Skip to main content
Glama
krllagent

Claude Watermark Remover

by krllagent

Claude Watermark Remover

An open-source MCP server that removes the statistical text watermark (SynthID-style, the kind Claude and Gemini put into their output) by rewriting the wording while keeping the meaning, the structure and the formatting. It runs on your computer and talks only to OpenRouter with your own key — including OpenRouter's free models, so the whole thing can cost nothing.

Works in Claude Desktop, Claude Code, Codex, Cursor and any other MCP client.

Prefer not to deal with keys and installs? Hosted version at painintheagent.com → The same rewrite as a one-click connector for claude.ai (works in the browser and on phones, where local MCP servers cannot run), plus the AI Humanizer and detectors. $10 a month, no OpenRouter account needed. Remote MCP URL: https://painintheagent.com/mcp · API & MCP docs

What it does

  1. Masks the parts that must come back untouched: web links, email addresses, quoted spans, currency amounts and percentages.

  2. Sends the masked text to the model with one instruction set: rewrite every sentence with a different construction and word order; keep every term, name, number and the layout; keep the strength of every statement (should is not must, 17.5% is not up to 17.5%); never translate.

  3. Checks the draft locally, with no model: placeholders intact, length within 80–125% of the source, paragraphs, lines and list markers unchanged, and at least 80% of five-word sequences replaced. If a check fails, one more draft is requested; a result that breaks the layout or leaves 70–140% of the source length is an error, not a result.

  4. Restores the masked parts and returns the text with novelty_percent (the share of five-word sequences replaced).

No second model checks the meaning. The result is a draft you compare with your source — that is what the tool tells the assistant, too.

The method is the one measured in Can rewriting remove AI text watermarks? My SynthID test: a single paraphrase on Qwen3.7 Plus crossed below the reference detector's threshold in 10 of 10 English reports and kept 100% of the claims checked by the panel. This program uses a stricter prompt (terms, layout, statement strength) and sampling at temperature 0.7, which were not part of that test. Private production keys of Claude and Gemini are not published, so complete removal cannot be verified against them.

Related MCP server: automatelab-ai-seo

Install

You need an OpenRouter account and an API key from https://openrouter.ai/settings/keys. Set a credit limit on the key. With the default paid model a 1,000-character text costs about $0.001; with a free model it costs nothing (see Free models).

Claude Desktop

  1. Download claude-watermark-remover-0.1.0.mcpb (checksums in releases/SHA256SUMS).

  2. Open the file. Claude Desktop installs it as an extension and asks for your OpenRouter API key (stored by Claude Desktop, not by this program) and, optionally, a model.

  3. In a chat: "Remove the watermark from this text: …".

Claude Code

claude mcp add watermark-remover -e OPENROUTER_API_KEY=sk-or-… -- npx -y --package=https://github.com/krllagent/claude-watermark-remover/raw/main/releases/claude-watermark-remover-0.1.0.tgz claude-watermark-remover

Then in a session: "Use remove_watermark on the text in draft.md and show me the result." The key is written to Claude Code's MCP configuration on your disk (~/.claude.json or the project's .mcp.json), so keep a credit limit on it.

Codex, Cursor and other MCP clients

Install once, then add a stdio server with the command claude-watermark-remover and the environment variable OPENROUTER_API_KEY:

npm install -g https://github.com/krllagent/claude-watermark-remover/raw/main/releases/claude-watermark-remover-0.1.0.tgz

For Codex, in ~/.codex/config.toml:

[mcp_servers.watermark-remover]
command = "claude-watermark-remover"
env = { OPENROUTER_API_KEY = "sk-or-…" }

Command line

export OPENROUTER_API_KEY=sk-or-…
npx -y --package=https://github.com/krllagent/claude-watermark-remover/raw/main/releases/claude-watermark-remover-0.1.0.tgz claude-watermark-remover --text-file draft.txt

The package is a single self-contained file (dist/index.cjs, Node 22+); the tarball and the .mcpb live in releases/ with their checksums.

Prints the rewritten text; the figures (share replaced, layout, calls, seconds, cost) go to stderr. --json prints everything as JSON; --stdin reads the text from standard input; --style-file rules.md passes your writing-style rules.

Tools

Tool

What it does

remove_watermark

text (100–10,000 characters) and optional style_guidance (your writing-style rules, applied to wording only) → the rewritten text, novelty_percent, target_met, layout_kept, model, model_calls, seconds, cost_usd.

get_configuration

The model, reasoning setting and temperature in use, and the measured presets. No model call.

Texts of 750 characters (about 120 words) and more give a reliable share; on a short text one kept citation such as "(Author, 2023)" alone pulls the figure down, so short texts are processed but the number means less.

Models

WATERMARK_MODEL

Cost

Measured on a 1,316-character list text (2026-10-03)

qwen/qwen3.7-plus (default)

≈ $0.001 per 1,000 characters

2–10 s, 85–100% replaced, layout kept. The model of the published test.

qwen/qwen3.8-27b:free

free

46 s, 81% replaced, layout kept. Needs low reasoning (set automatically). Often answers 429 "busy": the server waits and asks again up to three times.

nvidia/nemotron-3-super-120b-a12b:free

free

12–25 s, 63–78% replaced, layout kept. Available only if you allow "free endpoints that may train on inputs" in OpenRouter's privacy settings — your text may then be used for training.

Any other OpenRouter model id works; a :free model gets low reasoning and busy retries by default, a paid one no reasoning. Override with WATERMARK_REASONING (none, low, medium, high), WATERMARK_TEMPERATURE (default 0.7) and WATERMARK_PROVIDERS (comma-separated OpenRouter provider slugs; the default pins qwen/qwen3.7-plus to alibaba).

Free models

OpenRouter's free models are shared and rate-limited: 20 requests a minute, and 50 requests a day for accounts that never bought credit or 1,000 a day once $10 of credit has been bought at any time. A rewrite is one or two requests. They are often busy, they think before they answer (hence 12–46 seconds), and the ones from Nvidia and Poolside are served only to accounts that allow training on inputs. Of the 22 free models listed on 2026-10-03, two rewrote our test text usably; the rest returned it unchanged, ran out of tokens while reasoning, or were busy. Full notes: docs/free-models.md.

Privacy

Your text goes to OpenRouter and from there to the provider serving the chosen model; nothing is sent anywhere else and nothing is stored by this program. With the default model and the alibaba provider the endpoint is not a zero-data-retention endpoint; check the provider's policy on the model's OpenRouter page. The free Nemotron endpoint is explicitly one that may train on inputs.

OPENROUTER_BASE_URL points the server at an API gateway instead of OpenRouter; there is no fallback to the real endpoint when the gateway fails.

Development

pnpm install
pnpm test          # unit tests, a fake OpenRouter and the bundled server over stdio
pnpm run build     # dist/index.cjs
pnpm run package   # artifacts/claude-watermark-remover-<version>.mcpb for Claude Desktop

src/core.ts is the rewrite itself: masking, the prompt, the checks. It is the same code that runs behind painintheagent.com, extracted so that it has no dependency on the service.

License

MIT. Made by Kirill Balakhonov.

Available Tools

2 tools
get_configurationRead the configured modelA
Read-onlyIdempotent

Read which OpenRouter model, reasoning setting and temperature this server uses, and the measured presets available. Makes no model call.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, idempotent, non-destructive and closed-world, so the safety profile is covered. The description adds one genuinely new behavioral fact beyond them — that invoking it triggers no model call, i.e. no cost or outbound inference — which is valuable for an agent deciding whether it is safe/cheap to call.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence that lists the returned fields first and appends the no-model-call caveat. No filler, nothing restated from the title.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no parameters and no output schema, the description carries the burden of saying what comes back, and it does: the configured model, reasoning setting, temperature, and available measured presets. Nothing an agent needs to call this correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Zero parameters, so per the rubric the baseline is 4; there is nothing parameter-wise for the description to clarify or compensate for.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Specific verb (Read) plus specific resource (the server's configuration) and an explicit enumeration of the fields returned: OpenRouter model, reasoning setting, temperature, and measured presets. The sole sibling, remove_watermark, is unrelated, so no differentiation is required.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied — an agent infers it can call this to discover current configuration. The clause 'Makes no model call' usefully signals the call is free and side-effect-light, but there is no explicit when-to-use/when-not guidance or named alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

remove_watermarkRemove the watermark, keep the textA

Remove a statistical AI watermark without humanizing: one rewrite by one model that is instructed to keep the meaning, structure, formatting and language of the text. Links, quotations, amounts and percentages are masked and return unchanged. Returns the rewritten text with novelty_percent (share of five-word sequences replaced; the target is 80%), layout_kept, model_calls and the cost OpenRouter reported. A rewrite that breaks the layout or leaves 70–140% of the source length is an error. No meaning check and no AI score are run: compare the result with the source. Texts of 750+ characters give a reliable share; shorter texts are processed but the share is coarse.

ParametersJSON Schema
NameRequiredDescriptionDefault
textYes100–10000 characters of prose. Lists and headings are fine; code and tables are not.
style_guidanceNoThe user's own writing-style rules, if any: a style skill, custom instructions or a style named in the conversation. Pass them complete and in their original wording, up to 4000 characters. They shape wording only; the model is told not to let them change facts, terms or numbers, and nothing verifies that. Omit when no style rules exist.

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations: it discloses masking behavior for links, quotations, amounts and percentages, the returned fields (novelty_percent with an 80% target, layout_kept, model_calls, cost), the error conditions (broken layout, 70–140% length), and that no meaning check or AI score runs. It also sets expectations on short-text accuracy — exactly the behavioral context annotations cannot carry.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose and mechanism, then return values and error conditions in a logical order. It is dense and slightly long, but nearly every clause carries decision-relevant information rather than padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully covers the return contract (novelty_percent, layout_kept, model_calls, cost) and the failure modes. For a two-parameter transformation tool with annotations already declaring safety, nothing an agent needs to invoke or interpret it is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for both parameters, so the baseline is 3. The description restates the masking guarantee and that style_guidance shapes wording only without verification, but adds little syntax or format meaning beyond what the schema already spells out.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (remove) plus resource (statistical AI watermark) and the mechanism (one rewrite by one model instructed to preserve meaning, structure, formatting and language), explicitly contrasting with humanizing. The single sibling get_configuration is unrelated, so there is no ambiguity an agent could stumble into.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description establishes clear context — use it to strip a watermark while keeping the text, and it notes code and tables are not supported and that 750+ characters are needed for a reliable novelty share. It never names a concrete alternative tool or an explicit when-not, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 2 tool updatesv0.1.0
    • First observedget_configuration
    • First observedremove_watermark

TDQS

A4.3/5.0

Scored across 2 tools

Disambiguation5/5

The two tools are trivially distinguishable: remove_watermark performs the rewrite (a model call), while get_configuration only reads server settings and explicitly makes no model call. There is no plausible scenario where an agent would confuse them.

Naming Consistency5/5

Both names follow a clean snake_case verb_noun pattern (remove_watermark, get_configuration) with consistent imperative verbs. The convention is predictable and readable.

Tool Count3/5

For a narrowly scoped watermark-removal server, one action plus one introspection tool is defensible, but two tools is on the thin side. There is no batch, retry, or verification operation, so the surface feels minimal.

Completeness3/5

The core lifecycle (configure -> rewrite) is present, but configuration is read-only with no setter, and the tool itself notes that no meaning check or AI-score is run, leaving verification entirely to the caller with no supporting tool. Minor but real gaps for an agent trying to validate or tune results.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    Not graded
    maintenance
    Humanizer PRO - The Best AI Text Humanizer MCP Server Transform AI-generated content into natural, human-sounding text that bypasses GPTZero, Turnitin, Originality.ai, Copyleaks, ZeroGPT, and other AI detectors. Undetectable AI content rewriting with Stealth, Academic, and SEO modes.
    3
    -
  • A
    license
    A
    quality
    C
    maintenance
    AutomateLab AI-SEO audits, scores, and rewrites web pages for AI citation eligibility, AEO and GEO. No API keys or registration. Works with Claude, Cursor, Codex, and other MCP clients. Product and documentation: https://automatelab.tech/products/mcp/ai-seo/
    20
    58 npm
    3
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Detects and fixes LLM prose patterns in text, exposing tools for auditing and improving writing quality in MCP-compatible hosts.
    15 npm
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables humanizing AI-generated text and checking AI-detection scores directly from MCP-compatible clients like Claude and Cursor using the Rephrasy API.
    2
    204 npm
    MIT