Free image metadata viewer: EXIF, GPS and XMP
Drop an image and see what it says about where, when and with what it was taken. The form calls the same free API your code can call: one POST, no API key and no account. The full report is kept in Storage for 24 hours as JSON.
curl -s -X POST https://aisenseapi.com/services/v1/image_metadata \
-F "file=@photo.jpg"
{
"storage_id": "4528d367-4a08-474d-b01d-2c1b0798450a",
"storage_url": "https://aisenseapi.com/services/v1/storage/4528d367-4a08-474d-b01d-2c1b0798450a",
"sha256_hash": "208dee926f183fb3fddbf979058c6c45e14b0914848db7fb5b11dce1b24a1ae7",
"bytes": 2284,
"expire_timestamp": 1790778560,
"expire_datetime": "2026-09-30T14:29:20+00:00",
"content_type": "application/json",
"filename": "metadata.json",
"operation": "image_metadata",
"format": "jpeg",
"width": 1600,
"height": 1200,
"gps": true,
"findings": [
"GPS position",
"Serial number or unique ID",
"Camera or phone",
"Date and time",
"Software"
]
}Try it in the browser
This form posts your image to the same endpoint and shows the stored result. The image is sent to aisenseapi.com, and the result is kept for 24 hours at a link that anyone with the link can open.
What the report holds
The image is read, not decoded. The endpoint walks the segments of a JPEG, the chunks of a PNG or the chunks of a WebP and reports what it finds there, as JSON in these parts:
| Part | What it holds |
|---|---|
file | Format, size in bytes, width, height and megapixels, and what the format tells: the estimated JPEG quality, bit depth, progressive or interlaced, lossy or lossless WebP. |
orientation | The EXIF orientation as a number and in words, such as 6 and Rotated 90 degrees clockwise. |
color_profile | The ICC colour profile: its name, colour space, device class, version and size. |
exif | Every EXIF tag by name, in image, photo, gps, interoperability and thumbnail. An exposure time is written as 1/250, and a maker note by its size only. |
gps | Latitude and longitude in decimal degrees, the altitude in metres and the time in UTC, from the EXIF GPS tags. |
xmp | The fields of the XMP packet, such as dc:creator, photoshop:City and xmp:CreatorTool. |
iptc | IPTC fields such as By-line, City, Keywords and Caption-Abstract. |
comments, text | JPEG comments, and the text chunks of a PNG by their keywords. |
embedded | What else is inside: an EXIF thumbnail, a multi-picture index, and data after the end of the image, where phones keep depth maps and HDR gain maps. |
privacy | What can identify a person, a place, a device or a time, most sensitive first, each with item, level and why. |
A part the file does not have is null or empty. Long values are cut short, and a report is at most 2 MB.
The privacy summary
The privacy list in the report, and findings in the answer, can name these items:
- GPS position, high: where the picture was taken, to within metres.
- Location in XMP, high: a place an editing program recorded.
- Serial number or unique ID, high: it links the picture to other pictures from the same camera.
- Names, medium: an author, owner or copyright holder.
- Place names in IPTC, medium: a city or location written into the file.
- Camera or phone, medium: the make and model.
- Date and time, medium: when the picture was taken or last changed.
- EXIF thumbnail, JFIF thumbnail, Multi-picture index (MPF) and Data after the end of the image, medium: extra image data that can show more than the picture itself, such as the uncropped original.
- Descriptions and comments, low: free text written into the file.
- Software, low: the program that made or edited the file.
The EXIF remover takes all of it out without touching the pixels.
The API
POST https://aisenseapi.com/services/v1/image_metadata with multipart/form-data and one field, file. The report is stored as metadata.json, and the answer holds the Storage fields and a short version of it:
| Field | Meaning |
|---|---|
storage_id, storage_url | Where the result is. A GET on the URL returns it. |
sha256_hash, bytes | The digest and size of the stored result. |
expire_timestamp, expire_datetime | When the result is removed, 24 hours after it was stored. |
content_type, filename | application/json and metadata.json. |
operation, format, width, height | image_metadata, and the format and size of the image. |
gps | true when the image carries a GPS position. |
findings | The items of the privacy summary, most sensitive first. Empty when nothing was found. |
The example at the top of the page comes from a test run with a test photo of 1600 x 1200 pixels, given made-up EXIF data: a camera, a serial number, a date, software and a GPS position at the Oslo Opera House. Part of the stored report:
{
"gps": {
"latitude": 59.9075,
"longitude": 10.7531,
"altitude_m": 12.0,
"time_utc": null
},
"privacy": [
{
"item": "GPS position",
"level": "high",
"why": "Shows where the picture was taken, to within metres."
},
{
"item": "Serial number or unique ID",
"level": "high",
"why": "Links this picture to other pictures from the same camera."
},
{
"item": "Camera or phone",
"level": "medium",
"why": "Make and model of the device that took the picture."
},
{
"item": "Date and time",
"level": "medium",
"why": "When the picture was taken or last changed."
},
{
"item": "Software",
"level": "low",
"why": "The program that made or edited the file."
}
]
}
Anyone with the link can read the report until it expires, and a report can hold a GPS position, so keep the link to yourself for a private photo. Stored reports count against the Storage budget of 80 MB per IP address per day.
Limits
- The upload is a JPEG, PNG or WebP of at most 10 MB. There is no pixel limit, since the image is not decoded.
- HEIC is read by the image converter only.
- The report is at most 2 MB.
Errors
A refused request stores nothing and answers with error. The endpoint's own refusals also carry fix, a sentence saying what to send instead.
| Status | When |
|---|---|
400 | A field was sent, the upload is not one whole file, or the file cannot be read as an image. |
405 | The method is not POST. |
413 | The upload, its number of pixels or the result is over a limit. |
415 | The body is not multipart/form-data, or the file is not a JPEG, PNG or WebP. |
429 | More than 5000 requests from one IP address in 24 hours, or the day's Storage budget is used up. |
503 | The service cannot read or store the image right now. |
Questions
Is the image metadata API free?
Yes. No API key, no account and no sign up. The limit is 5000 requests per IP address per 24 hours, and stored results count against the Storage budget of 80 MB per IP address per day.
Does it show the GPS position?
Yes. The GPS tags are given as latitude and longitude in decimal degrees, with the altitude in metres and the time in UTC, and the privacy summary lists the position first.
Is my image stored?
No. The image is read and dropped. Only the JSON report is stored, for 24 hours, at a link that anyone with the link can open.
Can it read HEIC?
No. It reads JPEG, PNG and WebP. The image converter reads HEIC and removes the metadata on the way.
Related tools
- Image converter, which also reads HEIC, and image compression
- Image metadata viewer and EXIF remover
- Colour palette and favicon generator
- JSON to CSV, CSV to JSON and table matching
- JSON formatter and JSON validator
- File uploader and the Temporary Storage API, where every result is kept for 24 hours