Online Tool Store Online Tool Store
🔐 PDF Tools

· 8 min read

How to Password Protect a PDF in Your Browser

Manesh Jayawardhana

CIO & Co-founder

Manesh Jayawardhana is the CIO and Co-Founder of Ceyentra Technologies, where he has spent over nine years leading the design and delivery of software solutions for clients across the globe, spanning web, mobile, AI, and capital market systems. He has grown Online Tool Store's engineering team from the ground up while steering the company's technical direction. His writing draws on this breadth of experience building and shipping software across a wide range of industries and markets. View on LinkedIn

Share

How to Password Protect a PDF in Your Browser

You have a signed contract, a payroll summary, or a scan of your passport, and it needs to go to someone outside your organisation. Email is the channel everyone actually uses, and email is also the channel where a forwarded thread ends up in three inboxes you never intended. So you go looking for the option that says “add a password to this PDF” — and depending on what software you happen to have, it either costs a subscription, sits behind a menu you can’t find, or doesn’t exist at all.

The free web tools that fill that gap mostly work by uploading your file to a server, encrypting it there, and sending it back. For a holiday photo that’s fine. For the document that was confidential enough to need a password in the first place, it’s a strange trade: to stop the wrong people reading your file, you first hand a complete copy to a company you’ve never heard of.

What password protecting a PDF actually means

PDF has two separate passwords, and mixing them up is the single most common reason people end up with a file that isn’t protected the way they assumed.

The open password (the spec calls it the user password) is the one that encrypts the document. Without it the bytes are unreadable, and no reader can show you the pages. The owner password controls permissions — whether a reader should allow printing, copying text, editing, and so on — and the PDF format’s own documentation describes these as two distinct things for exactly that reason.

PasswordWhat it doesIf you lose it
Open (user)Encrypts the file. Nobody opens it without the passwordThe content is genuinely unrecoverable
OwnerSets print/copy/edit permissions for people who can already open itRestrictions can be lifted by most PDF software
Neither setThe file is readable by anyone who receives itNothing to lose

The practical consequence: if your goal is “people who shouldn’t see this can’t see it”, you need an open password. Permissions alone are a request, not a wall.

Why people get stuck here

Pain pointReal-world impactWhat to check
Set permissions but no open passwordAnyone who gets the file can still read every pageDoes the file actually ask for a password when you open it?
Uploading a confidential fileA copy now exists on someone else’s serverDoes the tool process the file in the browser only?
Forgotten open passwordWith modern encryption the document is gone for goodHave you saved the password somewhere before sending?
Metadata left in the fileAuthor name, employer, and software version travel with itHave you checked the document properties?

That last one surprises people. A PDF exported from Word or a design tool usually carries your name, your organisation’s licensed copy of the software, and timestamps — visible to anyone who opens the document properties, password or not.

What a good solution looks like

Real encryption, not a restriction flag

Some tools “lock” a PDF by setting the permission bits and nothing else. That’s a sticker on the door, not a lock. Look for AES-256, the current standard for PDF encryption and the same cipher family standardised by NIST in FIPS 197. Older PDF encryption used RC4, which should be avoided for anything you actually care about.

The file should never leave your device

Browsers are now capable enough to do the whole job locally. If a tool tells you the file stays on your machine, you should be able to verify it — load the page, disconnect from the internet, and see whether the tool still works.

It should tell you what you’re starting with

Before changing anything, you want to know what the file’s security already is: is it encrypted, does it need a password, which permissions are set, what metadata is attached, and whether it contains active content like embedded JavaScript or file attachments. That’s information you can act on.

It should prove the result before you download

“Encrypted successfully” is a claim. Re-opening the finished file with no password, with the open password, and with the owner password is evidence. Skipping this is how people email a file they believe is locked and isn’t.

Common mistakes to avoid

  • Using the same string for both passwords. Anyone who can open the file can then also lift every restriction you set.
  • Relying on “disable copying” for confidentiality. Any tool that can open the document can extract its text, whatever the flag says.
  • Encrypting a digitally signed PDF. Rewriting the file invalidates the existing signature — sign after encrypting, not before.
  • Sending the password in the same email as the file. Use a different channel entirely; a message and its attachment travel together.
  • Assuming encryption cleans the document. Encryption hides the content from outsiders; it doesn’t remove the author name stored inside.

How to do it with PDF Security

The PDF Security tool runs qpdf — the long-standing open-source PDF engine — compiled to WebAssembly, so the encryption happens inside your browser tab. The flow is Upload → Security settings → Secure → Download.

  1. Drop the PDF in. The security check runs straight away and gives you a score out of 100 with the current encryption, permissions, metadata, and any active content it finds.
  2. Pick the job. Each tab does one thing: Encrypt adds an open password, Permissions limits printing and copying, Change password replaces an existing one, Remove password saves an unlocked copy, and Remove metadata strips the document properties.
  3. Set the password. Type your own or generate one, and watch the strength meter — it shows the estimated entropy in bits rather than a vague colour. An owner password is generated for you automatically so the two are never identical.
  4. Secure it. The tool rewrites the file, then re-opens it three ways to confirm it refuses to open without the password, accepts the new one, and applies the permissions you chose.
  5. Save the password, then download. The result panel shows both passwords with copy buttons, and a before/after table of exactly what changed.

Because each tab does one job, encrypting doesn’t silently strip your metadata — if you want both, run the Remove metadata pass as well. If you only need part of this, the focused PDF Password Protector and PDF Metadata Editor cover the single tasks, and the rest of the catalogue is at /tools.

Frequently asked questions

Can I recover a PDF password I’ve forgotten?

Not an open password on a modern file. AES-256 protection means the content is unreadable without the password, and there’s no back door — that’s the entire point of the encryption. What can be removed is a permissions-only restriction on a PDF that already opens without a password, and you should only do that for documents you own or are authorised to change.

Do the permission settings actually stop someone copying text?

Only in software that chooses to honour them, which includes Acrobat, Chrome, Edge, and macOS Preview. The permissions are flags inside the file rather than DRM, so a tool that ignores them can still extract text from any document it can open. Treat them as a policy for cooperative readers and use an open password when the content itself must stay private.

Should I choose AES-256 or AES-128?

AES-256 unless the file has to open in software older than roughly 2010. It’s the method defined in the current PDF standard and uses a slower password hash, which makes guessing far more expensive. AES-128 opens in older readers but only accepts plain keyboard characters in the password — accented letters will produce a file that won’t accept its own password.

Does encrypting a PDF remove its metadata?

No, and it shouldn’t be assumed to. Encryption stops outsiders reading the content; the title, author, and creating application are separate fields inside the document. Use the Remove metadata option to clear the document-information dictionary and the XMP packet. The modification date is deliberately kept, since readers expect it.

Is my PDF or password uploaded anywhere?

No. The engine runs in the page, so the file, the passwords, and the result all stay on your device. Once the page has loaded you can disconnect from the internet and it keeps working — which is a test you can run yourself rather than taking the claim on trust.

Final thought

A simple rule covers most cases: if the document would be a problem in the wrong inbox, give it an open password and send that password another way. If you just want to discourage a colleague from reprinting a draft, permissions are enough and won’t lock anyone out of a file they legitimately need. And if you’re sending a document outside your organisation, take the extra ten seconds to strip the metadata — the author field has ended everyone’s anonymity at least once.

If you want to go deeper on choosing the password itself, how to calculate a password’s entropy explains what the bit count actually means, and password-protecting any file with real encryption covers the same idea for formats other than PDF.

Try the free PDF Security tool

#password protect pdf#pdf security#pdf permissions#remove pdf password#online-tools#free-tools