---
title: "How Watermark Removers Work in 3 Steps"
author: "Ecem Karaman"
source: "https://aiwithecem.com/guides/how-watermark-removers-work"
published: 2026-09-12
tools: ["Claude"]
topics: ["Security"]
---

# How watermark removers work in 3 steps

Watermark removers can clean hidden characters, strip file metadata, and rewrite text. **Only rewriting targets the statistical pattern in the words—and success needs checking.**

```animation-watermark-6
```

*The three operations at a glance. Tools differ in which ones they support.*

## First, what is a text watermark?

A statistical text watermark is a detectable pattern in how a model chooses its words. Claude uses a version of SynthID Text, which adds no hidden characters. [Anthropic's explanation](https://www.anthropic.com/news/claude-text-watermark)

Models generate **tokens**: words, word fragments, or punctuation. When several next tokens are plausible, a secret key and nearby tokens help determine the sampling choices. Repeated across a passage, those choices leave a pattern that a matching detector can recognise. There is no universal list of "watermarked words." [How SynthID Text works](https://huggingface.co/blog/synthid-text)

```animation-watermark-1
```

*The dots illustrate the pattern; they are not extra characters in the text.*

## 1. Clean hidden characters

The tool scans for specific artifacts—zero-width spaces, unusual spacing, or invisible tag characters—and removes or normalises them. The [example GitHub project](https://github.com/haidrrrry/claude-watermark-remover) uses scripts for this step.

That cleans the text, but does not remove the statistical pattern in its words. Invisible characters are not proof of AI use; some also serve legitimate formatting or language purposes.

```animation-watermark-2
```

*Hidden artifacts are shown as labels so you can see the cleanup.*

## 2. Strip file metadata

A file may record its author, generating application, or editing history. A remover can delete supported metadata fields, including embedded **C2PA Content Credentials**—signed provenance records. Some credentials can still be rediscovered through external records. [C2PA's explainer](https://spec.c2pa.org/specifications/specifications/2.2/explainer/Explainer.html)

Deleting an "Author" field does not change the sentences. Their statistical watermark can remain. This step depends on the file format and metadata present.

```animation-watermark-3
```

*Example fields; not every file contains all of them.*

## 3. Rewrite to scramble the pattern

The tool rewrites the text to try to scramble the token sequence while preserving the meaning. Changing the words also changes the context used for subsequent token choices.

Thorough rewriting can reduce detector confidence; light edits may leave the watermark detectable. More rewriting can also change your message, so check the facts and meaning. [SynthID Text's limitations](https://huggingface.co/blog/synthid-text)

```animation-watermark-5
```

*Illustrative rewrite, not a measured result. The highlights show wording changes.*

> **Verification matters.** Check the text before and after with a matching watermark detector. Anthropic's key is private, but its September 1 update describes a detection API in private preview for eligible organisations. A generic AI-writing score is a different test. [Detection details](https://www.anthropic.com/news/claude-text-watermark)

## Can Claude remove its own watermark?

Some removers run as Claude Code skills. A skill might run a cleanup script, ask Claude to rewrite, or call another model—the [example project](https://github.com/haidrrrry/claude-watermark-remover) supports an external rewrite hook.

My expectation: **a watermark-enabled Claude model could scramble the original pattern while generating a fresh one.** That is a hypothesis, not a measured result.

That's what I want to test next: does a Claude-powered rewrite reduce detection, or simply leave fresh evidence?
