Skip to content
ToolsOnDuty - free online tools
PDF Tools

Protect PDF

Add AES-256 password protection and configurable viewer permissions to a PDF.

Free browser toolRuns in your browserNo sign-up

Private PDF security studio

Protect a PDF with AES-256 encryption

Add an open password, configure viewer permissions and verify the encrypted result without uploading the document or password.

0

source pages

AES-256

encryption

Local

processing

Open password

Use at least 8 characters; 12+ with mixed characters is safer.Not set

Viewer permissions

Choose a preset, then customize if needed. Permissions are advisory and depend on the PDF reader honoring them.

Permission note: encryption requires the password to open the PDF. Print, copy and modification permissions are viewer-enforced controls, not unbreakable digital rights management.

Private workspace. Files stay in this browser tab and are never uploaded to ToolsOnDuty.

Choose an unprotected PDF to begin.

About the Protect PDF

Protect PDF applies AES-256 encryption to a readable, currently unencrypted PDF. Recipients use the open password to view the result, and the password must be at least eight characters, entered twice for confirmation, and is accompanied by a strength indicator that rewards length and mixed character types.

An optional separate owner password can be set for the person responsible for document permissions; otherwise the open password is also used as the owner password. Read only, Print allowed, and Review copy presets are available, while Custom mode separately controls printing, modification, and text or image extraction.

Permission flags are advisory controls enforced by compatible PDF viewers, not unbreakable digital rights management. A reader that ignores PDF permissions or a person with the owner password may allow actions that the selected preset discourages, so permissions should not be treated as DRM.

The source first page is previewed locally, then QPDF WebAssembly encrypts the file without rasterizing its visible pages. The result is verified first to reject password-free opening and then to open with the supplied password; after success all password fields are cleared, and the protected file is offered only through an explicit Download button.

Key features

  • AES-256 PDF encryption through local QPDF WebAssembly
  • Confirmed open password with minimum length and strength feedback
  • Optional separate owner password
  • Read only, Print allowed, Review copy, and Custom permission modes
  • Custom full, low-resolution, or blocked printing controls
  • Custom modification and text or image extraction controls
  • Local source-page preview and encrypted-output verification
  • Custom filename with explicit user-click download

How to use

  1. 1Choose a valid, readable PDF that is not already encrypted; unlock an already protected input first.
  2. 2Enter an open password of at least eight characters, confirm it exactly, and use the strength feedback to improve it.
  3. 3Optionally enable a separate owner password and enter at least eight characters for it.
  4. 4Choose Read only, Print allowed, or Review copy, or use Custom to set printing, changes, and extraction permissions.
  5. 5Select Protect PDF and keep the tab open while local QPDF WebAssembly applies AES-256 encryption and verifies the result.
  6. 6Review the verified page count, output size, processing time, and source preview, then choose a filename and explicitly select Download protected PDF.

Examples

Protect a review copy
Input: Unencrypted 18-page report, strong confirmed open password, separate owner password, Review copy preset
Output: AES-256 encrypted PDF allowing low-resolution printing and annotations as viewer-enforced permissions

The source preview is local; after verification and password clearing, click Download protected PDF explicitly.

Frequently asked questions

Which encryption does the tool use?
It uses QPDF WebAssembly to apply AES-256 encryption with the confirmed open password and either the same or a separate owner password.
What is the difference between open and owner passwords?
The open password is required to view the PDF. The owner password controls permission authority; when no separate owner password is set, the open password is used for both roles.
Are print, modify, and extraction restrictions DRM?
No. They are advisory PDF permission flags that depend on the viewer honoring them and should not be treated as unbreakable DRM.
Are the PDF or passwords uploaded or stored?
No. The source, passwords, QPDF processing, and verification remain in the browser, and password fields are cleared after successful protection.
How is the encrypted output verified?
The browser confirms that the generated PDF rejects an attempt without a password, then opens it with the supplied open password and checks its page count before enabling download.
Why can protection fail?
Already encrypted input must be unlocked first. A damaged PDF, unsupported structure, or a file too large for available browser and device memory can also fail.

Open a related tool to prepare your files or refine the finished result.