A C2PA checker result describes the provenance record available for a particular file. A validated credential supports a narrower conclusion than “this image is real.” Missing credentials do not prove AI generation, and a validation failure does not explain who changed the file or why.
The useful next step is to read the status, signer, declared actions, and limitations together. This guide explains the result labels shown by the C2PA checker, then gives you a way to record what the result actually supports.
What does each C2PA checker status mean?
These labels describe different outcomes of a credential check. They are not interchangeable authenticity ratings. Start with the exact wording in your report, and keep the result tied to the file version you submitted.
| Report label | How to read it | Your next step |
|---|---|---|
| Credential validated | The checker established trusted credential evidence for the inspected file | Read the signer and declared actions |
| Signer trust not established | A credential was found, but the checker did not establish trusted status | Inspect warnings and signer details; do not assume all validation checks passed |
| Validation failed | The available report contains a validation failure | Preserve the failure details and compare with the original file |
| No Content Credentials found | The check did not locate credentials through its supported method | Ask for the original and investigate other evidence |
| Verification unavailable | The credential check could not be performed | Treat this channel as unchecked |
| Report unsupported | The verifier output could not be interpreted as a supported credential report | Keep the available report details and seek a compatible inspection workflow |
The C2PA validation guidance distinguishes a parseable record, successful validation, and a trusted signing credential. An interface can compress these details into a badge, which is why the underlying warnings matter.
If you want a broader introduction to manifests and signatures, read what Content Credentials are and how they work. Here, the focus is what to do with a result already in front of you.
Does “Credential validated” prove that an image is real?
It supports the credential relationship reported by the checker. It does not independently verify a scene, caption, location, or date. A technically validated image can still be paired with an inaccurate story.
The C2PA consumer guidance explicitly separates verifiable provenance from judgments about the truth of digital media.
Read the actions before drawing an origin conclusion. The technical specification provides action and source-type fields that can describe creation, editing, and ingredients. These can answer different questions:
- A creation action can declare that an asset was generated using AI.
- An editing action can describe AI changes to an existing asset.
- An ingredient can be AI-generated even when the final asset combines several sources.
Do not flatten these cases into “the entire image was generated.” For example, an AI-created background in a composite is a different claim from a wholly generated scene.
When explaining your finding, use the declared scope: “The validated record declares AI editing” is more precise than “Every pixel is fake.” Then investigate whether the publisher represented that editing accurately.
How should you handle an untrusted signer or validation failure?
Keep signer trust and validation errors separate. “Signer trust not established” means this checker has not elevated the record to trusted status. The label alone does not establish that every other check succeeded, or that the signer acted dishonestly.
Look for a signer name, validation codes, and the report's explanation. If a second verifier differs, record the difference rather than choosing whichever badge feels reassuring. Ask whether both tools inspected the same bytes and whether their trust configuration or supported format differs.
With “Validation failed,” retain the specific warning. A failure can concern the credential or its relationship to the asset; the label alone does not identify the cause. Avoid diagnosing deliberate tampering from a summary badge.
A practical comparison is to obtain the creator's original signed file and inspect it separately. If the original and circulated copy produce different results, document that difference. It is a lead for investigating the distribution history, not automatic proof of misconduct.
For escalation, save the exact file, tool name, scan date, status, and any error codes. A screenshot of the badge is useful context, but keeping the inspected file makes the finding reproducible.
Why might a checker find no Content Credentials?
The finding applies to the credential discovery method and file inspected. It does not distinguish an unsigned original from a copy that lost its embedded provenance. It also does not establish whether AI was used.
Our checker inspects locally available credentials and does not fetch remote manifests from URLs embedded in untrusted files. An external provenance record can therefore exist without being available through this check.
Other implementations may offer recovery workflows. Adobe's documentation describes an approach using an invisible watermark, digital fingerprinting, and its Content Credentials cloud to recover matching records, including after screenshots. That is a feature of the documented Adobe workflow, not a capability you should assume every C2PA checker has.
Ask the source for the original signed export before creating a new copy yourself. Converting, re-saving, or screenshotting the file introduces another version into the investigation. If only a repost exists, preserve that limitation in your notes.
“Verification unavailable” and “Report unsupported” require a different response: resolve the inspection problem or use a compatible workflow. Neither is a completed check that found nothing.
How do you turn a result into a useful evidence note?
Write a narrow statement that another person can check. Separate what the report observed from the real-world claim you are evaluating. This prevents a provenance finding from becoming a broader verdict during sharing or review.
Use this template:
| Field | What to record |
|---|---|
| Asset | File name, format, dimensions, and version; file hash if available |
| Source | Where the exact copy came from and when you obtained it |
| Check | Tool, date, result label, and available validation details |
| Declaration | Recorded AI action, edit, or ingredient, using the report's wording |
| Limitation | Missing fields, unavailable checks, or lack of the original |
| Context | The caption or claim that still needs independent verification |
For a missing result, a suitable note is: “No credentials were found by the supported local inspection of this copy; the original has not been obtained.” For a trusted AI declaration, record the declaration's scope and the signer rather than making an accusation about the creator.
If provenance does not settle the question, the AI image detector provides another supported evidence channel. Review its limitations too, and use source research to check the story attached to the media.
Frequently asked questions
Is “Signer trust not established” the same as “Validation failed”?
No. They represent different report outcomes. Lack of trusted status does not by itself identify a validation failure or prove that all validation checks passed. Inspect the details and keep the exact label in your notes.
Can an AI-generated image have validated Content Credentials?
Yes. A credential can declare AI creation or editing. The relevant question is what action the trusted record declares, not whether the file has a credential badge at all.
Do missing Content Credentials prove that a file is fake?
No. This result means the supported check found no available credentials in that copy. It does not establish a human or AI origin, and it does not resolve whether the caption is accurate.
Should I edit the file to repair a failed credential?
Preserve the file before making changes. Ask for the original signed export and inspect it separately. An edited or re-exported copy is a new investigation asset and should not silently replace the evidence you first examined.