Compare the two writers
Switch between Write with watermark and Write without. Both paragraphs read normally. Watch the green share and the score: about 50% and close to 0 without, clearly higher with.
Change some words
Drag the edit slider. Each changed word breaks two green pairs. When about a quarter of the words are changed, the result usually drops to weak or nothing. This matches OpenAI’s 25% test.
Change one letter of the key
Edit the detector key. The same watermarked text now looks like normal text. This is why no public textGrain checker can exist.
Test your own text
Paste any text, even ChatGPT output, into the box under the demo. It will score like normal text, because it was not written with this demo key.
How an AI text watermark works, live
A hidden word watermark sounds like magic until you see one. This demo writes a paragraph the same basic way, then lets you detect it, edit it and break it. It uses the same idea as textGrain, with a public demo key.
Word watermark demo
A learning tool. It uses a public demo key and simple word swaps, not OpenAI’s method. It cannot detect real ChatGPT text.
When several words would fit, a watermarking model prefers “green” words picked by a secret key. A detector with the same key counts the green words. Normal text has about half green words. Watermarked text has clearly more. Without the key, the green words look random. That is why only OpenAI can check for textGrain.
Four things to try
The maths in one minute
For each word after the first, the detector mixes three things together: the key, the word before, and the word itself. If the result is an even number, the word is green. In normal text, about half of the words are green just by chance.
Then the detector asks: how surprising is this number of green words? With T word pairs and G green ones:
z = (G − 0.5T) ÷ √(0.25T)
A score (z) of 2.33 or more happens by chance only 1% of the time. That is the same error rate OpenAI used. Longer texts give higher scores because the evidence adds up. That is why length matters so much.
This method was published by Kirchenbauer and others in 2023 in a paper called “A Watermark for Large Language Models”. Real systems work with tokens and probabilities, not whole words from a short list.
How textGrain is different
- Secret key
Our key is public so you can play with it. OpenAI’s key is secret, and only approved researchers and expert groups can use its detector.
- How it works inside
OpenAI published a technical report but has not shared its code yet. It says it plans to make it open source. Its method works on tokens and is more subtle than our word list.
- Writing quality
Our writer can only pick from a few ready-made synonyms. A real model picks from all the words it knows. OpenAI says the quality of its answers stays about the same with textGrain on.
- Detection
Our detector counts words. A real detector works on tokens, is tested on large amounts of text, and gives a probability instead of a simple yes or no.
Questions people ask
Can this demo detect ChatGPT text?
No. It only knows its own demo key. ChatGPT text will score like any other normal text here.
Is the watermarked paragraph harder to read?
No, because every word option in the demo is a good choice. That is the goal of a good watermark: the reader cannot tell.
Why does editing hurt the watermark so much?
Each word is part of two pairs: one with the word before and one with the word after. Change one word and both pairs become random again. Enough changes spread over the text remove the extra green words.
Could someone fake a watermark?
With a known key, yes. You could pick green words on purpose. That is one more reason companies keep their keys secret and limit who can use the detector.