a C2PA honesty test

A valid signature proves less than you think.

Drop an image. See its provenance chain in plain language — and, beside every claim, what that claim structurally cannot establish.

nothing uploads — check the Network tabparsed by the official C2PA library3 adversarial demonstrations →
inspectorrecorded example

VALIDATES

These bytes were signed by the party named below, at the time shown — this says nothing about whether the depicted scene is real.

Signer

Issuer
C2PA Test Signing Cert
Common name
C2PA Signer
Signed at
15 Aug 2026, 17:01 UTC 2026-08-15T17:01:05+00:00
Algorithm
Es256
Proves
A named signer certified these exact bytes at a stated time, using the certificate shown.
Does not prove
Whether the depicted scene is real, whether the signer verified it themselves, or whether the certificate's issuer is trusted by anyone other than this file's own claim.

Assertions (2)

  • Edit actions c2pa.actions.v2

    Proves
    The signer's own tool declares these editing actions occurred, in this order.
    Does not prove
    That the list is complete. A tool can simply choose not to log an action — nothing in the chain can detect an omission.
  • my.assertion my.assertion

    Proves
    The signer's tool included this data under its own signature.
    Does not prove
    Anything about whether the data itself is accurate — only that it was included.
Technical validation details (1)
  • signingCredential.untrusted — signing certificate untrusted

Recorded from a real browser run of @contentauth/c2pa-web against a c2patool-signed JPEG, then summarised by the same code a live read uses. Drop your own file above to replace it.

provenote is not a verifier and it does not detect AI-generated images — it never will. It explains chains; it never judges content. The full reasoning, with citations, is on Limitations.