Checks for C2PA Content Credentials and known AI-generator metadata fingerprints (Stable Diffusion, ComfyUI, Midjourney, and others). A signal found is a hint, not proof; no signal found doesn't confirm authenticity either — details below.
Content Credentials are the industry standard (backed by Adobe, Google, Microsoft, and the broader Content Authenticity Initiative) for cryptographically attaching provenance data to a file at the moment it's created or edited.
Most AI image tools in everyday use — especially local, non-hosted ones — don't attach C2PA credentials at all, but many still leave their own fingerprints behind in ordinary file metadata.
Software, UserComment, ImageDescription, and Artist tags, where tools like AUTOMATIC1111's Stable Diffusion WebUI write full generation parameters (steps, sampler, CFG scale, seed).parameters chunk with the prompt and settings.DigitalSourceType property, which Midjourney and a growing number of other generators set to explicitly flag AI-generated or AI-composited output.curl -sS -X POST https://devops.majbase.com/ai-image-scanner/api \
-F "file=@photo.jpg"
{
"filename": "photo.jpg",
"format": "PNG",
"size_kb": 1842.5,
"sha256": "a82f3c1e…9d4b",
"dimensions": "1024x1024",
"verdict": "unverified_ai_signal",
"c2pa": {
"manifest_found": false,
"validation_state": null,
"claim_generator": null,
"ai_assertion": null,
"error": null
},
"metadata_signals": ["ComfyUI", "Stable Diffusion"],
"exif_texts": {"Software": "…"},
"png_texts": {"parameters": "…", "workflow": "…"},
"camera_details": {},
"camera_metadata_present": false
}
verdict is one of verified_ai, verified_provenance, unverified_manifest, unverified_ai_signal, no_signal. On a server-side error the response is {"error": "…"} with a non-200 status.
Want an AI agent (Claude Code, claude.ai, or anything else that supports the Agent Skills format) to use this tool for you on request? Download the skill below and add it:
~/.claude/skills/ai-image-scanner/SKILL.md