Content provenance & inspection
Content provenance & evidence inspector
Check an image's C2PA credentials locally, or get a cloud report on whether it declares AI generation, bound to its exact bytes.
Developer API and webhooks →Local
Read the credential in this tab
Local checks run entirely in your browser; images never upload.
Bundle
Verify a saved Evidence Bundle
Import a bundle and the original image. AIPwn recomputes SHA-256 locally and compares the exact bytes; nothing is uploaded.
Examples
What a report looks like
No signed file to hand? These are two hand-written example records, not generated from real files: one credential intact, one whose image bytes changed after signing.
Signature valid, signer in the trust list
The manifest hash matches the file bytes and the certificate chains to a trusted root. The claims inside it are still claims.
- manifest
- found
- data_hash
- match
- signature
- valid
- trust_root
- in trust list
- claim_generator
- Example Editor 2.1
Edit history (as claimed)
c2pa.createdInitial asset recordedc2pa.color_adjustmentsTone and colour adjustedc2pa.croppedCropped before export
Try this
Which of these two files carries a C2PA credential?
The plates are the same on purpose. Pick one anyway.
Cloud
Cloud inspection and API
Reads the AI-generation declarations vendors embed in their images (C2PA and IPTC source type) in milliseconds. Reports keep digests only; one credit per inspection.
Each successful cloud analysis costs 1 credit ($0.01 per credit); failed requests are never charged.
You can also drag an image into this area.
Automate it
The same inspection is available over an authenticated REST API and platform-signed bot webhooks.
Boundaries
Evidence and trust boundaries
What this tool can report
- Whether an embedded C2PA manifest exists
- Its local validation and trust state
- The SHA-256 of the exact inspected bytes
What this tool cannot determine
- Whether uncredentialed content came from AI or a human
- Whether an uncredentialed image was altered
- The real-world identity of an untrusted signer
- Model authorship or watermarks without reference keys