C2PA Content Credentials and Image Provenance
Some images carry provenance information about how they were created or edited. C2PA Content Credentials are one way of embedding it — used by cameras, editing apps and some AI tools alike. Check what a photo contains below.
Photo Metadata Checker — the full guide to inspecting photo metadata
Drop a photo here or choose a file
JPG, PNG or WebP · one photo at a time
Many photos?
Try the Bulk Photo CleanerNeed to clean a document? Try the Free PDF Metadata Remover →
- Private by design
- Processed locally in your browser
- No file uploads
- No file storage
What Are C2PA Content Credentials?
C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard for recording the provenance of digital content. Content Credentials are the information it produces: a set of statements about a file that can be attached to it and signed, so later tools can read them.
Depending on the credential and the tool that wrote it, it may include information relating to:
- Origin of the asset
- The creator or the tool used
- Editing history
- Software involved
- Other provenance assertions
- AI-related provenance information
- Other signed or asserted provenance data
Individual credentials contain only some of these. Pixurity detects that an embedded C2PA manifest store is present and reports its size; it does not display each assertion inside it or validate its signatures.
Are Content Credentials Proof That an Image Is AI-Generated?
No. Content Credentials are provenance information, not an AI label. Their presence doesn't automatically mean an image was entirely AI-generated — a credential might describe a camera capture, a crop in an editor, or an AI-assisted edit.
The reverse matters just as much: the absence of C2PA or other AI/provenance metadata does not prove an image was created without AI. Many tools never add it, and it is easily stripped.
Pixurity does not decide whether an image is AI-generated by visually analysing its pixels. It checks supported embedded metadata and provenance information, and reports what the file itself declares.
How Pixurity Checks AI and Provenance Metadata
- Select a photo.
- Pixurity inspects its supported metadata locally in your browser.
- It looks for supported AI/provenance indicators and embedded C2PA manifest stores.
- Anything detected appears in the AI & provenance part of the report.
- You inspect the findings before deciding whether to clean the file.
- If you clean it, Pixurity re-checks the final downloadable file against its supported metadata checks.
Detection covers the C2PA embedding formats and metadata fields Pixurity supports; it is not a guarantee for every provenance system or implementation.
What AI or Provenance Information Can a File Contain?
Where present and supported, embedded metadata may reveal:
- C2PA / Content Credentials manifest stores
- Provenance and edit-history fields
- Software or tool identifiers
- AI tool names, where explicitly stored
- Prompts or workflow settings, where explicitly embedded (common in some PNG generators)
- XMP provenance information
- IPTC digital source type, such as a value declaring algorithmic media
- Other supported provenance fields
Pixurity only shows what is written in the file. It does not reconstruct prompts, workflows or tools that are not explicitly stored there.
Is C2PA the Same as EXIF or XMP?
No. They are different things that can sit in the same file:
- EXIF commonly stores camera and image details such as device, date, settings and sometimes GPS. See what EXIF data is and how to remove it.
- XMP is an extensible metadata framework that can hold many kinds of information, including some provenance and AI-related fields.
- C2PA Content Credentials concern provenance and authenticity assertions, stored in their own structure (a manifest store) designed to be signed.
To see all three side by side for a particular photo, use the Photo Metadata Checker.
Can Pixurity Remove C2PA and AI Metadata?
Pixurity removes supported embedded metadata — including supported C2PA manifest stores, XMP, IPTC, EXIF and text fields that carry AI or prompt information — from JPG, PNG and WebP photos, then verifies the final downloadable file against its supported checks.
Removing embedded provenance metadata does not rewrite the real-world history of an image. It removes supported embedded information from the cleaned copy only. It does not make a file untraceable, and records held elsewhere (for example by a platform or provenance service) are unaffected. Location data is removed too; see removing GPS location from a photo.
Does Pixurity Upload the Image to Check C2PA Metadata?
No. Photo metadata scanning and cleaning run locally in your browser. The photo is not uploaded to Pixurity servers for either step, and the metadata detected in it is not sent there. Pixurity does use servers for optional paid accounts and payments, which never receive your files.
What Does “Cleaned & Verified” Mean?
After cleaning, Pixurity scans the final downloadable file again for the metadata and provenance structures it supports. "Cleaned & verified" means those implemented checks found nothing. It does not mean:
- proof that no unknown or proprietary metadata exists;
- proof that the image was never AI-generated;
- proof that no external provenance record exists;
- guaranteed anonymity.
Content Credentials questions
What are C2PA Content Credentials?
They are provenance information based on the C2PA standard. A credential can record statements about how a digital file was created or edited, packaged so tools can read it and, in principle, check that it hasn't been tampered with.
Are Content Credentials only used for AI-generated images?
No. Cameras, editing software and publishers can also attach them to ordinary photos and edits. An AI tool is only one possible source.
Do all AI-generated images contain C2PA metadata?
No. Many AI tools don't add Content Credentials, and credentials that were added are often lost when an image is edited, screenshotted or re-saved.
Can I check whether a photo has Content Credentials?
Yes. Add a JPG, PNG or WebP photo to the checker on this page. If it contains an embedded C2PA manifest store that Pixurity supports, the report lists it under AI & provenance.
Can Pixurity detect AI metadata?
It detects supported AI-related information that is explicitly embedded in metadata, such as AI tool names, an IPTC digital source type, prompt fields and C2PA manifest stores.
Can Pixurity tell if an image is AI-generated?
No. Pixurity does not analyse image pixels. It only reports what the file's metadata says, which may be missing, incomplete or edited.
What does it mean if no AI or C2PA metadata is found?
Only that Pixurity found no supported embedded indicators in this file. It is not evidence that the image was made without AI or never edited.
Can Pixurity remove C2PA Content Credentials?
Yes, for supported embedded manifest stores in JPG, PNG and WebP. The clean removes them with the other supported metadata, then re-checks the final file. This changes the copy you download, not the image's real history.
Can image metadata contain an AI prompt?
Sometimes. Some generators write the prompt or settings into text metadata, especially in PNG files. Pixurity shows them only when they are actually stored in the file.
Are my photos uploaded when Pixurity checks provenance metadata?
No. The check and any cleaning happen in your browser; neither the photo nor the metadata found in it is sent to Pixurity servers.
Is the C2PA metadata checker free?
Yes. Checking and cleaning single photos is free with no account.