What an open password changes about the file
The pages stop being stored in the clear. They are encrypted with a key derived from the password you type, and what you download is ciphertext with an encryption dictionary in front of it. Open it without the password and a reader has nothing to show you: no pages, no text layer, no thumbnails.
This is the version of protected that means something. If you ever set a password on a PDF and then found a website offering to unlock it instantly, that file was a different thing wearing the same word. The next section is about why.
The two passwords, and which one is the lock
The form here has two password fields because the PDF format has two, and they do different jobs. The open password is the one that decrypts. Anyone who wants to read the file needs it, and there’s no way round it. Set only this one and you have a genuinely locked document.
The owner password isn’t a second layer of protection. It decides who may change the permission settings stored beside the file, and if you leave it blank it simply inherits the open password. It’s worth setting when you want one password to read with and a different one to administer with.
Doing it here
- Drop the PDF onto the page. It’s read into the tab you’re looking at, and nothing is sent anywhere.
- Type an open password. Leave the owner password blank unless you specifically want a second, administrative one.
- Pick the strength: AES-256 for anything current, AES-128 if the file has to open in an older reader.
- Press the button. The engine loads at that moment, encrypts the file in the tab, and the download starts on its own.
Choosing the strength
The choice matters less than the password does. A long, unique password against AES-128 is a stronger file than a six-character password against AES-256, because the attack everyone runs first is on the password, not on the cipher.
- AES-256
- The default, and what current tools produce. Choose it unless something forces you off it.
- AES-128
- For readers from around 2005 to 2010 that never learned 256. Same cipher family, shorter key.
- RC4-40
- The original scheme, broken for practical purposes. Not offered here at all, because the engine refuses to write it.
A password you cannot lose
Nothing on this page stores your password. It isn’t sent anywhere, and it isn’t written into the file in any recoverable form. The file holds a value derived from it, which is the entire point of encryption.
That means there’s no reset, no recovery link, and no address you can write to for help. Forget an open password and the document is gone the way a lost key is gone. Put it in a password manager before you close the tab, and open the downloaded file once while you still remember, to confirm it does what you expected.
What this will not do
- It won’t encrypt a file that is already encrypted. The tool says so and disables the button rather than producing a doubly locked file that nothing can open.
- It won’t recover a password you have lost. No software can, which is why offers that claim to are always talking about the weaker kind of protection.
- It won’t stop someone who knows the password from re-sharing the file, or from taking the password off and passing on a clean copy.
- It doesn’t touch the metadata. Author, producer and creation dates stay where they were unless you clean them as a separate job.
