Renda
← All guides

Do Claude Design Exports Carry a Watermark or Content Credentials?

6 October 2026 · 6 minute read

Anthropic does not document whether Claude Design exports carry C2PA Content Credentials, and it documents no visible watermark on them either. A Content Credential is the signed label Claude attaches to PNG, JPG and SVG files it produces, but as of 6 October 2026 no Claude Design export format is listed as getting one. Claude's invisible text watermark is a separate question: it applies to text Claude writes, so the copy in a design may carry it, while the HTML and CSS around that copy carry little, since Anthropic says code has "generally less watermarking".

The short version: no visible mark is documented. The text watermark covers Claude's writing, but Anthropic does not name Claude Design or HTML. Content credentials are documented for files Claude produces in the Claude apps and API, not for Claude Design exports specifically. To check a particular PNG, upload it to claude.com/check-content, which cannot read HTML, PDF or PowerPoint.

What marks does Anthropic put on Claude's output?

Anthropic uses two separate techniques, described in its help article as "(1) watermarks embedded in text, and (2) Content Credentials (C2PA) attached to files." They work differently, they are checked differently, and a design can involve both: words Claude wrote, inside a file Claude made.

MarkWhat it isWhere it livesWho can check it
Text watermarkA statistical pattern in Claude's word choicesIn the wording itselfApproved organisations, through Anthropic's private detection API
C2PA Content CredentialSigned metadata saying a file was made or processed with ClaudeAttached to the fileAnyone, with claude.com/check-content or another C2PA viewer

The text watermark has its own guide: does Claude watermark its text? explains how the word-choice pattern works and which models carry it. This page is about what that means for designs and their files.

What is C2PA, and what is a Content Credential?

C2PA, from the Coalition for Content Provenance and Authenticity, is an open standard for recording where a media file came from. A Content Credential is that record: a small, cryptographically signed block of metadata inside the file that names the tool that made or edited it. It is not visible in the image and does not change a single pixel.

Anthropic's rule is: "When Claude produces a file of a supported type (such as a .png, .jpg, or .svg), it will attach a content credential", saying the file was made or processed with Claude. It applies "only where a platform offers Claude's file generation features: in the Claude apps and the Claude Platform (API)." Unlike the text watermark, Anthropic lists content credentials for every model in its table, older ones included. A third-party summary of the API documentation says the credentials are signed by "Anthropic Content Credentials Root CA" and are documented for the Claude API itself, not for Amazon Bedrock or Google Cloud.

Does the text watermark apply to a Claude Design?

Partly, as far as anyone can tell. The watermark covers what Claude writes on every surface, and Claude Design runs inside Claude: at claude.ai/design, in any conversation since 16 September 2026, and in Claude Code as /design. But Anthropic does not mention Claude Design or HTML by name. What its explainer does cover is code: where only one word or symbol is correct there is no choice to steer, comments within code can carry the watermark, and "it will have a negligible effect on the actual code produced."

A design file is mostly code (HTML, CSS, sometimes JavaScript) around a small amount of visible copy. A reasonable reading, not confirmed by Anthropic, is that the headlines and body text Claude wrote are ordinary generated text and can carry the pattern, while the markup carries little. Post and slide copy is usually short, and Anthropic says detection "doesn't work well on small samples". Copy you wrote yourself and asked Claude to use word for word is your writing, not Claude's.

The model matters too. Claude Design launched in April 2026 on Opus 4.7, which Anthropic's table lists as not yet watermarked (older models are due by 2 December 2026). Anthropic does not say which model Claude Design uses today.

Do Claude Design exports carry C2PA content credentials?

It is not documented. Anthropic's rule covers supported files that Claude produces, and Claude Design can now export a single artboard as a PNG, but Anthropic has not said whether that PNG gets a credential. HTML, PDF, PowerPoint and zip files are outside the documented scope; Search Engine Journal noted at launch that the support article "does not mention support for HTML or PDF formats". The guide to sharing a Claude Design covers which format suits which audience.

Claude Design exportContent Credential documented?Can the free checker read it?
PNG (artboard menu, or Share, Export, PNG in a conversation)Not documentedYes, PNG is supported
PDFNot documentedNo
PowerPoint (PPTX)Not documentedNo
Standalone HTML or project .zipNot documentedNo

If you need to know about a specific PNG, the answer is one upload away: run the file through the checker described below and it will tell you whether a Claude credential is attached.

What does claude.com/check-content actually check?

Anthropic's free file checker, live since early September 2026, looks for a Content Credential from Claude. It runs in your browser and the file stays on your device. It accepts JPG, PNG, GIF, WEBP, TIFF, HEIC, AVIF, SVG, DNG, JXL, MP4, MOV, AVI, WAV, MP3, M4A and FLAC, up to 100 MB. It does not accept HTML, PDF, PowerPoint, Word or zip files, and it says plainly: "The tool does not check text."

A positive result means Claude "may have made or processed the file"; it does not say who wrote the content or which account was used. A negative result is inconclusive, for the reasons in the next section.

Why does a missing content credential prove nothing?

A content credential is metadata attached to one particular file, and it does not always survive what happens to that file afterwards. Anthropic's checker page notes that it may not find a credential in screenshots, re-saved files or converted formats. So when the checker finds nothing, it cannot tell whether Claude was never involved, whether no credential was ever attached, or whether one was lost along the way. That is why it reports a negative result as inconclusive rather than as proof that Claude was not involved.

The same logic applies to every provenance check: the absence of a label is not evidence about where an image came from. Metadata describes a file; it does not change how the content was made. Any AI disclosure you owe a client, an employer or a platform applies whatever a file's metadata says or does not say.

Frequently asked questions

Does a content credential show who made the file?

No. According to Anthropic's checker, a credential tells you that Claude may have made or processed the file. It does not identify the person who wrote the content.

Does a watermark or credential change how my design looks?

No. The text watermark is a pattern in which words were chosen, and a content credential is metadata inside the file. Neither adds a logo, a badge or anything else you can see.

Do images Claude makes in a chat carry content credentials?

By Anthropic's rule, yes: a supported file such as a .png, .jpg or .svg that Claude produces in the Claude apps or the API gets a credential. Claude does not draw pictures the way an image generator does, so in practice these are charts, graphics and SVGs it creates with code. The text watermark guide covers the words Claude writes.

How Claude's text watermark works

The companion guide covers the word-choice watermark in full: which models carry it, what editing does to it, who can run the detector and what the EU AI Act requires.

Read the guide