← Back to tool

ComfyUI Metadata: Your Entire Workflow Can Be Hiding in the File

Guide · updated 4 October 2026
Quick answer

ComfyUI, the node-based Stable Diffusion interface, commonly embeds your entire generation graph — every node, model, LoRA, and connection in your workflow — as JSON inside a PNG text chunk (typically under a workflow or prompt key). That's a significantly larger exposure than a simple prompt string: it can reveal your exact custom pipeline, model combinations, and sometimes local file paths.

Why this is different from a typical Stable Diffusion export

A standard AUTOMATIC1111-style export writes a single text block with your prompt and generation settings (see our Stable Diffusion metadata guide). ComfyUI's node-graph architecture means the embedded data can be the complete recipe for your workflow — reproducible end to end by anyone who opens the file in ComfyUI and loads its embedded workflow directly from the image, which is in fact a feature ComfyUI offers by design (drag an image back into the canvas to reload the workflow that made it).

What can be exposed

Why creators often don't realize this

Because the workflow-embedding feature is genuinely useful for sharing reproducible setups with collaborators, it's easy to forget that the same convenience means every image you export to a public platform carries your whole pipeline unless you deliberately strip it first.

Removing it

Since this is stored as ordinary PNG text-chunk data (not a signed manifest), AiEraser can show you what's embedded in View mode and remove it entirely in Remove mode — the canvas re-encoding process drops the workflow JSON along with everything else, since it only preserves pixel data.

Frequently asked questions

Will I lose the ability to reload my own workflow if I strip the metadata?
Yes — stripping removes the embedded workflow JSON, so save your workflow separately (ComfyUI supports exporting workflow files directly) before cleaning images you plan to publish.
Does ComfyUI support C2PA natively?
Not by default — ComfyUI is open-source and locally run, with no built-in signing authority. Some community extensions exist to add C2PA signing, but it's not part of the core application.
Is this a bigger exposure than a Midjourney prompt?
Often, yes — a prompt reveals what you asked for, while a full node graph can reveal your entire technical setup, including models and custom logic you may not want public.

Related

This reflects ComfyUI's well-documented workflow-embedding convention, a core feature of the application. Custom nodes and configurations can alter exactly what's stored — check your own exports with a metadata viewer.