gallery of limits
Three things a valid chain cannot tell you.
Each fixture loads into the same Inspector a real upload uses — identical code path, identical copy. Click one and read what comes back.
1 — The indistinguishable twins
A file that never had provenance and a file whose valid provenance was deleted moments ago produce the identical verification result.
“Never signed” and “Stripped” are byte-for-byte identical — the same SHA-256, checked automatically in CI. Not files that merely look similar.
2 — Valid signature, fabricated scene
An obviously impossible scene, signed with a manifest asserting it was captured by a real device. The signature validates cleanly.
3 — Same badge, different crimes
One file was re-encoded by an ordinary, non-C2PA-aware tool after signing. The other had a single byte deliberately altered. Both land on the identical failure code, and nothing here can tell you which is which.