. This is the most common case and proves nothing on its own.

Important limits

  • Absence is not evidence. Screenshots, re-saving and many social platforms strip C2PA data, so a plain photo and an AI image can both arrive with no credentials.
  • A signature proves the signer, not the truth of every claim. It tells you who vouched for the data and whether it was tampered with, read it alongside who that signer is.
  • This is a strong signal, not a verdict machine. Use it as one input when judging whether media is authentic.

Good to know

Content Credentials Inspector, frequently asked questions

What are Content Credentials (C2PA)?

Content Credentials are tamper-evident provenance data embedded in a file using the C2PA standard. They record how a piece of content was made and edited, for example that it was generated by an AI tool or edited in Photoshop, and are cryptographically signed so the information can be trusted. OpenAI, Adobe, Google, Microsoft and several camera makers now add them.

How do I check if an image was made by AI?

Upload the image to this inspector. It reads any embedded C2PA Content Credentials and shows whether the file declares it was created or edited with generative AI, which software produced it, and who signed the credentials. The check runs entirely in your browser.

Does 'no Content Credentials' mean the image is real?

No. Most files on the internet carry no C2PA data at all, whether they are AI-generated or not, because the data can be stripped by screenshots, re-saving or social platforms. Absence of Content Credentials is not evidence either way, it simply means there is nothing to read.

Which files can I inspect?

Common images (JPG, PNG, WebP, AVIF), video (MP4) and audio (MP3, WAV) that may carry C2PA manifests. If a file has no credentials, the tool will tell you that clearly.

Is my file uploaded anywhere?

No. The entire inspection happens locally in your browser using WebAssembly. Your file never leaves your device, which matters when you are checking sensitive or private images.

Can Content Credentials be faked?

They are cryptographically signed, so tampering usually breaks the signature and shows as a validation warning. But credentials can be removed entirely, and a signature only tells you who signed it, not that every claim is true. Treat them as strong evidence, read alongside the signer's identity, not absolute proof.