How to Review C2PA Claim Generator Info
Start with the exact file and validator output
Save the media file you are reviewing and note where it came from, its filename, and when you obtained it. Open that same copy in a C2PA-compatible validator. Record the validator and version as well. These logging steps are an editorial method proposed here, not a procedure required by the C2PA specification.
Find the claim generator information in the validator output. In C2PA 2.2, detailed information about the claim generator is stored in claim_generator_info. A Manifest Consumer can use it to understand the claim generator or present that information in its interface. Copy the displayed values rather than reducing them to a badge such as “created by a trusted tool.”
Keep the result attached to the exact file and manifest being inspected. If the validator does not display a field, write “not displayed.” Do not infer a version from the application installed on your own computer, and do not infer a product identity from a familiar-looking icon.
Read each generator field at its stated scope
The generator information map must contain a name field. It may also contain a version field, an icon field, or both. The specification permits additional fields through its entity-specific namespacing rules. Record the exact field names and values shown by the validator, including any namespace, without renaming them for convenience.
C2PA says this object represents the non-human hardware or software actor that actually generated the claim. That is the narrow question the record answers. It does not name every application that may have touched the asset, identify the human who made an editorial decision, or explain why the claim was created. Leave those questions open unless another source answers them.
Use one row per inspected manifest. Suggested columns are file, manifest identifier shown by the tool, generator name, version, icon status, extra namespaced fields, validation result, and unresolved questions. This table is a review aid, not a C2PA data structure.
Treat an icon as referenced data, not identity proof
When an icon is present, C2PA specifies it as a hashed URI pointing to an embedded data assertion labeled c2pa.icon. The hash algorithm comes from the hashed URI's alg field or, when that is absent, from an alg field in the claim. Preserve the validator's status for that reference and the value it displays.
A recognizable logo can help a person read an interface, but appearance alone does not establish who supplied the manifest. Do not use a screenshot of the icon as a substitute for the validator result. If the reference is missing, unavailable, or fails a check, record that limited condition instead of guessing which organization produced the file.
Compare generator records only after labeling the copies. Two files may display different names or versions. That establishes a difference in the available records; it does not by itself explain the processing history or prove that either file's visible content is accurate.
Separate the tool record from the assertions and event
Review the claim generator information, the claim's signature and validation results, and the manifest assertions as separate evidence. A named generator tells you what the record identifies as the hardware or software actor that generated that claim. It does not make every assertion accurate, authenticate a caption, or establish that the depicted event happened.
Check assertions in their own context and retain their wording. Check a real-world claim against the publisher's original page, the account or organization presenting the media, the stated date and place, and independent evidence about the event. If any part remains unresolved, keep it unresolved in the report.
A failed or incomplete generator-information display also has a limited meaning. Preserve the exact error or missing field. Do not convert it into “the file is fake,” because the observed failure concerns a specific record or check rather than the truth of the scene.
Keep automated detection in a separate lane
A saved image, video, audio file, or text can be submitted to DeepFakeCheck for a probabilistic risk signal. Store that output separately from the C2PA generator record. DeepFakeCheck does not identify the claim generator, validate the icon reference, or verify the C2PA signature.
Automated analysis can produce false positives that flag authentic material and false negatives that miss synthetic or altered material. Attach the result to the analyzed copy. A high-risk signal supports further investigation, while a low-risk signal does not authenticate the file or confirm its generator information.
Finish with the exact file, validator and version, copied generator fields, icon-reference status, validation output, separately reviewed assertions, external context checks, detector result if used, and unresolved questions. Another reviewer should be able to repeat the inspection without turning a tool label into a broader claim.
Sources
- C2PA, “C2PA Technical Specification — Claim Generator Info”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_claim_generator_info
Need to check a suspicious file?
Open the matching detector and interpret the result alongside the source and context.
Open Detector