AI Watermark Detector · hidden characters

SynthID Detector: what it checks, and what it misses

Google opened its SynthID Detector to everyone on 7 October 2026. Here is exactly what it can tell you, what it cannot, and which half of the question a browser-based checker still covers.

Last updated

In one line

Google’s SynthID Detector reads watermarks inside images, video and audio from Google and its partners. It does not read text. It does not read file metadata. It is a website, not an API.

What Google opened, and when

On 7 October 2026 Google moved its SynthID Detector out of limited testing and opened it to everyone, in English, at synthid.com. An earlier version had been available to journalists, media professionals and researchers through a waitlist since May 2025.

Three facts from the announcement, in Google’s own numbers:

  • The portal checks images, video and audio. Text is not one of the supported content types.
  • It reads watermarks from Google, OpenAI, NVIDIA and Kakao, with Apple announced as coming soon.
  • Google says it has watermarked over 180 billion images and videos and 240,000 years of audio since 2023.

How to use it

  1. Open synthid.com and sign in. A third-party account such as Apple works.
  2. Upload one image, video or audio file. Supported formats include JPG, PNG, WEBP and HEIC for images; MP4, MOV and WEBM for video; WAV, MP3, OGG, FLAC, AAC and M4A for audio.
  3. Read the answer. It is binary: watermark detected, or watermark not detected. For video and audio it also marks which segments carry one.

Upload the highest-quality copy you have. Google’s own guidance says a heavily modified file may have a degraded signal, and that you should gather more than one point of data before reaching a conclusion.

What it cannot tell you

Google is unusually direct about the limits, and the limits are the reason this site exists. Its own FAQ states: “This is not a general AI detector.”

  • It only sees partners. A watermark is only readable if the company that made the file adopted SynthID. Anthropic is not on the partner list, so Claude output has nothing for the portal to find.
  • A negative result proves nothing. The site says so itself: the content may have come from a model without SynthID, or the watermark may have degraded.
  • It reads pixels, not metadata. The portal states that the watermark sits in the pixels and frequency components of a file, “rather than in metadata that can be lost”. That is the right design for robustness, and it means C2PA Content Credentials, EXIF and XMP are simply not part of what it checks.
  • It does not read text at all. SynthID text watermarking exists and is deployed in the Gemini app, but the portal does not accept text input.
  • It can be wrong in the other direction. Google notes rare cases where the system triggers on content that carries no watermark.

Is there a SynthID API?

No public one you can call from a web page today. Three things look like an API and none of them is one.

1. synthid.com is a portal, not an API

Google’s additional terms for the portal prohibit exactly the thing a third-party detector would have to do. You agree not to “bypass the user interface to programmatically submit requests, scrape data, or use the frontend as an automated API to run bulk media verification queries”, and not to evade quotas. Google reserves the right to suspend access for a breach.

So a detector that quietly forwarded your file to synthid.com would break those terms. It would also mean your file left your machine, which is the one thing a local checker promises not to do.

2. The AI Content Detection API is real, and closed

Google Cloud documents an AI Content Detection API on the Gemini Enterprise Agent Platform. It is a genuine REST endpoint that takes an image payload. Three things rule it out for a public checker today:

  • It is in Private Preview. You apply for access through a form; there is no self-service signup and no published price.
  • It accepts JPEG, PNG and WebP only. No video, no audio, no text.
  • The documentation states plainly that “Support for C2PA metadata detection is not included.”

The API does have one clear advantage over the portal: it does not store or retain processed images. If Google opens it generally, that is the endpoint a tool like this one would want.

3. synthid-text is open source, and is not a detector you can point at a stranger’s text

Google open-sourced SynthID Text as google-deepmind/synthid-text under Apache-2.0, and it is also published on PyPI. It ships both the watermarker and a Bayesian detector, so at first glance it looks like the missing piece.

It is not. The detector needs the same secret keys and ngram_len that were used to watermark the text. Google’s documentation says each watermarking configuration “should be stored securely and privately”, because otherwise the watermark is trivially replicable. Without the key there is no signal to score.

The library is built for a provider that wants to watermark its own output and then verify it later. It cannot read text that someone else generated.

What this site does that the SynthID Detector does not

The three gaps above are exactly where a browser-based checker still earns its place. The honest division of labour:

Where each question gets its answer
Questionsynthid.comThis site
Was this image, video or audio made by Gemini, ChatGPT, NVIDIA or Kakao? Yes. This is the authoritative answer. No. Use theirs.
Does this file still carry C2PA Content Credentials, EXIF or XMP? Not checked. It reads pixels, not metadata. Yes. We parse the manifest and name the claim generator.
Is there a hidden payload in this text? Text is not a supported input. Yes. Zero-width characters, tag characters, variation selectors, direction overrides.
Does the file leave my machine? Yes. You upload it to Google, which says it deletes it immediately. No. Nothing is uploaded; the check runs in the page.

Read that as a division of labour, not a competition. Use synthid.com for the question it was built to answer. Use the checker for text and for metadata. Neither one covers the whole field, and any tool that claims to is worth a second look.

Frequently asked

Does Google’s detector work on ChatGPT text?

No, and neither does anything else. The portal does not accept text. OpenAI is a SynthID partner for media, not for text. No third party can read a statistical text watermark, because reading one needs the key that wrote it.

Can I check a SynthID watermark without uploading the file?

No. The watermark lives in the pixels, and only Google holds the detector. There is no offline route, and no API to call. That is a real cost of the check, and it is why this site still does the metadata half locally.

Is synthid.com free?

Yes. It is free, requires a sign-in, and applies a daily quota. Uploaded media is processed in real time and Google says it is deleted once results are returned; a digital signature of the file is kept for 24 hours to enforce the quota.

Does it detect Claude or Midjourney content?

Not through SynthID. Anthropic and Midjourney are not in the partner list, so there is no watermark for the portal to find. A Midjourney image may still carry C2PA Content Credentials, which is metadata and is what the checker reads.

I got “watermark not detected”. Is the image human-made?

No. That is the single most common misreading of the result. A negative result means the detector found no watermark from a company that uses SynthID. The image may be AI-generated by a model outside the programme, or the watermark may have been degraded by editing or re-encoding.

Sources