NewAnthropic is watermarking Claude’s text output from 2 August 2026.See which models carry it →
Claude Watermark

Does the GitHub Claude watermark remover actually work?

By Claude Watermark Research · Updated

Its documentation is accurate, which is more than can be said for most of the paid alternatives. The repository is honest that a statistical watermark lives in which words the model chose, that removing one means rewriting a substantial share of the text rather than deleting characters, and — stated outright — that it cannot certify a vendor's detector will fail. That last sentence is the one nearly every commercial tool omits. We have read its claims, not audited its code, so this page is about what it says rather than how well it runs.

Check your own text for these artifacts. Runs in your browser, no account, nothing uploaded.

What it is

`guillaumemeyer/watermarks-remover` was created on 11 August 2026, days after Anthropic's announcement. As of 15 August it has roughly 9,550 stars and 980 forks, MIT licensed. That makes it comfortably the largest single artifact of this news cycle — bigger than any of the commercial tools, and free.

It is not Claude-specific. It handles several provenance mechanisms at once: Unicode and metadata hygiene, C2PA in images and documents, and a separate best-effort path for statistical text watermarks.

What the internet says about it

Dismissively. In the r/ClaudeAI thread where it circulated, one comment reads “I hope everyone realizes you can't detect watermarks and this repo is pointless af lol. Only Anthropic knows how the watermark is formed.” Another calls it a “snake oil vendor until that key is released to 3rd parties.” The thread's own auto-generated summary states it “has been debunked as snake oil”.

The underlying objection is correct: nobody outside Anthropic can verify a Claude watermark, so nobody can prove a removal worked. We make that point constantly. It just is not what this repository claims.

What it actually claims

Quoting the README directly, checked 15 August 2026:

“Modern LLM watermarks often hide a signal in which tokens are chosen (generative / sampling bias), not only in invisible characters.” That is the correct mechanism, stated more plainly than most press coverage has managed.

“Text watermarks live in the wording itself: the signal is spread across token choices, so nearly every sentence carries a little of it.”

“Stripping a statistical mark requires rewriting a substantial fraction of the text — sentence by sentence, not section by section.”

And the sentence that decides the whole question: “It cannot certify that vendor detectors will fail.

It also warns about the cost of the approach — “the result cannot exceed the rewrite model's ceiling” — and ships a section titled “what removing a text watermark costs”. A tool selling you something does not usually explain what you lose.

Compare that with what is being sold

On the same day, the tools ranking on Google's first page for “Claude watermark remover” read very differently. One advertises “Detect and remove watermarks from AI generated text in just a few clicks… 99% human output when verified by AI detection.” Another promises to remove “the watermarks for AI systems like Claude” while describing its method, two paragraphs later, as eliminating “hidden zero-width characters, invisible spaces, and other unicode markers”.

Neither carries a caveat. Both claim an outcome that requires a detector nobody has released.

So the position is roughly the reverse of the popular one: the free repository being called snake oil documents its limits correctly, and several products charging money do not.

Where it lands, and what we have not checked

Two layers, which is the only structure that makes sense here. Delete what is literally in the file — class names, zero-width characters, metadata. Then rewrite for the part that is carried by word choice, and accept that you cannot confirm the result.

We reached the same structure independently, which is why our own pipeline reports the watermark stage as skipped rather than pretending to have done something.

The honest limit on this page: we read the documentation, we did not audit the implementation. Everything above is about whether its stated limits are accurate. Whether the rewrite is any good is a separate question and we have not measured it.

Questions

Does the GitHub watermark remover remove Claude's watermark?
It attempts the only thing that can work — rewriting the text so different words are chosen — and it says explicitly that it cannot certify the result. Nobody can, including us, because Anthropic has not released a detector. Any tool promising confirmed removal is describing something that cannot currently be verified.
Is it snake oil, like Reddit says?
Not on the evidence of its own documentation. The Reddit objection — that nobody can verify a Claude watermark — is true, but the repository does not claim to. It states the opposite in the README.
Is it safe to use?
We have not audited the code, so we will not tell you it is. It is MIT licensed and public, so you or someone you trust can read it, which is more than is true of any hosted alternative.
Do I need it if I just want to clean pasted text?
No. For copy-paste artifacts — HTML class names, zero-width characters, smart quotes — a browser-side checker does the same job in one paste with nothing to install.

Check your own text. Free, unlimited, no account, and it runs in your browser so nothing is uploaded.

Open the checker
Nick Launches — featuredNick Launches — featuredDang.ai — featuredDang.ai — featuredFazier — featuredFazier — featuredStartup Fame — featuredStartup Fame — featuredTurbo0 — featuredTurbo0 — featuredTinyLaunch — featuredTinyLaunch — featuredToolPilot — featuredToolPilot — featuredTwelve Tools — featuredTwelve Tools — featuredNick Launches — featuredNick Launches — featuredDang.ai — featuredDang.ai — featuredFazier — featuredFazier — featuredStartup Fame — featuredStartup Fame — featuredTurbo0 — featuredTurbo0 — featuredTinyLaunch — featuredTinyLaunch — featuredToolPilot — featuredToolPilot — featuredTwelve Tools — featuredTwelve Tools — featured