AI Watermark Detector · hidden characters

Runs locally · nothing uploaded

AI watermark detector

An AI watermark detector that runs entirely in your browser. Paste text or drop an image — we show you every invisible character, every direction override and every provenance tag inside it, then tell you plainly what we cannot check.

  • Processed in your browser
  • No upload, no account
  • Open source, no tracking
offline · local only
0 chars
Try a sample:

Tip: press ⌘↵ to run. Everything stays on this device.

Nothing to show. Paste text above, or try one of the samples to see what a real hidden payload looks like.

How it works

Three steps, no sign-up, and no request ever leaves your machine.

01

Paste or drop

Text goes straight into a textarea. Images are read with the browser's own file API. Neither one is sent anywhere — there is no server to send them to.

02

We walk every code point

Each character is classified against the Unicode ranges that are invisible, reserved, or can reorder what you see. Payloads carried in tag characters or variation selectors are decoded and shown to you.

03

You see, then decide

Hidden characters are rendered as chips in place, so you can see exactly where they sat. Copy a cleaned version when you are done, or keep the original if it is legitimate.

What this checks — and what it does not

Most tools in this category blur this line. We think the honest version is more useful, so here is the whole boundary in one place.

We do detect

  • Zero-width characters — U+200B, U+200C, U+200D, U+FEFF and friends, all in the Unicode General Punctuation block. The standard way to stamp a unique fingerprint on every copy of a document.
  • Unicode tag characters (U+E0000–U+E007F, chart UE0000). An invisible channel that can carry a whole hidden message. We decode it and show you the text.
  • Variation selector runs — a documented way to smuggle bytes past filters.
  • Direction overrides (U+202A–U+202E, U+2066–U+2069) — the mechanism behind Trojan Source, where code reads differently than it runs.
  • Look-alike letters from Cyrillic, Greek and fullwidth ranges that render as Latin.
  • Private-use and noncharacter code points, which have no agreed meaning at all.
  • Image provenance — C2PA Content Credentials, EXIF, XMP and IPTC, including the IPTC trainedAlgorithmicMedia declaration and embedded Stable Diffusion or ComfyUI parameters.

We do not detect

  • Google SynthID. It has no public detector. No website can read it for you, and any page that claims otherwise is guessing. Use Google's own tools if you need that answer.
  • Statistical text watermarks. Detecting these needs the model provider's key. It cannot be done from the outside, by us or anyone else.
  • Whether a human or a model wrote a paragraph. We inspect the bytes, not the style. We will not guess at authorship and dress it up as a score.
  • Anything that has been stripped. Social platforms remove metadata on upload. A clean result here means the file is clean now — not that it was always.
Why we say this out loud. Plenty of tools label a byte-order mark as an “AI watermark”. It is not. Exaggerating what you can see is how a detector loses the right to be believed.

Frequently asked questions

Can this detect a ChatGPT, Claude or Gemini watermark?

Partly, and we will be precise about which part.

For text: what we can find is hidden characters — zero-width code points, tag characters, variation selectors. If a service stamped your copy with an invisible fingerprint, that fingerprint is made of exactly these characters, and we will surface it and decode it. What we cannot do is detect a statistical watermark, where the word choices themselves are biased by a secret key. That requires the provider's detector.

For images: we read C2PA Content Credentials, which is what OpenAI attaches to DALL·E output, and we read the IPTC trainedAlgorithmicMedia declaration that Adobe Firefly and others write. If the file still carries its manifest, we will show you the claim generator. If the manifest was stripped, we cannot recover it.

What is an AI watermark, exactly?

The word covers three different things, which is why so much of this category is confusing:

1. Hidden characters. Invisible code points inserted into text. A fingerprint, not a message. This is what a plain text editor will never show you.

2. Metadata and manifests. C2PA Content Credentials, EXIF fields, XMP properties. Signed or unsigned statements attached to a file. Trivially removable.

3. Statistical watermarks. Biases baked into the model's sampling, so the output carries a pattern only the provider's key can detect. SynthID for images is this kind. Nothing outside the provider can read it.

This tool handles the first two completely, and says plainly that the third is out of reach for everyone.

What are zero-width characters and why do they matter?

They are real Unicode code points that occupy no width when rendered: U+200B zero-width space, U+200C zero-width non-joiner, U+200D zero-width joiner, U+FEFF byte-order mark. You cannot see them in a browser, a chat window or a word processor.

They matter for two reasons. First, they are how a document gets a per-copy fingerprint: encode an account ID as a pattern of zero-width characters and you can find out who leaked it. Second, they break things quietly — a string with an invisible character in it will not match a search, will not equal itself after a round trip through some tools, and will fail validation for no visible reason.

What is a Unicode tag character?

The range U+E0020 to U+E007E is a direct copy of printable ASCII, mapped into an invisible plane of Unicode. Put them together and you get a hidden message that renders as nothing at all.

They were deprecated in 2021 but never removed, so they still work. This is the technique behind prompt injection hidden in a document, and behind text that reads one way to you and another way to a model. Because the mapping is exact, we can decode the payload and show you the message rather than just counting characters.

What is Trojan Source?

A class of attack published in 2021 where bidirectional control characters make source code display in a different order than it executes. A reviewer approves one thing; the compiler sees another.

The characters involved are U+202A–U+202E and U+2066–U+2069. They have legitimate uses in right-to-left languages, which is what makes them dangerous — a single stray override in a file of English code is not something a human eye will catch.

Is the text or image I paste uploaded anywhere?

No. There is no server. The analysis is a few hundred lines of JavaScript that run in the page you already loaded.

You can confirm it yourself: disconnect from the network after the page loads and everything still works. The page also ships a strict Content-Security-Policy that blocks outbound connections, so even a bug could not leak your text.

Does stripping metadata make an image undetectable?

It removes the provenance record, yes — but it does not make the image “undetectable”, because there is nothing else here to detect in the first place.

This is worth being blunt about. A camera photo and an AI image are the same kind of file. Without metadata or a statistical watermark, there is no property of the pixels that reliably says “generated”. Tools that return a confident percentage for every image are returning a guess dressed as a measurement.

Why does a clean result not mean the text is safe?

Because we only report what is in the bytes right now. Text that passed through a chat interface, a CMS or a copy-paste step may already have lost whatever was attached to it. Equally, a clean result on a file you just received means that copy is clean — not that the original was.

Treat a clean result as “nothing hidden in this copy”, which is a real and useful answer, rather than “nothing was ever there”.