The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For a new Ruby application, use HexaPDF’s HexaPDF::Document#encrypt before writing the file. HexaPDF documents AES 128-bit as its default and the best choice when recipient compatibility matters. Prawn also has encrypt_document, but the versioned Prawn 2.5.0 API documents a password-derived key limited to 40 bits, so it is not an equivalent choice for confidential documents.
Encrypt a generated PDF with HexaPDF
Install HexaPDF in your application, create or load a document, configure encryption, and then write the output. Keep the password outside source control; an environment variable or secret manager is appropriate for production.
- Add the gem to your project:
gem 'hexapdf'in the Gemfile, then runbundle install. - Generate the document and add its content.
- Call
encryptbeforewrite. - Deliver the resulting file and provide the user password through a separate, protected channel.
require 'hexapdf'
pdf = HexaPDF::Document.new
page = pdf.pages.add
page.canvas.text('Confidential report', at: [50, 750])
pdf.encrypt(user_password: ENV.fetch('PDF_USER_PASSWORD'))
pdf.write('report.pdf')
Run it with a password set in the process environment:
PDF_USER_PASSWORD='use-a-long-random-secret' ruby generate_report.rb
The user_password is the password a recipient must enter to open the file. HexaPDF’s standard security handler also supports an owner password, which has broader authority under the PDF security model. Consult the standard security handler API and the documentation for your installed HexaPDF version before selecting owner-password or permission options.
#1 Best Overall
- EDIT text, images & designs in PDF documents. ORGANIZE PDFs. Convert PDFs to Word, Excel & ePub.
- READ and Comment PDFs – Intuitive reading modes & document commenting and mark up.
- CREATE, COMBINE, SCAN and COMPRESS PDFs
- FILL forms & Digitally Sign PDFs. PROTECT and Encrypt PDFs
- LIFETIME License for 1 Windows PC or Laptop. 5GB MobiDrive Cloud Storage Included.
Choosing AES settings and reader compatibility
AES 128-bit
HexaPDF documents AES 128-bit as the default and a good compatibility-minded choice. Use it when recipients may open the PDF with a mixture of desktop, mobile, browser and embedded PDF readers. “Compatible” does not mean universal: open a test file in the actual readers used by your audience.
AES 256-bit
AES 256-bit was standardized with PDF 2.0. It can be appropriate when your security requirements call for it, but some older readers may not open the result. Select it only after testing the generated file against every required reader and verifying the exact option name in the installed HexaPDF release.
Avoid RC4
HexaPDF’s encryption guide states that RC4 is old and insecure and should be avoided. Do not choose an RC4 mode merely to accommodate an untested legacy viewer; first determine whether that viewer can be upgraded.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesWhat PDF passwords do—and do not—control
- Opening the file: a user password protects opening the encrypted document.
- Owner authority: an owner password can open the file without the user-level restrictions represented by PDF permission flags.
- Printing and copying: permissions are part of the PDF security-handler model, but reader applications may not enforce them consistently.
- Secret distribution: encryption does not help if the PDF and its password are sent through the same exposed channel.
Treat password protection as file-level confidentiality, not as a replacement for authorization, an authenticated download endpoint, access logging, data-loss prevention, or document revocation. A recipient who can open a PDF can still photograph the screen or use a reader that ignores permission flags.
Rank #2
- Edit PDFs with Ease. Modify text, images, and layouts directly within your PDF documents.
- Convert & Organize. Export PDFs to Word, Excel, or ePub, and organize files with ease.
- Read & Annotate. Enjoy intuitive reading modes and powerful tools to comment, highlight, and mark up PDFs.
- Create & Manage PDFs. Create new PDFs, combine multiple files, scan documents, and compress for easy sharing.
- Fill & Sign Forms. Complete forms and digitally sign documents with secure e-signature tools.
Using Prawn’s encrypt_document
Prawn is primarily a PDF content-generation library. Its manual documents encrypt_document and requires a user_password when you want opening the file to require a password.
require 'prawn'
Prawn::Document.generate('report.pdf') do
text 'Confidential report'
encrypt_document(user_password: ENV.fetch('PDF_USER_PASSWORD'))
end
You can also supply owner_password as documented by Prawn:
encrypt_document(
user_password: ENV.fetch('PDF_USER_PASSWORD'),
owner_password: ENV.fetch('PDF_OWNER_PASSWORD')
)
Do not use sample values such as foo or bar in production. The Prawn 2.5.0 API documentation warns that its encryption is weak and that the password-derived key is limited to 40 bits. That is a statement about that documented API version, not an independent measurement of every Prawn release. Check the documentation and source for the exact version you deploy before relying on it for sensitive material.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Prawn’s manual also notes that, without a user password, a document can still be encrypted but may not require a password to open. Therefore, explicitly pass user_password when a password prompt is required.
Rank #3
- Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go.
- Edit text and images without jumping to another app.
- E-sign documents or request e-signatures on any device. Recipients don’t need to log in to e-sign.
- Convert PDFs to editable Microsoft Word, Excel, or PowerPoint documents.
- Share PDFs for collaboration. Commenting features make it easy for reviewers to comment, mark up, and annotate.
HexaPDF or Prawn?
| Consideration | HexaPDF | Prawn |
|---|---|---|
| Encryption entry point | HexaPDF::Document#encrypt |
encrypt_document |
| Documented security detail | AES choices; AES 128-bit is the default compatibility option | Prawn 2.5.0 documents a 40-bit password-derived key |
| Best fit | New workflows where stronger, configurable PDF encryption is important | Existing Prawn generation where the documented limitation is acceptable |
| Reader compatibility | Test AES 128-bit or AES 256-bit against target readers | Test every target reader and assess whether the documented weakness is acceptable |
| Scope | Broader PDF reading and manipulation capabilities | Focused primarily on PDF content generation |
For a new confidential-document workflow, HexaPDF is the more defensible default. If your system already generates PDFs with Prawn, migrating encryption is a security decision: test output, confirm downstream readers, and document the version and accepted risk.
Passwords, permissions and deployment practices
Generate and store secrets safely
- Read passwords from a secret manager or environment variable, never from committed Ruby source.
- Use a high-entropy, unique password for each file or recipient policy.
- Do not log the password, command line, generated URL or exception payload containing it.
- Send the PDF and its password through separate channels when confidentiality matters.
- Decide how forgotten passwords, employee departures and key rotation are handled before shipping.
Verify the artifact in automation
After writing the file, check that it exists, has a non-zero size, and can be opened by the PDF readers you support. Include at least one test that opens the file without a password and expects failure, and another that opens it with the expected password. Test printing and copying behavior only as a reader-specific compatibility check; do not treat those flags as a guaranteed control.
Consider licensing
The HexaPDF project documentation says a commercial license is needed in certain distribution or remote-access situations when application source is not made available under AGPL. Review the current official terms against your deployment model; do not assume that an internal service, hosted application and redistributed binary have identical obligations.
Troubleshooting common failures
LoadError: cannot load such file -- hexapdf
The gem is not installed in the active bundle or the process is using a different Ruby environment. Add gem 'hexapdf', run bundle install, and execute the script with bundle exec ruby generate_report.rb.
Rank #4
- Perfect Adobe Acrobat Pro alternative – lifetime license for Windows 10 and 11.
- EDIT text, images, pages, hyperlinks, designs in PDF documents. ORGANIZE PDFs.
- READ and Comment on PDFs – Intuitive reading modes & document commenting and mark up tools!
- CREATE, COMBINE, SCAN and COMPRESS PDFs.
- FILL forms & Digitally Sign PDFs. Work with Digital certificates
The PDF opens without asking for a password
Confirm that user_password is present and non-empty, that encrypt runs before write, and that you are opening the newly generated file rather than a cached copy. In Prawn, omitting user_password can produce encrypted output that does not require a password to open.
A recipient’s reader reports an unsupported encryption type
Check which AES mode was selected and test the file in an up-to-date reader. If the recipient environment is mixed or partly legacy, AES 128-bit is HexaPDF’s documented compatibility-minded default. Do not fall back to RC4; HexaPDF identifies it as insecure.
Printing or copying is still possible
Permission flags are advisory in practice because reader applications may ignore them. If preventing disclosure is essential, enforce access at the download or application layer and distribute only to authenticated users.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The password works locally but not in production
Compare the production Ruby and gem versions, confirm the secret variable is present in the service’s runtime (not just your shell), and check for whitespace or encoding changes introduced by deployment. Regenerate the PDF after correcting the secret rather than reusing a failed artifact.
Best Value
- ALL-IN-ONE SOLUTION – read, edit, convert, merge and protect your PDF files
- MAXIMUM FUNCIONALITY – create interactive forms, compare PDFs, bates numbering, find and replace text or colors, convert documents, OCR engine, comment, highlight, fill out and print forms, document protection and others
- EASY TO INSTALL AND USE – well-structured user-interface, in-program instructions, free tech support whenever you need it
- GREAT VALUE FOR MONEY - why spend a fortune if you can have maximum functionality at a reasonable price - this also fits the requirements of companies very well
Performance and operational notes
Encryption is applied when the document is written, so it belongs in the same job that finalizes the PDF. For large reports, stream or queue generation according to your existing workload design, retain only the encrypted artifact you need, and delete unencrypted temporary files promptly. Measure your own document sizes and job times; the supplied library documentation does not establish a universal performance number.
Or skip the browser setup
If your workflow also needs a clean screenshot or PDF capture of a web page, ScreenshotNeo provides a single HTTP request instead of maintaining a browser stack. It accepts cookie and consent banners like a visitor, removes more than 60 known consent platforms plus newsletter popups and chat widgets before capture, and bills only clean shots. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and each response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for request options and authentication. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo to get the free allowance.
Recommended Free Tools
Ruby implementation checklist
- Choose HexaPDF for new confidential-document workflows unless a documented compatibility requirement says otherwise.
- Use
user_passwordand load it from a secret source. - Call encryption before writing the file.
- Prefer AES 128-bit when broad reader compatibility is the priority; test AES 256-bit where required.
- Never select RC4 for new work.
- Version-scope Prawn’s 40-bit limitation and reassess whether it is acceptable.
- Test opening, wrong-password handling and target readers in CI or a release check.
- Use application authorization when PDF permissions alone are insufficient.
Frequently Asked Questions
Can I add a password after a PDF has already been generated?
Yes, but the encryption must be applied by a PDF library that reads and rewrites the existing document. For a new Ruby workflow, configure HexaPDF encryption before writing; test rewritten files for signatures, forms and other features your document uses.
Should I use the same user and owner password?
Use separate secrets when you need distinct recipient and administrative authority. Confirm the exact owner-password and permission behavior in the HexaPDF version you deploy.
Is a password-protected PDF fully secure?
It protects the encrypted file from opening without the password, but reader-enforced permissions are not guaranteed and an authorized recipient can still copy the content by other means.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

