Security

Protect PDF with a password — encrypted in your browser

Add a genuine password that every PDF reader will ask for. The encryption runs in your browser using a WebAssembly version of Python’s pypdf library, so your password and your document never leave your device.

No upload Files stay in your browser Free, no signup Works offline

How to password protect a PDF

Add the PDF

Drop the file above. The first time you use this tool, your browser downloads the encryption engine once (about 12 MB) and caches it.

Set the password

Choose a strong password, repeat it to avoid typos, and optionally set an owner password that keeps printing and editing rights for you.

Encrypt and download

Press “Protect PDF”. The file is written with AES encryption and downloads ready to send. Store the password safely.

Encryption strength options: AES-128 (recommended), AES-256 (strongest) and RC4-128 (maximum compatibility with older software).

Features

Real encryption

Standard PDF security handlers. Readers show a password prompt — this is not a cosmetic lock.

Zero transmission

The password is used to derive the key inside your browser tab. It is never sent, logged or stored anywhere.

Print and copy permissions

Decide whether the recipient may print, copy text, or edit the document.

Widest compatibility

Choose AES-128 for a balance of strength and support, or RC4-128 for maximum compatibility with legacy software.

Fast after the first run

The encryption engine is cached by your browser, so later files are protected in a couple of seconds.

Free and unlimited

Protect as many documents as you like. No signup, no account, no file limit.

What PDF password protection really does

A protected PDF is not locked in the sense that a ZIP with a password is locked. The PDF standard defines a security handler, and the file stores the encrypted content together with the parameters needed to derive a decryption key from the password.

When a reader opens the file it applies the password, derives the key, and decrypts the pages in memory. Without the password, a reader cannot even render the first page — which is why a properly encrypted PDF is genuinely unreadable rather than merely hidden.

There are two passwords in the standard. The user password is what a reader asks for and what allows someone to open and read the document. The owner password controls permissions: it is what you would give your own software to unlock printing or editing while everyone else is restricted. If you only set one, both roles are filled by the same password, which is fine for personal documents.

Choosing an encryption strength without overthinking it

RC4-128 is the oldest of the three and the most widely supported. Every PDF reader made in the last twenty-five years handles it, including very old versions of Adobe Reader, ancient government portal viewers and specialised printing software. It is technically weaker than AES but remains far beyond practical attack for a well-chosen password.

AES-128 is the sensible modern default. It is strong, it has been supported by Adobe Reader since version 7 in 2005, and it opens in Chrome, Edge, Firefox, Safari, all mobile PDF apps and virtually every PDF library.

AES-256 is the strongest option and the current recommendation of the PDF 2.0 standard. Support is nearly universal in software released in the last decade, but some older tools and a few legacy government viewers still cannot open it.

The practical recommendation: AES-128 for anything you are sending to another person or an organisation, AES-256 for storage and archival of your own files, and RC4-128 only if you have already hit a compatibility problem.

What makes a PDF password actually strong

All three algorithms are vulnerable to the same thing: a guessable password. Encryption limits how many attempts an attacker can make per second, but it does not stop a dictionary attack against “123456” or your date of birth.

Length matters more than complexity. A five-word passphrase is far stronger than an eight-character string of symbols, and much easier to remember. “indigoTractorMorning42” is both stronger and simpler than “P@ss!23”.

Avoid: your name, your date of birth, your phone number, the document’s own subject (“salary”, “aadhaar”), the current year, and anything reused from another account. If you reuse a password that has appeared in a breach, and the attacker knows that, the encryption is irrelevant.

Store the password in a password manager, and keep a note somewhere you would find it if you needed the file in ten years. There is no recovery mechanism — a protected PDF cannot be opened without its password, by us or by anyone else. That is the point of the feature, and it is also its only real risk.

Permissions versus protection

The permission checkboxes — allow printing, allow copying, allow editing — are properties of the owner password. They are honoured by well-behaved PDF software, and ignored by software that chooses to ignore them.

Treat them as clear instructions to legitimate users rather than an unbreakable technical control. A document marked “printing not allowed” will not print from Adobe Reader, but a determined person with different tools will not be stopped by the flag.

The user password, by contrast, is real: without it the pages cannot be decrypted at all. That is the part that protects a confidential document. Use permissions to communicate intent; rely on the password and, where you need more, on simply not sharing the file.

For a layered approach: password-protect the document, watermark it with the recipient’s name, and compress it so it is small enough to transmit efficiently. All three take under a minute together, and all three run in this browser.

Frequently asked questions

Is my password sent to your server?

No. There is no server-side processing code on this site, so there is nothing for it to be sent to. The encryption runs in your browser using a WebAssembly runtime, and the password is used to derive the key inside that tab. It is discarded when you close the page.

Which encryption should I choose?

AES-128 for anything you send to other people or organisations — it is strong and universally supported. AES-256 for your own archival files. RC4-128 only if you have hit a compatibility problem with older software.

Can you recover my PDF if I forget the password?

No — and neither can anyone else. That is what encryption means. A protected PDF is genuinely unopenable without the password, so store it in a password manager before you close the tab.

What is an owner password?

An owner password unlocks the document’s permissions, such as printing or editing, without being needed to open it. Set one if you want to keep full rights for yourself while recipients can only read.

Do the print and copy permissions really work?

They are respected by mainstream PDF software but can be ignored by other tools. Treat them as clear instructions rather than an unbreakable control. The user password is the part that genuinely protects the content.

Why does the first use take longer?

The encryption engine — a WebAssembly runtime plus the pypdf library — is about 12 MB and is downloaded on first use, then cached by your browser. Later documents are protected in a few seconds.

Will the protected PDF open on a phone?

Yes. Every mainstream mobile PDF reader supports AES-128 and RC4-128, and modern ones support AES-256 as well. You will need to type the password on the phone the first time.

Can I protect several PDFs at once?

This tool protects one document at a time. Run it again for each file — the engine stays loaded, so each subsequent file takes only a couple of seconds.

Written and maintained by the PDFUtilise team. Last reviewed: 2026-10-07. Found a problem with this tool? Tell us — we fix reported bugs fast.