Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To require a password before someone can open a PDF, set a user (open) password. If you create the PDF with ReportLab, you can encrypt it during generation. If you already have the completed PDF, use pypdf to encrypt it afterward and explicitly select an AES algorithm. An owner password and restrictions on printing or copying are different controls; they do not replace an open password.

Choose where to apply encryption

There are two useful points in a Python workflow to protect the file:

  • During creation: pass an encryption setting to ReportLab’s canvas.Canvas when you generate the document. This is convenient when ReportLab is already responsible for producing the PDF.
  • After creation: use pypdf to read the generated PDF, create a writer from it, encrypt the output and write a new file. This is a straightforward choice when the PDF already exists or you want to keep generation and encryption as separate steps.

Neither approach needs to be treated as universally better: choose based on which library creates the document and whether you have a finished PDF to process. The cited documentation does not establish a performance comparison or a universal viewer-compatibility guarantee.

Know which password does what

A user password, also called an open password, is the password the reader must enter to open the PDF. Use this when your requirement is “the recipient must know a password to read this file.” ReportLab’s documentation distinguishes that from the owner password, which is associated with changing security settings and with permission controls such as printing, copying, modifying and annotating.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Epson Workforce ES-50 Compact & Lightweight Mobile Document Scanner
  • PORTABLE SCANNER FOR USE ON-THE-GO — The fastest and lightest mobile single-sheet-fed compact document scanner in its class¹
  • QUICK DOCUMENT SCANNING ― This Epson ultra-fast scanner scans a single page as quickly as 5.5 seconds²; Windows and Mac compatible
  • VERSATILE PAPER HANDLING ― Portable scanner scans documents up to 8.5 x 72 in; Also easily digitizes receipts and ID cards to make accounting, bookkeeping, and organizing simpler
  • INTUITIVE, HIGH-SPEED SOFTWARE — Epson ScanSmart Software³ is a smart tool allowing you to easily scan, review, and save; Stay organized easily with the help of this Epson scanner
  • EASY SETUP — USB-powered connect to your computer for quick and simple scanning; No batteries or external power supply required to operate portable document scanner; Standard Connectivity: USB 2.0

Those permission flags describe how a PDF viewer should handle actions after the user password has been provided; they are not a substitute for requiring a password to open the file. ReportLab also documents that setting only an owner password does not require an opening prompt. See the ReportLab encryption guide for the documented password roles and permission options.

Install pypdf with AES support

For the pypdf method below, install the crypto extra so AES encryption is available:

python -m pip install 'pypdf[crypto]'

The pypdf project repository documents that install command for AES use: pypdf on GitHub. If your environment already has pypdf installed without the extra, install the extra in the same Python environment that will run your script. The pypdf 6.3.0 encryption guide lists the supported algorithm names and notes the crypto dependency for AES: pypdf encryption and decryption documentation.

Rank #2
Sale
Brother DS-640 Compact Mobile Document Scanner, (Model: DS640)
  • FAST SPEEDS - Scans color and black and white documents a blazing speed up to 16ppm (1). Color scanning won’t slow you down as the color scan speed is the same as the black and white scan speed.
  • ULTRA COMPACT – At less than 1 foot in length and only about 1. 5lbs in weight you can fit this device virtually anywhere (a bag, a purse, even a pocket).
  • READY WHENEVER YOU ARE – The DS-640 mobile scanner is powered via an included micro USB 3. 0 cable allowing you to use it even where there is no outlet available. Plug it into you PC or laptop and you are ready to scan.
  • WORKS YOUR WAY – Use the Brother free iPrint&Scan desktop app for scanning to multiple “Scan-to” destinations like PC, Network, cloud services, Email and OCR. (2) Supports Windows, Mac and Linux and TWAIN/WIA for PC/ICA for Mac/SANE drivers. (3)
  • OPTIMIZE IMAGES AND TEXT – Automatic color detection/adjustment, image rotation (PC only), bleed through prevention/background removal, text enhancement, color drop to enhance scans. Software suite includes document management and OCR software. (4)

Encrypt an existing PDF with pypdf

This example takes a generated PDF named generated.pdf, applies AES-256 encryption, and writes protected.pdf:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
from pypdf import PdfReader, PdfWriter

reader = PdfReader("generated.pdf")
writer = PdfWriter(clone_from=reader)
writer.encrypt(
    "use-a-secret-from-a-secure-source",
    algorithm="AES-256",
)
writer.write("protected.pdf")

The workflow follows the pypdf guide: create a reader, construct a writer from the reader, call encrypt with an explicit algorithm, then write the output. Replace the example password with a value retrieved securely at runtime. Do not put a real password in source code or write it to application logs.

Why the algorithm is explicit

The pypdf guide lists RC4-40, RC4-128, AES-128, AES-256-R5 and AES-256 as algorithm options, and recommends AES-256-R5. It also warns that if you omit algorithm, pypdf chooses RC4 for compatibility, and its documentation says RC4 is insecure and advises using AES algorithms. In this example, AES-256 is selected explicitly so the code does not silently rely on that default. If you need a different algorithm, use one listed in the documentation and account for the recipient’s PDF software; the cited sources do not provide a complete compatibility matrix.

Rank #3
Canon imageFORMULA R10 - Portable Document Scanner, USB Powered, Duplex Scanning, Document Feeder, Easy Setup, Convenient, Perfect for Mobile Users, White
  • STAY ORGANIZED – Easily convert your paper documents into digital formats like searchable PDF files, JPEGs, and more.Power Consumption : 2.5W or less (Energy Saving Mode: 0.7W). Suggested Daily Volume : 500 scans..Does it contain liquid: no
  • CONVENIENT AND PORTABLE –lightweight and small in size, you can take the scanner anywhere from home offices, classrooms, remote offices, and anywhere in between
  • HANDLES VARIOUS MEDIA TYPES – Digitize receipts, business cards, plastic or embossed cards, reports, legal documents, and more
  • FAST AND EFFICIENT – No technical hurdles or complicated setups here; easily scan both sides of a document at the same time, in color or black-and-white, at up to 12 pages-per-minute, and with a 20 sheet automatic feeder
  • BROAD COMPATIBILITY – Works with both Windows and Mac devices, be it laptop or computer

Keep the original and protected files distinct

The example reads one path and writes another. Keeping the source and encrypted output separate makes the transformation clear and avoids accidentally replacing the input while testing. Distribute protected.pdf only after checking that it opens as intended with the chosen password in the PDF software your recipient will use.

Generate and encrypt a PDF with ReportLab

If ReportLab is creating the document, pass the user password as the encrypt argument to canvas.Canvas. The following is a minimal complete generation example; the password is deliberately an instructional stand-in, not a production secret:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
from reportlab.pdfgen import canvas

pdf = canvas.Canvas(
    "protected.pdf",
    encrypt="use-a-secret-from-a-secure-source",
)
pdf.drawString(72, 720, "Generated PDF")
pdf.showPage()
pdf.save()

ReportLab documents the encrypt argument on canvas.Canvas, and its canvas guide describes save() as finalizing and storing the generated document: ReportLab pdfgen guide. When the goal is an opening prompt, the string form supplies the user password.

Rank #4
IRIScan Express 4 Black Compact Portable USB Simplex Document Scanner, 8 PPM for Contracts, Invoices and Business Cards, Compatible with Windows, Readiris PDF Included
  • IRIScan Express, portable scanner : scans color and black and white documents a blazing speed up to 8ppm simplex. Color scanning won’t slow you down as the color scan speed is the same as the black and white scan speed.
  • IRIScan Express mobile scanner is powered via an included micro USB 2. 0 cable allowing you to use it even where there is no outlet available. Plug it into you PC or laptop and you are ready to scan. USB cable provided. AC Adapter not provided and not needed.
  • IRIScan flatbed scanner uses a simplex scanning mode allows for quick and straightforward scanning of single-sided documents. IRIScan with its full portable features is the ideal document scanners for computers.
  • IRIScan document scanner : Versatile scanning capabilities, including scanning to Word, PDF, and Excel formats with companion software provided Readiris OCR
  • Receipt scanner and card scanner with Additional features include scanning business cards directly to Outlook, photo scanning, and receipt scanning for efficient document management

Set an owner password and permissions when needed

For more granular settings, ReportLab documents reportlab.lib.pdfencrypt.StandardEncryption with a user password, an optional owner password and flags including canPrint, canModify, canCopy and canAnnotate. A simplified shape is:

from reportlab.lib.pdfencrypt import StandardEncryption
from reportlab.pdfgen import canvas

encryption = StandardEncryption(
    userPassword="open-password-from-a-secure-source",
    ownerPassword="owner-password-from-a-secure-source",
    canPrint=0,
    canModify=0,
    canCopy=0,
    canAnnotate=0,
)
pdf = canvas.Canvas("protected.pdf", encrypt=encryption)
pdf.drawString(72, 720, "Generated PDF")
pdf.showPage()
pdf.save()

Check the constructor and behavior against the ReportLab version installed in your project before relying on particular security settings. The cited ReportLab guide’s constructor signature documents a default strength of 40, but it does not establish a modern AES setting for this API. Do not assume that this ReportLab interface provides AES based on that guide.

Which approach fits your workflow?

Question ReportLab encryption pypdf encryption
When does encryption happen? While ReportLab generates the PDF. After a PDF exists; pypdf reads it and writes an encrypted output.
Best fit You are already generating the document with ReportLab. You need to protect an existing PDF or keep encryption as a separate processing step.
AES setup established by the cited sources The cited guide does not establish an AES setting for this API. Install pypdf[crypto] and select an AES algorithm explicitly.
Password and permission controls Documents a user password and a StandardEncryption option with owner password and permission flags. The cited encryption workflow demonstrates applying a password and algorithm; use its documentation for the precise API options.

The comparison is limited to the cited library documentation; it is not a benchmark or a promise that every recipient’s PDF viewer handles every option identically.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Canon Canoscan Lide 300 Scanner (PDF, AUTOSCAN, Copy, Send)
  • Scanner type: Document
  • Connectivity technology: USB
  • With Auto Scan Mode, the scanner automatically detects what you're scanning
  • Digitize documents and images
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect the password as carefully as the PDF

  • Supply the secret at runtime. Use an appropriate secret store or runtime configuration instead of committing a real password in a script or repository.
  • Do not log it. Check exception handling, debug output and application logs so the secret is not copied into operational records.
  • Deliver the password separately from the file. If the PDF and its password travel together through the same channel, the password offers less practical separation. Choose a delivery method suited to your risk and recipient.
  • Test the recipient experience. Open the output in a PDF viewer and confirm that it prompts for the user password and that the intended password works before sending it.

These are operational security practices, not claims about a particular library feature. Encryption cannot compensate for a password that is exposed alongside the file.

Common errors and fixes

  • AES-related import or crypto error: the environment running the script may have pypdf but not its crypto extra. Install python -m pip install 'pypdf[crypto]' in that environment, then run the script with the same interpreter.
  • The output does not ask for a password: check that you set a user/open password. An owner password by itself does not require an opening prompt in ReportLab’s documented behavior.
  • Unexpected RC4 encryption: check that the pypdf call includes an explicit AES algorithm. The documented default is RC4 when the argument is omitted.
  • The source PDF cannot be read: verify that generated.pdf exists at the path your process uses and is the completed PDF you intend to protect. If the input already requires a password, resolve access to that source file before applying the shown workflow.
  • The recipient cannot open the result: verify the password you supplied and test the exact output file. If the file is encrypted with an algorithm unsupported by the recipient’s viewer, choose an algorithm appropriate for the recipient and validate it; the cited documentation does not establish compatibility for every viewer.
  • ReportLab rejects an encryption setting: check the constructor signature and supported behavior for the ReportLab version installed. The cited guide does not establish AES support through this API.

Or skip the browser setup

ScreenshotNeo is a separate tool for taking website screenshots or PDFs; it does not replace either Python PDF-encryption workflow above. If the file you need is a capture of a web page rather than a PDF your application has already generated, its one-request API can return an image or PDF. The ScreenshotNeo website describes the service; see the API documentation for request options.

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)

ScreenshotNeo removes cookie banners, popups and chat widgets before a shot; bot checks, blank pages and failed loads are never billed. It also has an MCP server for AI agents, and includes 1,000 screenshots a month free with no card; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month, with no card.

Frequently asked questions

Can I use an owner password without making readers enter a password?

Yes. ReportLab documents that an owner password alone does not require an opening prompt. That is different from the user/open password used in this article’s main workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which pypdf algorithms are listed in its encryption guide?

The pypdf 6.3.0 guide lists RC4-40, RC4-128, AES-128, AES-256-R5 and AES-256. It recommends AES-256-R5; choose deliberately rather than relying on the documented RC4 default.

Frequently Asked Questions

Can I use an owner password without making readers enter a password?

Yes. ReportLab documents that an owner password alone does not require an opening prompt. That is different from the user/open password used in the main workflow.

Which pypdf algorithms are listed in its encryption guide?

The pypdf 6.3.0 guide lists RC4-40, RC4-128, AES-128, AES-256-R5 and AES-256. It recommends AES-256-R5; choose deliberately rather than relying on the documented RC4 default.

Quick Recap

Bestseller No. 3
Canon imageFORMULA R10 - Portable Document Scanner, USB Powered, Duplex Scanning, Document Feeder, Easy Setup, Convenient, Perfect for Mobile Users, White
Canon imageFORMULA R10 - Portable Document Scanner, USB Powered, Duplex Scanning, Document Feeder, Easy Setup, Convenient, Perfect for Mobile Users, White
BROAD COMPATIBILITY – Works with both Windows and Mac devices, be it laptop or computer; This product is not intended for scanning photographs on photo paper / photographic media
$184.00
Bestseller No. 4
IRIScan Express 4 Black Compact Portable USB Simplex Document Scanner, 8 PPM for Contracts, Invoices and Business Cards, Compatible with Windows, Readiris PDF Included
IRIScan Express 4 Black Compact Portable USB Simplex Document Scanner, 8 PPM for Contracts, Invoices and Business Cards, Compatible with Windows, Readiris PDF Included
Find our Software here : irislink.com/start; IRIScan Express is only compatible Windows platform and not macintosh
$129.00
Bestseller No. 5
Canon Canoscan Lide 300 Scanner (PDF, AUTOSCAN, Copy, Send)
Canon Canoscan Lide 300 Scanner (PDF, AUTOSCAN, Copy, Send)
Scanner type: Document; Connectivity technology: USB; With Auto Scan Mode, the scanner automatically detects what you're scanning
$75.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.