Zerowidth CleanerAll measured guides

CLAUDE WATERMARK REMOVER · PRACTICAL TEST

Can cleaning JSON silently overwrite a value?

Yes. Removing a hidden character from a JSON key can turn two distinct keys into the same key. Parse a copy, inspect decoded keys, and detect collisions before changing the original.

Tested October 4, 2026 · v24.19.0 · 3 measured runs

Open the Claude text cleaner · Full measured data

Code-point comparison for Literal hidden key

Measured inputs and outputs

These are locally constructed test strings, not evidence that Claude inserts these characters. We executed the saved homepage script snapshot with a minimal DOM harness and compared exact strings. Invisible removal is enabled; the dash mode appears in each row. The observations below test this page's specific question. We make no detector-score or statistical-watermark removal claim.

Before and after observations; full code points and strings are in the JSON download.
Fixture and modeInput string and code pointsOutput and cleaner statusObserved before / after
Literal hidden key
direct string / keep
"{\"user\":1,\"us​er\":2}"
U+007B U+0022 U+0075 U+0073 U+0065 U+0072 U+0022 U+003A U+0031 U+002C U+0022 U+0075 U+0073 U+200B U+0065 U+0072 U+0022 U+003A U+00 …
"{\"user\":1,\"user\":2}"
Removed 1 invisible character
{"keys":["user","us​er"],"user":1,"values":[1,2]}
{"keys":["user"],"user":2,"values":[2]}
Escaped hidden key
direct string / keep
"{\"user\":1,\"us\\u200ber\":2}"
U+007B U+0022 U+0075 U+0073 U+0065 U+0072 U+0022 U+003A U+0031 U+002C U+0022 U+0075 U+0073 U+005C U+0075 U+0032 U+0030 U+0030 U+00 …
"{\"user\":1,\"us\\u200ber\":2}"
No selected invisible characters found
{"keys":["user","us​er"],"user":1,"values":[1,2]}
{"keys":["user","us​er"],"user":1,"values":[1,2]}
Hidden character in a value
direct string / keep
"{\"note\":\"re​view\"}"
U+007B U+0022 U+006E U+006F U+0074 U+0065 U+0022 U+003A U+0022 U+0072 U+0065 U+200B U+0076 U+0069 U+0065 U+0077 U+0022 U+007D
"{\"note\":\"review\"}"
Removed 1 invisible character
{"keys":["note"],"user":null,"values":["re​view"]}
{"keys":["note"],"user":null,"values":["review"]}

Our measured collision

The literal-key fixture starts with two properties: user and us + U+200B + er. The homepage cleaner deletes that actual U+200B. Both keys then spell user. Parsing the cleaned JSON in Node.js yields one key with value 2; the earlier value 1 is lost in that parsed object. The saved output records both the complete JSON string and its parsed keys. This is a data-integrity failure even though parsing succeeds. A parser success message cannot replace a collision check.

Why the escaped fixture behaves differently

The second fixture contains six ASCII characters spelling a JSON Unicode escape. Our cleaner processes raw text and leaves that escape unchanged. JSON.parse subsequently decodes it into U+200B inside the property name, leaving two distinct properties. Therefore a zero removal count on raw JSON does not certify that decoded strings lack hidden characters. Inspect both representations deliberately; never run a replace over every escape sequence, because many escapes are legitimate content. The third fixture changes only a string value and does not merge keys.

A safe JSON workflow

Keep the source file and parse it without editing. For each object, compute proposed cleaned keys, group originals by proposed key, and stop if a group contains more than one original. Decide which field is intended using the schema or data owner. Apply approved transformations to decoded values and serialize with JSON.stringify. Recheck required fields, identifiers and types. This experiment covers these three fixtures and JavaScript parsing; another parser may reject duplicate names or retain them differently. RFC 8259 advises unique object names and describes interoperability problems when names repeat. The homepage has no JSON parser, schema checker or collision warning.

Reproduce this test

Save reproduce.cjs and tested-app.js in the same folder. Run the command below with Node.js. The harness prints its runtime, script SHA-256 and every measured row. Compare those rows with the original record. Using a newer script or runtime creates a new experiment; retain the version information with your rerun.

node reproduce.cjs

Reference and next check

JSON grammar and interoperability provides the relevant primary definition. The table and fixture analysis are original measurements. For broader inspection, use our Unicode inspector. Read the scope distinction before interpreting cleanup as a watermark result.