Anthropic-focused
Claude watermark detector
Two different things are called “Claude's watermark”: a statistical watermark inside Claude-generated text, and a signed content credential inside Claude-generated files. One you can verify — right here, in your browser, without uploading anything. The other only Anthropic can verify.
Runs entirely in your browser — your file is never uploaded.
① Check a file for Claude's content credential
Drop an image here, or browse files
JPEG · PNG · WebP — up to 25 MB. Files are read locally and never uploaded.
Quick answer
Files: Claude attaches a signed C2PA Content Credential to .png/.jpg/.svg outputs (Anthropic, Aug 2026). Drop one above — if the credential is intact, the manifest names Claude and its signatures are tamper-evident.
Text: Claude marks generated text with an invisible SynthID-Text-derived pattern. Verifying it requires Anthropic's key, so no honest third-party detector exists yet; Anthropic's detection API is in private preview.
The two “Claude watermarks”, precisely
| Text watermark | File credential | |
|---|---|---|
| What it is | A statistical pattern in word choices (SynthID-Text family — no hidden characters added) | C2PA content credential: signed metadata inside .png/.jpg/.svg |
| Visible? | Invisible to readers | Invisible unless you inspect metadata |
| Verifies with | Anthropic's key only — official detection API (private preview) | Any C2PA-aware reader — including this page |
| Survives | Light editing; destroyed by full rewrites | Re-saving in most apps; destroyed by screenshots/re-encodes |
| Can tell you | Likelihood Claude wrote (part of) the text | That a file was made/processed with Claude |
② Checking text? Read this first — then scan what's actually checkable
Anthropic's implementation is explicitly key-based: word choices remain random, but they can be confirmed as consistent with Claude's key. That's cryptography, not vibe detection — which is good (no false accusations) but also means every online tool claiming to detect the Claude text watermark today is faking it. The legitimately available path is Anthropic's detection API, currently in private preview for eligible organizations under the EU AI Act. Meanwhile, two things you can check in any pasted text: hidden characters that some tools do insert, and admittedly soft stylistic signals.
Spotting a fake Claude watermark detector
Since Claude watermarking launched (Aug 2026), several sites have appeared promising “paste text → get a detection score”. Here is the technical reality check, straight from Anthropic's own explanation of the system: the watermark is a statistical pattern in Claude's word choices, verifiable only against Anthropic's private key. A website without that key cannot produce a true watermark check — no more than a stranger could verify a Monopoly game was played with a particular loaded die without its rulebook.
Three standards to hold any “Claude watermark detector” to before you trust it:
- Can it explain the method? A real watermark check is cryptographic: it examines whether the sequence of word choices is consistent with a key. Any tool that won't describe its cryptographic basis is producing a stylistic guess, not a detection.
- What does the score actually measure? Watch for tools that relabel things other than the watermark — hidden Unicode characters (Claude explicitly adds none), AI-“tells” word lists, or generic “AI detector” scores — as a “watermark score”.
- What is sold next to it? Be extra skeptical of a “detector” whose sibling product is a remover or “humanizer”. A tool that profits from rewriting your text has a built-in incentive to scare you first.
Our position is the boring one: for text, only Anthropic's gated detection API can verify the watermark today, and there's no honest shortcut. For files, everything does become publicly checkable — the signed C2PA credential at the top of this page.
So what can you use today for text?
- The official path: Anthropic's watermark detection API (private preview, for eligible organizations under the EU AI Act). This is the only true watermark check.
- The community-vetted fallback: reputable stylometric AI-text detectors — e.g. Pangram, which reviewers on Reddit consistently rate as accurate while being upfront that it is not the official tool and cannot access the watermark. Keep their nature in mind: probabilistic classifiers with real false-positive risk, not cryptographic proof.
- The provenance approach (our lane): for documents with any file component — the signed C2PA content credential Claude attaches to generated files, which any C2PA reader can verify.
In short: skip tools that fake a watermark score; don't expect style detectors to be evidence; and when the artifact is a file rather than text, verify the credential.
Paste text to scan
Checks invisible/bidi characters and common AI-stylistic markers. This does not read Claude's SynthID-based text watermark — that requires Anthropic's key.
How the file check works
- The file's container is scanned for the C2PA manifest store — a
caBXchunk (PNG) or APP11 segment (JPEG). - JUMBF boxes are walked; the CBOR claim is decoded to reveal generator strings, actions and timestamps.
- The manifest's signature box is located, so claims are tamper-evident. (Certificate-chain validation is on the roadmap; see methodology.)
FAQ
Does Claude watermark images?+
Claude doesn't stamp visible watermarks or pixel watermarks on files. Per Anthropic (Aug 2026), when Claude produces a file of a supported type (.png, .jpg, .svg) it attaches a C2PA Content Credential — a small cryptographically signed note in the file's metadata saying the file was made or processed with Claude. That credential is what this page reads.
Can I check text for Claude's watermark online?+
Not with any third-party tool, honestly at least. Claude's text watermark is a SynthID-Text-derived statistical pattern that can only be verified with Anthropic's private key, through their detection API, which is currently in private preview for eligible organizations (regulators, media, educators, researchers). Sites claiming an online 'Claude text watermark detector' are misleading you.
What exactly does Claude's C2PA credential contain?+
It's a JUMBF-structured manifest with a CBOR claim naming the generator (e.g. strings referencing Claude), the file format, action records (created / edited, timestamps, software agents) and a signature box. It contains no personal information about the user or conversation.
Are online “Claude watermark detector” tools that return an instant score trustworthy?+
Hold them to a technical standard: Anthropic's watermark is a statistical pattern in word choices that can only be verified against Anthropic's private key — a website without that key cannot perform a true watermark check. Be skeptical of tools that (a) don't describe a cryptographic method, (b) relabel hidden-character scans or generic “AI detector” scores as a watermark score, or (c) sell a watermark 'remover' alongside the detector. Community review has already called out several such tools. The honest options are Anthropic's gated detection API (private preview) and, for files, the publicly readable C2PA credentials.
If the credential is missing, is the image human-made?+
Not necessarily. Content credentials are removed by screenshots, re-saving, and most social-platform processing. Absence means 'no provenance data found', not 'a human made this'.
Does this tool upload my file?+
No. Parsing happens in your browser via JavaScript; formData never leaves your device. It also works offline once the page has loaded.
Is AI Watermark Checker affiliated with Anthropic?+
No. We read the open C2PA standard, which Anthropic explicitly says any C2PA-aware tool can read. Claude, Anthropic and related marks belong to Anthropic PBC.
Sources
- Anthropic — How Claude's text watermark works (Aug 14, 2026; updated Sep 1, 2026) — accessed 2026-09-29
- Google DeepMind / Nature — Scalable watermarking for identifying large language model outputs (SynthID-Text, 2024) — accessed 2026-09-29
- C2PA — Technical specification — accessed 2026-09-29
- EU AI Act — Code of Practice on Transparency of AI-Generated Content (July 2026) — accessed 2026-09-29