Protect / Unlock PDF
Password-protect or unlock your PDF files.
Drop a PDF to lock or unlock
or click to browse
Password-protect or unlock your PDF files.
or click to browse
Switch to Unlock mode, drop in the protected PDF, enter the password you already know, and download an unencrypted copy. This removes protection from a document you can open — it is not a recovery tool for a forgotten password.
Both directions run entirely in this browser tab. The document and the password never leave your device, which is rather the point for a tool whose whole subject is confidentiality.
This matters more than it sounds, because a good number of "protect PDF" tools do something considerably weaker than the word implies.
Encryption here is AES-256 under the PDF 2.0 specification, applied by qpdf compiled to WebAssembly — the same engine used in server-side document pipelines, running locally in your browser. The file's contents are genuinely encrypted. Without the password there is nothing to read: not by opening it in another reader, not by extracting the text, not by examining the raw bytes.
The weak alternatives are worth naming so you can recognise them. Some tools set a permissions flag, which politely asks readers not to allow printing or copying and which any reader is free to ignore. Others use 40-bit RC4, an obsolete scheme broken decades ago. Others rasterise every page into images and call the result protected, which destroys your text layer, bloats the file, and protects nothing.
None of that happens here. Your text stays selectable and searchable inside the encrypted document — once the reader supplies the password, they get your real document, with working fonts, copyable text and sharp vector art, not a stack of pictures.
A PDF carries a user password, which is the one that opens the document, and an owner password, which governs what may be done with it once open. Both are set here, and the owner password is generated as an independent random value rather than being derived from yours — so knowing the open password does not hand someone the permissions password as well.
The permissions applied are chosen to keep the document useful to the person you sent it to:
The real security boundary is the open password. Everything past that point is a courtesy setting that a determined reader's software can disregard — which is exactly why the encryption itself is the part worth getting right.
AES-256 is not the weak link in this system. The password is.
A short or guessable password can be attacked offline: an encrypted PDF is a file someone can try passwords against as fast as their hardware allows, with no lockout. Length is what defeats that — a passphrase of four unrelated words beats a short string of substituted characters comfortably, and is easier to type over the phone.
Then there is delivery, which is where most real-world protection quietly fails. Emailing the protected PDF and the password in the same message protects nothing at all. Send them by different routes: the document by email, the password by phone or a messaging app. For documents you send regularly to the same person, agree a password once and reuse the channel rather than the password.
And keep an unprotected master copy somewhere safe. There is no recovery path for a PDF password — no reset, no support desk, no back door. That is the property that makes the encryption worth having, and the reason to be careful with it.
Removing protection is just as routine: unlocking your own archived files so they can be searched, or stripping a bank's automatic statement password before filing a year of statements.
Encryption stops other tools reading the content — deliberately. So a protected PDF is the last step, not the first. Do the work on the unprotected document — merge, compress, sign, watermark — and encrypt at the end.
If you already have a protected file and need to change it, unlock it here, make the change, then protect it again. That round trip is normal and loses nothing, because unlocking restores the document exactly as it was.
AES-256 under the PDF 2.0 specification, applied by qpdf compiled to WebAssembly and running in your browser. This is real encryption — the contents are unreadable without the password, in any reader. It is not a permissions flag, and it is not the obsolete 40-bit RC4 that some tools still use.
No, and no legitimate tool can — that is the property that makes the encryption worth using. Unlock mode removes protection from a document when you supply the correct password. Keep an unencrypted master copy of anything you protect, stored somewhere safe.
Printing and copying are deliberately left enabled so the document stays usable and accessible to screen readers; modification is denied. Those permission flags rely on the reader honouring them, so treat them as intent rather than enforcement. The genuine protection is the open password, which is enforced cryptographically.
Yes, and it is safer than the alternatives. The document and the password are processed by WebAssembly running inside this browser tab — neither is transmitted, and nothing is stored. You can disconnect from the network before you start and both protecting and unlocking still work, which is a test worth doing if the file is sensitive.
Yes. Once the password is entered, the recipient gets your real document — selectable text, embedded fonts, sharp vector graphics, working search. Nothing is converted to images, which is what some tools do and which quietly destroys the document's usefulness.
Yes, and that is the right order: fill, sign, then protect. Encrypt last, because encryption prevents other tools from reading the file.
Barely. Encryption transforms the existing content rather than adding to it, so a protected file is close to the size of the original. If you also need it smaller, compress first and protect afterwards.
Yes. AES-256 is part of the PDF standard and is supported by Acrobat, Preview, current browsers and mainstream phone readers. Some very old software predates PDF 2.0 encryption; if a recipient hits that, they need a current reader.
Privacy: Encryption and decryption both run in-browser through qpdf (WebAssembly, AES-256). No passwords, no file contents, and no metadata cross the network.