October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
ASP.NET

How to Fix OpenHtmlToPdf “Access Denied” in ASP.NET

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

First find out what was denied: an HTTP request, a local file operation, or access to a remote resource. The words “Access Denied” alone are not enough to identify the cause. Capture the full exception and stack trace, the HTTP status, and the exact path or resource named before changing permissions. If the converter exception identifies a local folder, grant the IIS application-pool identity only the rights that operation needs on that folder—not administrator access to the server.

Identify which layer is returning “Access Denied”

ASP.NET applications can encounter access-denied errors at different layers. IIS or ASP.NET may reject the incoming HTTP request before PDF generation starts. Alternatively, the application may reach OpenHtmlToPdf and then fail when the hosting process tries to read an input, create a temporary file, or write output. A remote resource can also reject the credentials used to access it. These cases need different fixes.

Evidence Likely area to investigate
HTTP 403 or an IIS/ASP.NET response, with no converter exception in the application log Request authorization, IIS configuration, or another HTTP access rule. A 403 does not by itself prove that OpenHtmlToPdf failed.
Converter exception or “access to the path is denied” message naming a local path Filesystem permissions for the process identity attempting that file operation.
Exception names a network share, URL, or other remote resource Remote authorization and the credentials or identity used for that resource; changing a local folder ACL may not help.

Microsoft advises reading the actual error to determine whether missing permissions concern a local or remote resource and identifying the account involved. See Microsoft’s ASP.NET permissions troubleshooting guidance and its discussion of IIS application-pool identities.

Collect the evidence before changing permissions

  1. Record the complete failure. Capture the full exception text, inner exceptions, stack trace, HTTP status, and the exact denied path or resource. A short log entry containing only “Access Denied” is insufficient.
  2. Check whether PDF code ran. Look for an OpenHtmlToPdf or converter exception in the application logs. If the request returned 403 without reaching PDF-generation code, investigate the request pipeline and IIS/ASP.NET authorization first.
  3. Identify the hosting process and identity. For IIS, determine the application pool serving the affected app and its configured identity. Do not assume that it runs as your interactive Windows account. If the app is hosted another way, identify that service or process account instead.
  4. Follow the named resource. For a local path, inspect that folder and its access control list (ACL). For a remote path or service, check the remote system’s authorization and the credentials actually presented.
  5. Reproduce the same operation after a targeted change. Review the new exception and logs. If access is still denied, use the newly reported path and identity as evidence rather than widening permissions elsewhere.

Grant the IIS application pool only the required folder access

When the exception establishes a local filesystem denial, grant the identity that runs the affected app pool the minimum rights required on the specific denied folder. Rendering may need to read an input and create or modify temporary or output files; the needed rights depend on the operation and the folder’s role. Do not automatically grant write access to the whole website, the entire Windows temporary directory, or unrelated folders.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. In IIS Manager, locate the affected site or application and note the application pool assigned to it. Confirm the pool and identity in the affected environment, especially if deployment configuration differs from development.
  2. Open the security properties for the exact folder named by the exception. Review its existing permissions before editing them.
  3. Add the corresponding application-pool identity, commonly entered in Windows ACL tools as IIS APPPOOLPoolName, replacing PoolName with the actual pool name.
  4. Grant only the permissions needed for the confirmed operation on that folder. If rendering must create files there, the identity will need suitable write/create access; if it only reads a resource, do not grant write access without evidence it is necessary.
  5. Apply the change, repeat the failing request under the normal app-pool identity, and inspect the logs. Remove any temporary diagnostic elevation or permissions that are no longer needed.

Microsoft’s application-pool guidance demonstrates granting an application-pool identity read and write ACL permissions for a particular App_Data scenario. That example is not an instruction to grant the same rights to every OpenHtmlToPdf folder; apply permissions to the resource and operation your error actually identifies.

When the reported path is C:WindowsTempOpenHtmlToPdf

A community report about an OpenHtmlToPdf access-denied error says the author resolved it by allowing access to C:WindowsTempOpenHtmlToPdf. Treat that as a case-specific lead, not a universal default path or guaranteed fix. The report does not establish that every version, host, or deployment uses this directory.

Use this path only if the exception in your application names it and you have verified the affected deployment uses it. Then inspect that folder’s ACL and grant the actual hosting identity only the rights required there. If the exception identifies another path, investigate that path instead. The report is available at the matching OpenHtmlToPdf community question.

Check the installed package and target framework

Do not assume that packages with similar names have identical targets or runtime behavior. NuGet lists OpenHtmlToPdf 1.12.0 for .NET Framework 4.5 and records its last update as 2014-12-02. It lists OpenHtmlToPdf.netcore 1.13.0 with .NET Standard 2.0 and .NET Framework 4.5 compatibility. Those are package-page facts, not evidence of which version your application uses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the project file, lock file, or installed dependencies in the deployed application before applying version-specific advice. The package listings are OpenHtmlToPdf on NuGet and OpenHtmlToPdf.netcore on NuGet.

Common mistakes and what to do instead

  • Treating every 403 as a converter failure: determine whether the request was rejected before PDF code ran. Check HTTP status, IIS/ASP.NET logs, and application logs.
  • Changing permissions based only on the library name: use the exact path in the exception and the identity that attempted the operation.
  • Granting broad write access: scope access to the confirmed folder and operation. A general grant to the website or system temp directory can expose unrelated files without addressing the actual denial.
  • Leaving the app pool as Administrator or Local System: elevated execution may help test a permissions hypothesis, but it is not an appropriate permanent repair. Restore the intended identity and fix the specific ACL or remote authorization problem.
  • Assuming local ACL changes fix a remote denial: verify the credentials and permissions on the remote share or service as well.
  • Assuming package versions behave alike: identify the actual package and framework in the affected application before relying on package-specific assumptions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting by symptom

The site returns 403 and there is no PDF exception

Investigate IIS and ASP.NET request authorization, the URL and endpoint being requested, and relevant server logs. Confirm whether the request reaches the code that invokes OpenHtmlToPdf. Do not change a temp-folder ACL unless evidence points to a filesystem denial.

The exception names a local file or directory

Record the exact path, identify the hosting process account, inspect that resource’s ACL, and grant only the access needed for the operation. Re-run the same request and use any new path in the resulting error to guide the next check.

The path is remote

Check which identity or credentials the application presents to the remote system and whether that identity has the required access there. Local IIS folder permissions alone cannot authorize a network resource.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The error persists after a targeted permission change

Confirm that the request is running in the app pool and environment whose ACL you changed; verify the exact pool identity and path from the current exception. Check for a second denied resource, such as a separate output location or remote input, instead of granting broader rights indiscriminately.

Or skip the browser setup

If the task is simply to capture a web page as an image or PDF rather than generate PDFs from HTML inside your ASP.NET application, ScreenshotNeo provides a website screenshot API and MCP server. A single GET request can return PNG, JPEG, WebP, or PDF. The example below captures a URL as WebP; see the ScreenshotNeo documentation for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers. Its MCP server offers take_screenshot, get_page_info, and capture_pdf tools for AI agents and MCP clients. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. These are separate website-capture capabilities, not a fix for an ASP.NET filesystem permission error. Sign up free for 1,000 screenshots a month with no card.

Frequently Asked Questions

Is C:WindowsTempOpenHtmlToPdf always the folder that needs permission?

No. It is a path named in one community report. Use it only when your exception and deployment confirm that it is the denied folder.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should I run the IIS app pool as Administrator to fix the error?

No. Elevated access may be used briefly to test a permissions hypothesis, but the permanent fix should target the specific resource and process identity.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.