← Back to tool

What's Inside a DALL·E / ChatGPT Image's Metadata

Guide · updated 4 October 2026
Quick answer

OpenAI has embedded C2PA Content Credentials in DALL·E-generated images since 2023, and ChatGPT's current image generation (branded internally as "gpt-image") continues this. When we decoded a real file generated through OpenAI's pipeline, the manifest listed "OpenAI Media Service API" as the claim generator, a software agent of "gpt-image", a chain of recorded actions (created → converted → watermarked), and a cryptographic ES256 signature — a full, signed provenance record, not just a flag.

What's actually in the manifest

Unlike Midjourney's plain-text prompt approach, OpenAI's images carry a structured, cryptographically signed C2PA manifest (technically a JUMBF box containing CBOR-encoded data). Based on direct inspection, it typically includes:

Why this is the easiest case for platform AI-detection

Because the manifest is both present and signed, platforms like Instagram, Facebook, and TikTok — all of which read C2PA on upload — detect OpenAI-generated images reliably. This is the main reason ChatGPT-generated images get labeled consistently, while Midjourney images (no C2PA at all) often slip through metadata-based detection.

Does the signature mean the image is "verified"?

The signature proves the manifest hasn't been altered since OpenAI signed it — it doesn't make any claim about the image's content being true, accurate, or non-misleading. It's a provenance record, not a fact-check.

Removing it

Use AiEraser's View mode to decode the actual manifest on your own file — claim generator, every recorded action, and signature algorithm, exactly like the breakdown above — then Remove mode to strip it via in-browser canvas re-encoding before you share or publish.

Frequently asked questions

Does every ChatGPT-generated image have this exact manifest?
The structure we describe reflects a real file we inspected directly; exact fields can vary by generation pipeline version and image format (PNG vs JPEG vs WebP each embed the manifest differently — see our C2PA guide).
Can I remove just the signature but keep other metadata?
AiEraser's Remove mode strips everything at once via re-encoding, since a partially-edited C2PA manifest would fail signature verification anyway and serve no purpose — removing it fully is the cleaner outcome.
Does OpenAI's manifest include my account or prompt?
Based on direct inspection, the manifest we examined did not include the account identity or prompt text — it recorded the generating service, software agent, and action history, not user-identifying details. This can change between versions; verify with View mode on your own files.

Related

Primary source: direct JUMBF/CBOR decoding of a real OpenAI-generated image file, cross-checked against public reporting that OpenAI added C2PA Content Credentials to DALL·E outputs in 2023 in partnership with the Content Authenticity Initiative.