C2PA remover: check and remove Content Credentials
See whether a photo or video carries a C2PA manifest, what it claims, and remove it in one step. Works with JPG, PNG, WebP, MP4 and MOV, entirely in your browser.
What C2PA Content Credentials are
C2PA (the Coalition for Content Provenance and Authenticity) is an open standard for attaching a signed history to a media file. The record is called a manifest. It can say which device or app created the file, which edits were made, and whether the content is AI-generated, and it is cryptographically signed so that tampering can be detected.
Major platforms read these manifests. TikTok uses Content Credentials to automatically label AI-generated content uploaded from elsewhere (TikTok), and Meta reads the "AI generated" information in C2PA and IPTC to label images on Instagram, Facebook and Threads (Meta). Generators add them by default: OpenAI attaches C2PA metadata to images made with ChatGPT and its API (OpenAI).
Where the manifest lives in each format
| Format | Container | What we remove |
|---|---|---|
| JPEG | One or more APP11 segments holding JUMBF boxes | All APP11 segments |
| PNG | caBX chunk | The chunk (plus XMP and text chunks) |
| WebP | C2PA chunk inside the RIFF container | The chunk, with the header size and flags corrected |
| MP4 / MOV | Top-level uuid box (ID d8fec3d6-1b0e-483c-9297-5828877ec481) | Converted to an empty free box |
Many files also mention their manifest a second time in XMP (a dcterms:provenance or similar reference). That is removed too, so nothing points to a manifest that no longer exists.
What's inside a manifest
A C2PA manifest is a bundle of signed statements, called assertions, plus the signature that protects them. The pieces you will most often see are:
- Claim generator: the app or library that wrote the manifest.
- Actions: a list such as "created", "edited" or "converted", each of which can carry a digital source type. The IPTC value
trainedAlgorithmicMediameans the content was generated by an AI model;compositeWithTrainedAlgorithmicMediameans AI was used to edit part of it. - Ingredients: earlier files the content was made from, sometimes with their own manifests nested inside.
- Hash binding: a fingerprint of the file's bytes, so that any change to the image can be detected.
- Signature: made with a certificate issued to the signer, which is how a verifier knows who vouched for the claims.
Because the hash covers the image data, editing a signed file normally breaks the manifest's validity. Removing the manifest is different: there is nothing left to validate.
C2PA, IPTC and EXIF compared
| C2PA | IPTC / XMP | EXIF | |
|---|---|---|---|
| Purpose | Signed provenance history | Descriptive fields, including the digital source type | Camera and capture details |
| Can say "AI-generated" | Yes, in actions | Yes, via DigitalSourceType | Only indirectly (software name) |
| Tamper-evident | Yes, cryptographically signed | No | No |
| Read by platforms for AI labels | Meta, TikTok | Meta | Not as a stated signal |
| Removed by this tool | Yes | Yes | Yes (orientation kept) |
How to check a file for C2PA
- This tool: drop a file and read the report. It tells you whether a manifest is present before anything is removed, so you can use it as a checker.
- Content Credentials Verify: the Content Authenticity Initiative's public verifier at contentcredentials.org shows the full manifest and validates the signature. Note that it works by having you upload the file.
- c2patool: the open-source command-line tool from the C2PA project prints the manifest as JSON.
What the report shows
When a manifest is found, the report says so and lists what can be read from it without a full verification: whether it marks the content as AI-generated (the IPTC trainedAlgorithmicMedia source type) and which well-known tool or company names it mentions. Names are listed as "mentions" on purpose: a name appearing in a manifest is not the same as that company having signed it.
Before you remove it
A valid C2PA manifest can also work in your favour. Camera makers and some newsrooms use it to prove that a photo is not AI-generated and has not been altered. If you shoot with a C2PA-enabled camera and want that proof to travel with your image, keep the original and only share a cleaned copy where provenance doesn't matter.
Frequently asked questions
Is removing C2PA metadata legal?
Removing metadata from your own files is generally your choice. What matters is how you use the result: platform rules can require you to disclose AI-generated content, and some laws target deceptive use of synthetic media. Check the rules that apply to you.
Can a removed manifest be recovered?
Not from the cleaned file. But a file without metadata is not automatically unmarked: OpenAI and Google also embed SynthID watermarks in the pixels, which metadata removal does not affect. More on SynthID.
Does taking a screenshot remove C2PA too?
Usually, yes, and OpenAI itself notes that a screenshot can remove it. But a screenshot re-encodes the image, may change its size and adds your device's own metadata. Removing the manifest directly keeps the original image data intact.
Do you verify the C2PA signature?
Not yet. The report detects manifests and reads the AI-generated flag and named tools. Full signature verification against trust lists is planned.