C2PA checker for Content Credentials changes
Compare original and edited JPEG or PNG files to see whether embedded C2PA provenance survived.
Your inputs stay in this tab. Processing runs locally; nothing is uploaded or saved to browser storage.
Nothing processed yet.
Exact outgoing report
No output yet.
Check whether Content Credentials survived an edit
This C2PA checker compares the embedded provenance records in two images. Use an original image and the version you plan to share to inspect whether a readable record remains and how the offline validation results differ.
- Choose the original JPEG or PNG and the edited image, each up to 20 MB.
- Select Compare credentials. The page loads its validator from QuietUtils and processes the images locally.
- Read the state for each file: absent, valid under offline settings, invalid, or unavailable. Review the comparison and validation codes.
- Download the report if you need a record of the comparison. Review it before sharing because provenance records can contain identifying details.
Does the same manifest mean the edit preserved validity?
No. Two images can carry the same active manifest label while producing different validation results. Compare both results. An editing application may also create a new record, so different labels do not automatically indicate a problem.
Can this tell whether an image is AI-generated?
It cannot establish that from the presence or absence of credentials. An absent embedded record says nothing about human or AI authorship. Declared editing actions are claims in the record, not independent observations. Remote manifests, online trust lists and revocation refresh are disabled.
Compare versions after compressing an image, removing image metadata or redacting a screenshot. Use this to inspect what happened to the credentials, rather than assuming that every export preserves them.
What this does not prove
No credentials does not mean human-made or AI-made. Validation uses the local C2PA SDK with remote manifests, network revocation and trust-list fetching disabled. Cryptographic validity is not identity trust or proof that a depicted event happened. Remote-only manifests, unsupported formats and parsing failures are not reported as valid.