Runs on your device — images are never uploaded

Content Credentials (C2PA) checker — is this image AI-generated?

Drop an image to read its Content Credentials: which tool made it, whether AI was declared, and whether the signature is valid. Free, unlimited, and nothing is uploaded.

How do you check whether an image is AI-generated?

Open the image in a Content Credentials (C2PA) reader and read its signed manifest. If the image came from an AI tool that supports the standard, the manifest names the generator and records that AI was involved — the strongest evidence currently available. StaysPrivate reads the manifest in your browser using the official C2PA library, so the image is never uploaded. Credentials cannot prove the opposite, though: social platforms strip them on upload and any non-C2PA editor drops them on re-save, so treat "no credentials" as unknown, never as "authentic".

Drop an image here or click to choose — JPEG, PNG, WebP, AVIF, TIFF, MP4

Which AI image generators add Content Credentials?

Support is uneven, and that unevenness is the whole reason a missing credential proves nothing. Checked August 2026 — this landscape changes often, so verify against the vendor's own documentation for anything that matters.

GeneratorC2PA manifestOther marking
OpenAI — DALL·E 3, ChatGPT images, SoraYes—
Adobe FireflyYes — since launch, 2023—
Google — Gemini, ImagenYesSynthID invisible watermark
Microsoft Designer / Bing Image CreatorYes—
MidjourneyNo—
Stable Diffusion (run locally)No—

The pattern: the large hosted services sign their output, while Midjourney and locally-run open models generally do not. An image with no manifest may simply have come from one of those.

Why an image with no Content Credentials might still be AI-generated

Manifests are fragile. All of these remove them:

  • Social platforms. Instagram, Facebook, X and TikTok re-encode uploads, which usually discards the manifest.
  • Screenshots. A screenshot is a brand-new image with no provenance at all — the most common way credentials vanish.
  • Ordinary editing. Any tool that does not support C2PA drops the manifest when it saves.
  • Messaging apps. WhatsApp and similar apps compress images on send.
  • Deliberate removal. Re-saving through almost any converter strips it, intentionally or not.

So credentials are useful as positive evidence and nearly worthless as negative evidence. A verified manifest saying "made with Firefly" is strong. Silence means nothing.

Content Credentials vs SynthID vs EXIF vs visible watermarks

Content Credentials (C2PA)SynthIDEXIF metadataVisible watermark
What it isSigned provenance recordInvisible pixel watermarkCamera/edit metadataMark drawn on the image
Cryptographically signedYesNoNoNo
Survives re-encodingOften notUsuallyOften notYes
Survives a screenshotNoOftenNoYes
Who can check itAnyone, with a readerGoogle's detectorAnyoneAnyone, by eye
Can be forgedNot without the private keyHardTriviallyTrivially

What the EU AI Act requires from 2 August 2026

Article 50 of the EU AI Act (Regulation 2024/1689) applies from 2 August 2026. Providers of generative AI systems must mark synthetic image, audio, video and text output in a machine-readable way, and deployers must disclose deep fakes. C2PA manifests are one of the accepted ways to satisfy the machine-readable marking requirement, which is a large part of why the major providers adopted it. Penalties for non-compliance run into the millions of euros or a percentage of worldwide turnover.

This matters for the strip function on this page: removing credentials from your own photo to protect your privacy is reasonable. Removing them to pass AI-generated content off as real is exactly what the regulation targets — don't.

How to read a Content Credentials manifest

When a manifest is present, these are the fields worth understanding:

  • Claim generator — the software that produced or last signed the file.
  • Signature issuer — who vouches for it, and whether the signature validates.
  • Actions — what was done: c2pa.created, c2pa.edited, c2pa.published.
  • digitalSourceType: trainedAlgorithmicMedia — the field that literally means "generated by an AI model". This is the specific marker to look for.
  • Ingredients — earlier files used to make this one, each with its own provenance.

What to do when an image has no credentials

  • Reverse image search it to find earlier copies and the original context.
  • For suspected Google-model output, Google's SynthID detection can find its watermark even after re-encoding.
  • Ask the sender for the original file straight from the camera or tool — provenance usually survives one hop.
  • Check ordinary EXIF metadata for a camera make and model (easily faked, but its absence is a hint).
  • Cross-check with the official verifiers: contentcredentials.org/verify and OpenAI's own verification page. Both upload the image to their servers — which is the difference with this tool, not a reason to avoid them.

Does this checker upload my image?

No. Verification runs entirely in your browser via the official C2PA library compiled to WebAssembly — load the page, disconnect from the network, and it still reads manifests. Most online checkers, including the official verify page, process server-side. That distinction matters if you are a journalist handling source material, a legal team reviewing evidence, or anyone checking unpublished work.

Frequently asked questions

What are Content Credentials (C2PA)?

Content Credentials are a tamper-evident record attached to an image showing where it came from — which camera or app made it, whether AI was involved, and what edits were applied. They follow the C2PA standard backed by Adobe, Google, Microsoft, Samsung, OpenAI and others.

Does this prove an image is AI-generated?

Only if the creator attached credentials. OpenAI, Adobe Firefly, Google and Microsoft sign their AI output, so a manifest declaring AI involvement is strong evidence. But the absence of credentials proves nothing — Midjourney and locally-run models do not add them, and social platforms, screenshots and ordinary editing all strip them. Treat "no credentials" as "unknown", not "authentic".

What is the difference between Content Credentials and SynthID?

Content Credentials are a cryptographically signed record attached to the file, readable by anyone with a C2PA reader but easily lost when the file is re-encoded. SynthID is Google’s invisible watermark embedded in the pixels themselves — it survives re-encoding and often screenshots, but only Google’s detector can read it. Google applies both to its own image models.

Are my images uploaded anywhere?

No. Verification runs entirely in your browser using the official C2PA library compiled to WebAssembly. Your images never touch a server — useful when you are checking sensitive or unpublished material.

Why would I remove Content Credentials?

Credentials can contain your name, software, device and edit history. If you are publishing anonymously or sharing a photo where that trail is private, stripping it is reasonable. Note the EU AI Act requires AI-generated content to remain marked in many commercial contexts — do not strip credentials to disguise AI content.

Which file types work?

JPEG, PNG, WebP, AVIF, TIFF and common video and audio formats can carry credentials. Drop any of them to inspect; stripping is available for JPEG and PNG images.

Last updated: