Check what an image says about its origin
Check reads the provenance information an image carries about itself: Content Credentials (C2PA), the IPTC digital source type that marks AI-generated and AI-edited media, and the generator settings that tools such as Stable Diffusion and ComfyUI write into PNG files.
Signed Content Credentials are verified in your browser with the official C2PA SDK, which checks that the signature matches and that the image has not changed since it was signed. No trust list is downloaded and nothing is uploaded.
How to check an image
Add an image
Drop a JPEG, PNG or WebP file. Check reads it on your device.
Read the verdict
One of four verdicts, with a sentence on which parts of the file support it.
Review the details
Generating tool, signer, signing time, recorded actions, signature status and any prompt found.
The four verdicts
- Marked as AI-generated: Content Credentials or the IPTC source type say a generative model made the image, or the file holds generator settings.
- Marked as AI-edited: a generative tool changed part of the image, for example with generative fill.
- Has Content Credentials, no AI marker: a signed manifest is present and names no generative tool, as with some cameras and editing apps.
- No provenance data found: nothing in the file describes where it came from.
What metadata can and cannot prove
Metadata can be missing, removed or, when it is not signed, edited. So “No provenance data” does not mean an image is real, and Check does not use an AI classifier or look for watermarks in the pixels. A valid signed manifest is the only strong evidence. Learn more in how to check if an image is AI-generated and what Content Credentials are.
Questions about Check
Can Exifo tell me for certain whether an image is AI-generated?
No tool can from metadata alone. Check reports what the file says about itself. A valid C2PA signature is strong evidence; unsigned labels can be added or removed, and missing metadata proves nothing.
What does the signature check do?
It uses the C2PA SDK to confirm that the Content Credentials were signed by the certificate they name, and that the image and its claims have not changed since. It does not check the signer against a trust list.
Why does a signature show as invalid?
Usually because the file was changed after signing, for example re-saved, cropped or had other metadata removed. It can also mean the signature does not match the claim. Check shows the reason.
Does Check use an AI detector?
No. It only reads metadata stored in the file. It does not analyse pixels and does not detect invisible watermarks such as SynthID.