How Metadata Decides
Read unsigned file observations, coverage limits, and the separate C2PA verification receipt without treating them as an authenticity verdict.
Metadata inspects the submitted bytes and returns file_evidence and content_credentials. The file report describes structure and selected claims. The credential receipt describes a separate C2PA check on the original file. The scan makes no safety or authenticity decision.
File claims and observations
EXIF, XMP, PDF Info, and container fields are unsigned. A recognized camera or software label describes a field in the file; it does not verify the camera, the editor, or the file's history. JPEG v2 returns selected camera and software labels only when they match bounded patterns. Presence flags can show that a tag exists even when its value is withheld. It can also return a parsed capture_time and gps_fix_utc. A capture time without an offset is local_unqualified, so it cannot be compared with GPS as an exact instant.
JPEG and PDF observations name a code and an effect. context records a clue with benign explanations. contradiction means parsed claims disagree under the stated comparison rule. For JPEG, a qualified EXIF capture-time and GPS fix-time gap under one minute is context; a gap of at least one minute is a contradiction. Both times remain unsigned claims. Other formats can report a metadata.chronology_code and coarse gap band instead of an observation effect.
Extra bytes after a JPEG, an EXIF size that differs from current pixels, software markers, XMP history, and a PDF previous-cross-reference marker can all have ordinary export or document causes. None establishes an edit on its own. Missing metadata does not establish human origin or an unchanged file.
Coverage sets the limit
Each report identifies its format and collection status. JPEG and PDF have component status; other format reports also include coverage.status and coverage.reasons. The latter lists why inspection was limited. complete means that collection finished for that component. It is not a clean-file verdict.
The scan leaves a comparison undecided when the necessary scope is incomplete or ambiguous. For example, an uninspected linked EXIF directory prevents a capture-time or GPS-absence claim. A PDF child with unsupported image bytes is not counted as analyzed. A PDF page can also report an uninspected transparency mask or inline image even when another image stream on that page was analyzed. Read the page, child, and parent coverage separately.
Content Credentials
content_credentials is a bounded C2PA receipt for the original encoded file. It does not authenticate the unsigned EXIF, XMP, or PDF Info in file_evidence.
| Status | Meaning |
|---|---|
trusted | A signed claim passed integrity and trust checks. It authenticates the signed claim within its scope, not the visible scene. |
invalid | The signature or content binding failed. |
untrusted | The claim was cryptographically valid, but its signer was not trusted by the verifier. |
absent | A completed check found no embedded manifest. Remote and sidecar manifests were not checked. |
unavailable | The check could not reach a conclusion. |
Only a trusted receipt can name a claim such as captured or ai_generated_or_edited. The latter does not distinguish generation from AI editing. A trusted action sequence is the signer's declaration, not an independently verified edit timeline. The receipt does not verify a pixel watermark.
Read the response fields
The scan API reference lists the format schemas, observation fields, and limits on inspection.
