How-to

How to remove C2PA Content Credentials from an image

Where the manifest lives in JPEG, PNG and WebP, the free command that deletes it, and what stays behind after it has gone.

Updated 24 September 2026

A C2PA manifest is a block of bytes in a known place: an APP11 segment in a JPEG, a caBX chunk in a PNG, a chunk named C2PA in a WebP. Delete that block and the Content Credentials are gone. Nothing in the picture has to change, and a tool that decodes and re-saves your image to do it is doing more damage than the job needs.

Where the manifest sits, and what else goes with it

The table is what our own cleaner does, read from its source code. Other tools draw the line in other places, which is why two “metadata removers” can give you files of different sizes from the same input.

What the WipeTheAI cleaner removes and keeps in each format, as of 24 September 2026
FormatContent CredentialsAlso removedKept
JPEGAPP11 segments carrying JUMBF boxesEXIF and XMP (APP1), IPTC (APP13), picture info (APP12), commentsJFIF header, ICC colour profile (APP2), Adobe colour transform (APP14), the rotation flag on its own, and every byte from the start of scan to the end of the file, copied unchanged
PNGcaBX chunktEXt, zTXt and iTXt text (where Stable Diffusion and ComfyUI write prompts), eXIf, tIME, unknown ancillary chunksImage data, palette, transparency (tRNS), gamma, chromaticity, sRGB, ICC and HDR colour chunks, pixel density, APNG frames
WebPC2PA chunkEXIF, XMP and Photoshop (PSAI) chunks, with the EXIF and XMP flags cleared in the VP8X headerVP8 or VP8L image data, alpha, animation frames, ICC profile

The colour chunks stay on purpose. A photo tagged Display P3 that loses its ICC profile gets read as sRGB, and saturated reds and greens go flat. ExifTool’s documentation warns about the same thing, as the section below shows.

That table is the cleaning step, and it runs first in the Wipe tool. Both wipe modes then change the pixels and save a new file, so what you download from a wipe is never the cleaned original byte for byte. If the manifest is all you want gone, our free Content Credentials remover runs that step alone and hands the file back without touching the picture.

20 files with Content Credentials, before and after

On 24 September 2026 we ran that remover in Chromium on every public file with a manifest we could find in an afternoon: ChatGPT and Adobe Firefly pictures from Wikimedia Commons, a Google image, three Photoshop generative edits (two of them of Nikon D4 photos), the Nikon Z 9 and Truepic camera samples from the C2PA public test files, and four test files from the c2pa-rs project. For each one we decoded the original and the output to raw pixels and compared them, then read the output again with the same code as our Is this image AI? check.

Content Credentials removed by our free tool, 24 September 2026 (7 of the 20 files; sizes in bytes)
FileMade byBeforeManifestAfterPixels
Coruscant.pngChatGPT1,746,29378,937 (4.5%)1,667,356identical
Clubberbes.pngGoogle1,216,46422,866 (1.9%)1,193,598identical
Firefly landscape (JPEG)Adobe Firefly844,288269,593 (31.9%)574,695identical
Bentley 4.5 Litre (JPEG)Photoshop edit of a Nikon D4 photo7,228,57813,391 (0.2%)7,183,437identical
nikon-20221019-buildingNikon Z 91,530,098238,404 (15.6%)1,192,366identical
truepic-20230212-cameraTruepic camera app2,261,231192,699 (8.5%)2,054,953identical
exp-test1.png (c2pa-rs)Photoshop5,884,4393,439,701 (58.5%)2,444,293identical

All 20 manifests came off, and the read-back found no manifest in any output. All 20 pictures decoded to the same pixels, bit for bit. The “After” size is smaller than “Before” minus the manifest on the Bentley photo because its EXIF, IPTC and XMP came off too: the tool removes every metadata block, and the list it shows says which. The camera files lost their EXIF the same way; the Truepic one kept only its rotation flag, so it still shows upright.

Manifest size varies more than we expected. The seven ChatGPT PNGs carried 47,844 to 78,937 bytes each, a few percent of the file. The three Firefly JPEGs carried a third of their file, split over three to five APP11 segments because one JPEG segment holds at most 64 KB. The Photoshop test PNG was more than half manifest. The three Photoshop-edited JPEGs had exactly 13,391 bytes each.

We found no public WebP with a manifest in it. The two WebPs in the c2pa-rs test folder carry none, so the WebP row in the first table rests on our synthetic test, not on a real file.

What testing the remover cost us

Building test files for it turned up a bug in the cleaner that the Wipe tool and our EXIF remover share. It treated the PNG tRNS chunk as disposable metadata. That chunk holds the transparency of palette and colour-key PNGs, so on the c2pa-rs file libpng-test_with_url.png the old cleaner changed 3,656 of its 6,279 pixels: every see-through pixel turned solid. It keeps tRNS now, along with the HDR colour chunks cICP, mDCV and cLLI, and it also removes the PSAI chunk Photoshop writes into WebP files, which it used to leave behind. Both have tests now.

We shipped the WebP case wrong

Until 23 September 2026 our WebP cleaner looked for a chunk called JUMB. JUMBF is the box format inside a manifest, so the guess sounded right. It isn’t: section A.3.6 of the C2PA specification puts the manifest store of any RIFF file, WebP included, in a chunk named C2PA. Any WebP with Content Credentials went through our cleaner with its manifest intact, and our tests passed because none of them had a WebP manifest in it. There is a test for it now.

The lesson we took from it is narrow. Check the output, not the tool’s report of what it did, whichever tool you use.

You can do this for free with ExifTool

If you are happy in a terminal, you don’t need us for this part. ExifTool deletes the JUMBF group, which is where C2PA lives, with exiftool -jumbf:all= photo.jpg, and it keeps a copy of the original next to it. The broader exiftool -all= photo.jpg removes every metadata group it can write. ExifTool’s own documentation warns that this also removes colour space information, so colours may shift unless you copy those tags back, and that it leaves the Adobe APP14 segment alone by default for the same reason.

Paying anyone for C2PA removal alone is hard to justify when that command exists, which is why our remover is free. What it adds is the before and after list for people who would rather not read tag dumps, and the colour profile left in place.

What deleting the manifest leaves behind

The pixels. Google’s SynthID and similar invisible watermarks live in the image itself, so they survive any metadata edit. OpenAI announced in May 2026 that its images carry SynthID as well. The SynthID guide covers what that mark is and why a screenshot can leave it in place.

A copy can also exist away from your file. Adobe says Content Credentials for Firefly images may be stored in its public Content Credentials cloud, and the C2PA design allows a manifest to be recovered through a watermark or a fingerprint lookup after the embedded copy is gone. We haven’t tested how often a stripped image gets matched back that way, and we don’t know of anyone who has published figures on it.

Firefly output comes with a rule as well. Adobe’s Generative AI User Guidelines say “You must not remove, alter, or disable any Content Credentials,” so deleting the manifest from those images goes against Adobe’s terms, whichever tool does it.

Checking your result

Scan the cleaned file, not the original. In WipeTheAI the result panel re-reads the output and shows its signals next to the input’s, so a manifest that survived shows up as still present. With ExifTool, exiftool -G1 -a -s cleaned.jpg lists every tag left, grouped by where it lives. Other ways to check, including the public Content Credentials inspection site, are in how to check an image for Content Credentials.

Sources

  1. C2PA public test files (Nikon Z 9 and Truepic samples)
  2. c2pa-rs test fixtures (C.jpg, CA.jpg, exp-test1.png, libpng-test_with_url.png)
  3. Wikimedia Commons: Images generated by GPT Image 1
  4. Wikimedia Commons: Images generated by Adobe Firefly AI
  5. Wikimedia Commons: Clubberbes.png (Google C2PA)
  6. C2PA Technical Specification 2.2, Appendix A (embedding manifests)
  7. ExifTool application documentation (-all= and colour space tags)
  8. ExifInjector: removing C2PA with ExifTool (-jumbf:all=)
  9. Adobe: Content Credentials in Firefly
  10. Adobe Generative AI User Guidelines
  11. PetaPixel: OpenAI adds SynthID to its images (20 May 2026)