How to verify where an image or video came from
6 min read
Step 1: open the file
On the home page, drop a file or choose one. It is parsed locally in your browser and never uploaded. For files on the web, switch to "From URL" and paste a direct link.
Step 2: read the verdict
- Green · signer trusted: signature, hash and certificate chain all pass, and the certificate is on a trust list.
- Yellow · valid signature, signer not on a trust list: unchanged since signing, but the signer's identity cannot be confirmed (test certificates, individual signers, newer vendors).
- Red · failed validation: changed after signing, or damaged credentials. Open "Validation" for the exact failures.
- Grey · no credentials: the file contains no C2PA data.
Step 3: check the signer and software
"Signed by" is the name on the signing certificate — e.g. Adobe Firefly, a camera maker or a platform. "Software" is the tool that wrote the manifest. Together they tell you who issued the credential.
Step 4: check for AI generation
A source type of "AI-generated (trained model)" means the creator declared the asset as generative-AI output; "Composite with AI-generated content" means only part of it is.
Step 5: review actions and ingredients
Actions list what happened — created, opened, cropped, color adjusted and so on. Ingredients list the parent version or components used; they may carry their own credentials, so you can trace the history back step by step.
Step 6: keep a record
"Export report" produces a one-page report you can print or save as PDF. For files checked from a URL, "Copy share link" gives a link that re-verifies automatically when opened.