Drop an image, a video or a document to see the C2PA manifest a verifier would read, then remove it in one click.
C2PA content credentials are a signed provenance record stored in a file's metadata. They sit in a metadata segment beside the media stream; in images they sit alongside EXIF and XMP. Removing the manifest clears that record and leaves every frame and pixel untouched.
C2PA stands for the Coalition for Content Provenance and Authenticity, whose members include Adobe, Microsoft, the BBC, Intel, Truepic, Sony, Google and OpenAI. The record is metadata, not a visible watermark.
An image, a clip and a PDF all carry the identical signed record. Where it sits inside the file is what decides whether an export or an upload leaves the credential intact.
JPEG, PNG, WebP, AVIF, TIFF and HEIC hold the manifest in an APP11 or equivalent metadata segment, alongside EXIF and XMP. Firefly, DALL·E, Imagen and recent Leica, Sony, Nikon and Canon bodies all sign stills this way.
MP4 and MOV keep the manifest in a JUMBF box in the container, next to the moov atom rather than inside the frames. Some workflows ship a sidecar file instead.
Signed PDFs carry the manifest as an embedded object, and MP3 and SVG use their own metadata containers. The assertions are identical, only the wrapper differs.
The generating model or camera, each editing action a supporting tool applied, and the certificate that signs the set. AI generators declare themselves as trainedAlgorithmicMedia regardless of the output format.
A re-encode or a platform re-compress usually breaks the hash binding, so the credential reads as invalid rather than absent. Editors that support the standard re-sign on export and append a new manifest to the chain.
LinkedIn, TikTok, YouTube and Meta read the manifest on upload and can label a post as AI-generated from it, without ever looking at the pixels.
The scanner above reads all of them, reports the signer, and drops the provenance data: the metadata segments are spliced out and every other byte is copied through unchanged.
A worked example of a real manifest: the claim generator, the actions, the signer and the AI declarations.
JPEG, PNG, WebP, AVIF, HEIC, GIF, MP4, MOV, MP3, SVG, HTML, Markdown, DOCX, ODT and PDF. TIFF is read-only: it is inspected but never modified.
Reading the manifest means parsing the file, so it is uploaded to be inspected and cleaned. It is processed in memory and never written to disk or kept after the response.
Metadata segments are spliced out and everything else is copied byte for byte, so images and audio come back bit-identical. Documents are the exception: those containers are rebuilt.
Five stages. Break any one of them and verification fails, which is the point: a file either carries an intact history or it does not.
A camera or an AI model creates the file and records what it did.
Each action becomes an assertion: edits, crops, AI use, training permissions.
The assertions are hashed and signed with a certificate, forming a manifest.
The manifest is written into the file, or into a store beside it.
A reader re-hashes the file. Matching hashes mean the history is intact.
This is what a reader extracts from a signed image: the tool that made the file, the actions it performed, and the certificate that vouches for both.
claim_generatorThe exact software and library version.
digitalSourceTypeDeclares the file as AI-generated media.
signature_infoIssuer, certificate serial and timestamp.
Most people meet the standard for the first time when a platform labels their upload, or when a client asks why an export mentions a generative model.
Recent Leica, Sony, Nikon and Canon bodies can sign photographs at the moment of capture.
Adobe Firefly, DALL·E, Imagen, Google Veo and other image and video generators attach credentials by default.
LinkedIn, TikTok, YouTube and Meta read credentials on upload and can label a photo or a clip as AI-generated.
Photoshop, Lightroom, Premiere and other supporting apps extend the manifest on every export.
Provenance data is useful in journalism and evidence work. In commercial production it is often unwanted detail travelling with a deliverable.
A manifest lists every tool and version you used. Most delivery contracts do not require that.
Credentials can carry device identifiers, timestamps and account details you did not intend to share.
A file touched by an AI-assisted filter can be labelled AI-generated even when the work is your own photograph.
Stale manifests break verification after ordinary re-encoding, which looks worse than no manifest at all.
JPEG · PNG · WebP · AVIF · HEIC · GIF
Manifest, EXIF and XMP spliced out; every other byte copied unchanged
MP4 · MOV · M4V
Manifest box neutralised in place, stream untouched
PDF · MP3 · SVG · DOCX · ODT
Provenance and document properties removed
It is an open standard that lets a file carry a signed record of how it was made. Software that supports the standard can read that record and show the file's history, or warn that the history is missing.
Inspect the C2PA manifest in an image, video or document, then remove it in one click.
Open the C2PA remover