Drag & Drop a PDF file here
or click to choose a PDF from your device
✅ .PDF · Local Browser EncryptionLock a PDF with real password encryption directly in your browser. Require a password to open the document, choose optional printing, editing and copying permissions, and download a separate protected PDF without sending the file or password to a conversion server.
Choose an unencrypted PDF, then set a strong document-open password. The QPDF WebAssembly security engine encrypts the PDF locally and creates a separate password-protected copy.
Drag & Drop a PDF file here
or click to choose a PDF from your device
✅ .PDF · Local Browser EncryptionThis Protect PDF tool focuses on actual PDF Standard Security Handler encryption rather than renaming, compressing or wrapping the document in a proprietary archive.
Add PDF password security without installing a desktop application or uploading the document to a conversion server.
PDF password security combines cryptographic encryption with optional permission flags. Understanding the difference helps you choose settings that match the real risk.
When you add a document open password, compatible PDF software must derive the file's encryption key from a correct password before it can decrypt protected strings and streams. This is fundamentally different from merely hiding controls in a viewer. A correctly encrypted PDF cannot normally be opened as readable document content without a valid password or the underlying encryption key.
PDF also supports an owner or permissions password. Adobe describes document-open passwords and permissions passwords as different security roles: the open password controls access to the PDF, while the permissions password can control actions such as editing, printing and copying. See Adobe's current PDF password security overview.
QPDF's encryption documentation makes an important distinction: encryption protects the document data, while PDF printing/editing/copying restrictions depend on the reader honoring permission flags. Software that has already decrypted the document necessarily has access to the encryption key and can technically ignore those restrictions. For that reason, permission controls should be treated as cooperative document-policy controls—not as an absolute way to stop every screenshot, extraction technique or determined recipient.
Use AES-256 for modern PDF protection unless a specific legacy compatibility requirement gives you a reason to choose otherwise.
| Security Option | Strength | Compatibility | Recommended Use |
|---|---|---|---|
| AES-256 | Strong modern PDF encryption | Modern mainstream PDF readers | Default for confidential documents |
| AES-128 | Strong but shorter key | Useful for some older PDF workflows | Only when compatibility requires it |
| 128-bit RC4 | Obsolete / insecure | Old software | Not offered by this page |
| 40-bit RC4 | Insecure | Very old readers | Not offered by this page |
QPDF's security documentation recommends AES for secure password-based PDF encryption and specifically advises using 256-bit encryption rather than obsolete 40-bit or non-AES 128-bit modes. You can review the technical background in the official QPDF PDF encryption documentation.
A secure setup uses the correct password type for the job rather than treating every PDF password as interchangeable.
| Capability | Open / User Password | Owner / Permissions Password |
|---|---|---|
| Required to view encrypted content | Yes | Can also grant access |
| Normal recipient credential | Yes | Usually keep private |
| Controls permission settings | Restricted role | Full permissions role |
| Best shared with recipient | When authorized to view | Generally no |
| Should be different when restrictions matter | Yes | Use a separate strong value |
If the same password is used for normal opening and owner access, anyone who knows the reading password may also possess the credential intended to override document permissions. When restrictions are important, use a separate owner password that is not distributed to ordinary recipients. The tool requires an owner password when you select restrictive permission settings.
PDF permission flags can communicate and enforce allowed actions in conforming viewers, but they are not a substitute for controlling who receives the file.
| Permission | Available Settings | What It Means | Important Limitation |
|---|---|---|---|
| Printing | Full / low resolution / none | Requests the viewer to limit document printing | Viewer software must honor the permission |
| Editing | All / annotation / forms / assembly / none | Controls categories of document modifications | Not a guarantee against all external reconstruction |
| Copying | Allow / disallow | Controls extraction permission for text and images | Cannot prevent photographing or retyping visible information |
| Open access | Password required | Cryptographically protects document contents from casual unauthorized access | Password strength and handling remain critical |
Adobe Acrobat exposes similar permission categories for printing, changes and copying. Adobe's official PDF printing, editing and copying restriction guide explains how these settings are represented in Acrobat's security workflow.
Password-protected PDFs are commonly used when sensitive documents must travel through ordinary storage, email or messaging workflows.
AES-256 does not compensate for a weak, reused or easily guessed password. Credential quality is a core part of PDF security.
A long unique passphrase is generally easier to remember and harder to guess than a short password with predictable symbol substitutions.
The PDF password should be unique to the document or sharing context rather than copied from email, banking or workplace credentials.
Names, birthdays, invoice numbers, client names and filenames are often obvious to the same person who receives the PDF.
For high-value documents, generate and store a unique credential in an approved password manager instead of relying on memory alone.
If you email the encrypted PDF, consider sending the password through a different trusted channel rather than in the same message.
Protect a copy rather than making the encrypted PDF your only surviving file. This prevents a forgotten password from becoming a data-loss event.
A password-protection tool handles two sensitive things at once—the document and its password—so local processing is especially valuable.
The selected file is read with browser APIs and passed to QPDF compiled to WebAssembly. Encryption happens in browser memory, and the resulting PDF bytes are downloaded through a local Blob. This page does not require sending your PDF or password to a ProPDFMaker conversion endpoint.
Good security depends on the complete workflow, not just the encryption checkbox.
Encryption protects the file before authorized access. Once a recipient legitimately opens a PDF, no permission flag can absolutely prevent screenshots, photography, manual transcription or information being recreated in another document. Use PDF protection as one layer in an appropriate sharing policy.
Printing, copying and modification permissions are honored by conforming PDF viewers, but they do not constitute unbreakable DRM. QPDF explicitly documents that a program capable of decrypting the file has the key and could choose not to enforce the restrictions. The strongest control is still limiting who receives the open password.
Encrypting a PDF does not prove who created it, whether it was approved by a particular signer, or whether it was altered before encryption. Digital signatures and certificates address authenticity and integrity questions that are different from confidentiality.
Encrypted PDFs can be harder for indexing systems, document-management software, accessibility pipelines, search tools and archival systems to process. Before encrypting a long-term record, check the policy of the organization or repository that must receive it.
Most failures relate to existing encryption, invalid PDFs, browser memory or security-engine loading rather than the password itself.
This page intentionally stops rather than stacking unknown security settings. Use the correct current password to unlock or change the existing protection first.
The open password and confirmation must match exactly, including capitalization, spaces and punctuation.
When printing, editing or copying is restricted, use a separate owner password so normal recipients do not also receive the permissions credential.
A malformed PDF may need repair before QPDF can safely rewrite it. Open and verify the original file before applying security.
The first protection attempt loads a WebAssembly component. Strict network, CSP or browser settings may block that dependency on some hosted setups.
Large PDFs are staged in browser/WebAssembly memory during processing. Close other tabs or use a desktop device with more available RAM.
A deeper explanation of encryption, viewer compatibility, password handling, permission settings and secure PDF sharing practices.
In a normal document-open password workflow, the password participates in the standard security-handler process used to retrieve the PDF's encryption key. The file's protected strings and streams are encrypted, and a compatible reader needs the correct credential to recover readable document data. This is why a password-protected PDF is different from a webpage that merely asks for a PIN before offering an unencrypted download.
Older PDF encryption methods included weak RC4 modes. QPDF's documentation recommends AES and states that 256-bit encryption is the appropriate modern choice instead of legacy 40-bit or non-AES 128-bit security. AES-256 is therefore selected by default on this page.
The output uses standard PDF encryption produced by QPDF rather than a proprietary container. Modern PDF readers that implement the relevant PDF security handler should prompt for the document-open password. Compatibility can vary with very old software, which is why a 128-bit AES option is exposed for specialized legacy workflows.
No. The browser creates a new encrypted byte stream and downloads it under a protected filename. Your selected source file on disk is not overwritten by browser JavaScript. Keeping that original is strongly recommended in case you lose the password or later need a clean archival copy.
The PDF standard supports configurations where a document opens without a user password but still carries owner-password permission restrictions. This page is intentionally centered on genuine access protection, so it requires a non-empty open password. That reduces ambiguity about what “Protect PDF” means to ordinary users.
Standard document encryption is applied at the PDF file level rather than as a simple per-page password switch. If only some pages are sensitive, first use a PDF splitter or page-extraction tool to create a separate document, then protect that PDF.
Usually complete structural edits before encryption. If you need to merge PDFs, compress a PDF, rotate pages or add a watermark, doing that first avoids repeatedly decrypting and re-encrypting the document. Protect the final delivery copy at the end of the workflow.
Yes, assuming the email system accepts the attachment size and encrypted PDFs are allowed by organizational policy. For sensitive documents, transmitting the password through a different trusted channel can reduce the risk of sending both the encrypted file and its credential to the same compromised inbox.
This browser tool does not keep a password-recovery database. Strong encryption is valuable precisely because the file cannot simply ask ProPDFMaker for a hidden copy of your password. Retain an unprotected original and store the credential in an approved secure location.
Finish document edits before protection, or use related tools when an existing PDF already has security applied.
Answers to common questions about PDF passwords, AES encryption, printing restrictions, privacy, password recovery and compatibility.
Select an unencrypted PDF above, choose a strong open password and AES security settings, then download a protected copy created directly in your browser.
🔒 Open Protect PDF Tool ↑