How green-list watermarking works
The best-documented scheme comes from Kirchenbauer et al. (2023). Before generating each token, the model uses a keyed pseudorandom function, seeded by the preceding token, to split its vocabulary into a “green” list and a “red” list. Generation is then nudged toward green tokens.
The nudge is small enough that the output still reads naturally, but across hundreds of tokens the excess of green choices becomes statistically obvious. Detection is a one-proportion z test: count the green tokens, compare to what chance would give, and read off how unlikely the excess is.
The elegance is that the mark lives in the choice between near-equivalent words, so it survives light editing and does not degrade quality, and it is invisible without the key.
Why the key is the whole story
The partition is determined by a secret. Without it, you cannot tell which words were green, so you cannot count them, so there is no test to run. This is a deliberate property, not an oversight, because a publicly checkable mark would be a publicly removable one.
The practical consequence is that no third-party tool, including this one, can detect a specific vendor’s mark unless that vendor publishes a detection key or grants access to one. Any tool claiming to detect “the Claude watermark” without a key is not doing what it says.
WatermarkRemoverPro therefore tests the keys it holds and names them on every result. It ships a published open reference key so the machinery is auditable, and you can mark text under it yourself on our verify page and watch the detector find it, and it accepts vendor or institution keys through configuration.
What a mark would and would not prove
A detected mark is evidence that text carrying that key’s signature is present. It is not proof of authorship: text can be quoted, translated, edited, or produced collaboratively, and a mark travels with the words regardless of how they got into the document.
An absent mark proves even less. Marks are not applied by every system, they weaken under paraphrase and translation, and they are undetectable without the key. Absence is consistent with a great many histories, only one of which is “a person wrote every word”.
Wherever this page describes a result: a detected mark is not proof of authorship, and an absent mark is not proof of human authorship. WatermarkRemoverPro's on-device rewrite can reduce detectable evidence but cannot guarantee defeating a vendor's undisclosed watermark, on any tier.