Drop the file on Adobe’s Inspect tool at inspect.cr. If the image carries a C2PA manifest, the page shows who signed it, with what app or device, and what was done to it. If there is none, it says “No Content Credential.” (The older Verify site at contentcredentials.org/verify still answers too; it forwarded to verify.contentauthenticity.org when we checked on 23 September 2026.) That covers most people. Not everyone. The rest of this page is for when you want to see the raw record, check a batch from a terminal, or understand why two checkers disagree about the same file.
Four ways to read the record
| Checker | Setup | Checks the signature | Shows which manifest is current | Watch out for |
|---|---|---|---|---|
| Adobe Inspect | None, a web page | Yes, against the C2PA trust list | Yes, with ingredients in a tree | We couldn’t confirm where an added file goes |
| c2patool | A command-line install | Yes, against trust lists | Yes, in its JSON | Output is long, raw JSON |
| ExifTool | A command-line install | No | No | Lists every manifest flat |
| WipeTheAI signals panel | Sign in with Google | No, only whether a signature block exists | Yes, and lists earlier generators | Merges the actions of every manifest into one list |
Adobe’s Inspect tool
Inspect is Adobe’s tool, still labelled beta, and the Content Authenticity Initiative documents it alongside the open-source C2PA tools. Its documentation lists JPEG, PNG, WebP, HEIC, AVIF, TIFF, DNG, GIF and SVG among the image formats it reads, plus video, audio and PDF. You can add a file, or point it at a public URL with https://inspect.cr?source= followed by the address, as long as the host allows it. It shows the signer under “Recorded by,” the app or device, AI generation indicators, the actions, and any ingredients, and it can search Adobe’s Content Credentials cloud for content similar to those ingredients.
We couldn’t find a plain statement of what happens to an uploaded file after the check. If the picture is private, use one of the local options below.
c2patool, for the full record
c2patool is the reference command-line tool from the same project. c2patool photo.jpg prints the whole manifest store as JSON. c2patool photo.jpg --info gives a short report about the file and its C2PA data, and -d dumps the internal format for when you are debugging a manifest rather than reading one. When a claim fails validation, the JSON gets a validation_status array with one entry per problem. Its JSON names the active manifest outright, which matters more than it sounds (see the panel section).
ExifTool, if it is already installed
ExifTool has read C2PA blocks since 2021. On the two manifests we tried, these field names pulled out the useful lines:
exiftool -a -G1 -s -Claim_Generator_InfoName -ActionsAction -ActionsDigitalSourceType photo.jpg
On a Google image that printed Google C2PA Core Generator Library, the actions c2pa.created, c2pa.edited, and trainedAlgorithmicMedia. Older manifests written in JSON use different field names, so if that prints nothing, run exiftool -G1 -a -s photo.jpg and look for lines in the JUMBF and CBOR groups. Nothing in the output tells you whether the signature is valid. ExifTool is the best general metadata reader there is, and for this job we’d still rank it last of the three free options, because a file with two manifests comes out as one flat list.
The signals panel in WipeTheAI
When you add an image to the wipe tool, it reads the file on your device before anything else happens and lists what it finds under “Signals in this file.” You need to be signed in with Google to add a file. For C2PA it shows the claim generator of the current manifest, any earlier ones, the declared actions, and whether a signature block is present. It does not check that signature cryptographically; “present” means the bytes are there, not that they verify. The same panel lists the EXIF, XMP, IPTC and PNG text it would remove, which the Inspect doesn’t cover. Without an account, our free Is this image AI? check reads the same fields for several files at once, and doesn’t verify the signature either.
Testing it for this page, we found a limit in our own panel and fixed half of it. One file in our set carries two manifests: an earlier one from OpenAI Media Service API and a later Google one that lists the OpenAI image as its input. Our panel first reported the claim generator as OpenAI’s, because that is the first one in the file. The current manifest, the one describing the file you actually have, is Google’s, and the panel now says so, with OpenAI’s listed under earlier manifests. It still merges the four actions from both manifests into one line, so it can’t tell you which company declared which step. c2patool’s JSON keeps them apart and Inspect lays the ingredients out as a tree; ExifTool flattens everything.
What the fields mean
Read the claim generator first, since it names the software making the statement. Then the actions: c2pa.created means the record starts with this file, c2pa.opened means an existing file was brought in, and c2pa.edited or c2pa.converted describe what happened next. A digital source type of trainedAlgorithmicMedia on an action is the manifest saying a trained model made that content. Ingredients point at earlier files and their own manifests.
A valid signature means the record and the image bytes are unchanged since the signer signed them, and that the signer holds the certificate named. An invalid one usually means the file changed after signing. Neither says anything about whether the picture is true; the C2PA specification is explicit that it makes no judgment on that. What the fields are and where they come from is laid out in the C2PA explainer.
Sources
- Content Authenticity Initiative: using the Inspect tool
- c2patool usage documentation
- ExifTool version history (C2PA JUMBF support)
- C2PA Technical Specification 2.1
- PetaPixel: DALL-E images carry C2PA; OpenAI on screenshots and social uploads (8 February 2024)
- IPTC: Midjourney and Shutterstock adopt the Digital Source Type field