Home/Encrypt PDF/Password protect

Password protect a PDF — the kind that stops people opening it

There are two ways to password protect a PDF, and only one of them encrypts anything. This page is about that one: an open password, the kind a reader demands before it will show a single page.

Drop the PDF you want to lock

or choose a file

The qpdf engine (about 430 KB) is fetched only when you press the button, and it runs in this tab.

What an open password changes about the file

The pages stop being stored in the clear. They are encrypted with a key derived from the password you type, and what you download is ciphertext with an encryption dictionary in front of it. Open it without the password and a reader has nothing to show you: no pages, no text layer, no thumbnails.

This is the version of protected that means something. If you ever set a password on a PDF and then found a website offering to unlock it instantly, that file was a different thing wearing the same word. The next section is about why.

The two passwords, and which one is the lock

The form here has two password fields because the PDF format has two, and they do different jobs. The open password is the one that decrypts. Anyone who wants to read the file needs it, and there’s no way round it. Set only this one and you have a genuinely locked document.

The owner password isn’t a second layer of protection. It decides who may change the permission settings stored beside the file, and if you leave it blank it simply inherits the open password. It’s worth setting when you want one password to read with and a different one to administer with.

A password on the permissions isn’t encryption. The flags that stop printing, copying and editing are a request a reader chooses to honour, and the pages stay readable to anything that ignores the request. Only the open password locks the content. The print and copy page takes that distinction apart in full.

Doing it here

  1. Drop the PDF onto the page. It’s read into the tab you’re looking at, and nothing is sent anywhere.
  2. Type an open password. Leave the owner password blank unless you specifically want a second, administrative one.
  3. Pick the strength: AES-256 for anything current, AES-128 if the file has to open in an older reader.
  4. Press the button. The engine loads at that moment, encrypts the file in the tab, and the download starts on its own.

Choosing the strength

The choice matters less than the password does. A long, unique password against AES-128 is a stronger file than a six-character password against AES-256, because the attack everyone runs first is on the password, not on the cipher.

AES-256
The default, and what current tools produce. Choose it unless something forces you off it.
AES-128
For readers from around 2005 to 2010 that never learned 256. Same cipher family, shorter key.
RC4-40
The original scheme, broken for practical purposes. Not offered here at all, because the engine refuses to write it.

A password you cannot lose

Nothing on this page stores your password. It isn’t sent anywhere, and it isn’t written into the file in any recoverable form. The file holds a value derived from it, which is the entire point of encryption.

That means there’s no reset, no recovery link, and no address you can write to for help. Forget an open password and the document is gone the way a lost key is gone. Put it in a password manager before you close the tab, and open the downloaded file once while you still remember, to confirm it does what you expected.

Store the password before you download. This is the one warning on the page that can’t be undone afterwards. There’s no back door in the file, and no copy of anything on this side.

What this will not do

  • It won’t encrypt a file that is already encrypted. The tool says so and disables the button rather than producing a doubly locked file that nothing can open.
  • It won’t recover a password you have lost. No software can, which is why offers that claim to are always talking about the weaker kind of protection.
  • It won’t stop someone who knows the password from re-sharing the file, or from taking the password off and passing on a clean copy.
  • It doesn’t touch the metadata. Author, producer and creation dates stay where they were unless you clean them as a separate job.

Straight answers

Is the file uploaded to a server to be encrypted?

No. The encryption runs in the page you’re looking at, using an engine compiled to WebAssembly and loaded when you press the button. There’s no request carrying your file or your password. The engine runs inside the tab, and nothing leaves the machine.

What happens if I only set the owner password?

You get a file anyone can open, with print, copy and edit restrictions attached: the weaker arrangement. The tool requires at least one password, and if the point is to lock the file, set the open one.

Why is there no 40-bit option in the strength list?

Because RC4-40 is broken. It’s the original PDF encryption from the 1990s and current hardware walks straight through it. Rather than offer it with a warning attached, it isn’t offered.

Can I add a password to a PDF that is already protected?

Not in one step. Encrypting an already encrypted file stacks two layers that most readers refuse to open. Remove the existing password with the unlock tool first, then add the new one here.

More on encrypt pdf

The full tool, with every option: Encrypt PDF.