Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To require a password to open a PDF generated in Ruby, use a PDF library’s encryption support and set its user (open) password. HexaPDF is the stronger documented fit when you need modern AES options or need to manipulate existing PDFs. Prawn can encrypt a generated document with encrypt_document, but its version 2.5.0 documentation warns that its password-derived key is limited to 40 bits—a significant security limitation.
In either library, an owner password and permission settings are not substitutes for an opening password. The examples below use placeholders: load real passwords from a secret store or environment variable, and deliver the PDF password to its recipient through a separate channel.
How PDF passwords work
PDF password protection uses the PDF format’s encryption machinery; it is not the same as encrypting the finished file’s bytes with a general-purpose cipher. A PDF library must write the encryption information into the document structure so compatible readers can request and use a password.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →- User password: also called the open password. A reader needs it to open the PDF. This is normally the password shared with the recipient.
- Owner password: provides owner-level access and may allow a reader to change or override restrictions.
- Permissions: settings can request limits on printing, copying, or editing. PDF readers may enforce these differently, and some do not enforce them. Permissions alone do not keep a readable PDF confidential.
Both libraries can produce an encrypted PDF that has no user password. That is not password-gated viewing: if opening does not require a password, it does not meet the usual meaning of “password-protect the PDF.”
#1 Best Overall
- Transform audio playing via your speakers and headphones
- Improve sound quality by adjusting it with effects
- Take control over the sound playing through audio hardware
Choose between HexaPDF and Prawn
Choose based on the application’s existing PDF stack, the encryption options it needs, and how it distributes its software. The libraries are not equivalent in their documented encryption strength.
| Consideration | HexaPDF | Prawn |
|---|---|---|
| Best fit | Creating and manipulating PDFs; a fit when modern AES options matter. | Generating PDFs in an application already built around Prawn. |
| Encryption documented in the cited documentation | The guide describes AES 128-bit as its default and broad-compatibility choice. It also describes AES 256-bit, standardized with PDF 2.0; earlier use was an Adobe extension. The guide says to avoid old, insecure RC4. | Prawn 2.5.0 documents a password-derived key limited to 40 bits and warns that its security is inadequate against a moderately motivated person. |
| Passwords and permissions | Supports user and owner passwords and permission settings through its standard security handler. | Supports a user password, owner password, and permission options through encrypt_document. |
| Ruby requirement | The project repository states Ruby 3.0 or newer. | Not stated in the cited Prawn security API documentation. |
| License and deployment | The repository lists AGPL and a commercial license. Some proprietary distribution or network-access deployments may require a commercial license; check current vendor terms for your use. | Not stated in the cited Prawn security API documentation. |
HexaPDF’s AES options make it the more appropriate starting point if you need current encryption choices, while Prawn may be convenient for an existing Prawn codebase whose threat model does not require stronger protection. Do not select Prawn’s documented encryption for sensitive material without a separate security review and a different solution if your threat model requires stronger protection.
Sources: HexaPDF encryption guide, HexaPDF StandardSecurityHandler API, HexaPDF repository, and Prawn 2.5.0 security API.
Free tools Windows power users keep installed
One-click scans. No signup required.
Protect a generated PDF with HexaPDF
HexaPDF exposes encryption through HexaPDF::Document#encrypt. Use the API reference for the version installed in your application to confirm the exact option names and supported values; version-specific details can change. The pattern is to create or load the document, configure encryption, then write the encrypted document:
Rank #2
- Create, edit and style DOCUMENTS, SPREADSHEETS & PRESENTATIONS – all the features that you need to get work done
- Included PDF functions to FILL & SIGN forms, ANNOTATE and password PROTECT your PDF documents
- Compatibility with the most popular file formats - OPEN, EDIT & CREATE new and existing documents
- Manage all your email accounts and efficiently schedule with the inlcuded MAIL & CALENDAR apps
- Lifetime License for 1 Windows PC or Laptop
require "hexapdf"
user_password = ENV.fetch("PDF_USER_PASSWORD")
owner_password = ENV.fetch("PDF_OWNER_PASSWORD")
doc = HexaPDF::Document.new
page = doc.pages.add
page.text("Confidential report", at: [50, 750])
doc.encrypt(
user_password: user_password,
owner_password: owner_password
)
doc.write("report-protected.pdf")
This example illustrates the intended password roles, but check the installed HexaPDF version’s encryption guide and security-handler API for the exact accepted options and defaults. The encryption guide describes AES 128-bit as the default and recommends it for broad compatibility; it also documents AES 256-bit. Do not assume a permission option changes the opening-password behavior.
Encrypt an existing PDF
HexaPDF is a PDF manipulation library as well as a generator. Its API supports supplying a password through decryption_opts when creating a document to decrypt an input. For example, the documented pattern is:
require "hexapdf"
source_password = ENV.fetch("SOURCE_PDF_PASSWORD")
doc = HexaPDF::Document.new(
"source.pdf",
decryption_opts: { password: source_password }
)
user_password = ENV.fetch("PDF_USER_PASSWORD")
owner_password = ENV.fetch("PDF_OWNER_PASSWORD")
doc.encrypt(
user_password: user_password,
owner_password: owner_password
)
doc.write("reprotected.pdf")
Confirm the input and output options against your installed version’s API documentation, particularly if the source PDF is already encrypted or has restrictions. HexaPDF’s repository specifies Ruby 3.0 or newer. It also lists AGPL and commercial licensing; review the current terms for proprietary distribution or network-access deployments, including serving generated PDFs from a web application.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Protect a generated PDF with Prawn
Prawn’s manual demonstrates calling encrypt_document inside the document generation block. Its user_password is the open password; owner_password concerns modifying the document or changing or overriding permissions.
Rank #3
- EXCLUSIVE AMAZON BUNDLE - Securely create, edit, and share PDFs with Adobe Acrobat Pro. Secure your pc and personal information against advanced threats, frauds, and scams with McAfee Total Protection. Introductory offer for new users
- ULTIMATE TOOL FOR CREATIVING – Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go
- REVISIONS - Edit text and images without jumping to another app.
- ELECTRONIC SIGNATURES - E-sign documents or request e-signatures on any device. Recipients don’t need to log in to esign.
- CONVERT PDFs - Convert your pdf files to editable Microsoft Word, Excel, or PowerPoint documents.
require "prawn"
user_password = ENV.fetch("PDF_USER_PASSWORD")
owner_password = ENV.fetch("PDF_OWNER_PASSWORD")
Prawn::Document.generate("report-protected.pdf") do |pdf|
pdf.encrypt_document(
user_password: user_password,
owner_password: owner_password
)
pdf.text("Confidential report")
end
The manual’s example uses literal demonstration strings; do not copy real passwords into source code. Read them from a managed secret or environment variable, and make sure the process has them before generation. Prawn’s API says that an omitted or empty user password leaves the document encrypted but readable without a password, so set a non-empty user password when recipients must enter one.
Prawn 2.5.0 documents a 40-bit limit for its password-derived key. Its security API states, in that context, “In short, you have no security at all against a moderately motivated person.” The same documentation warns that PDF readers are not required to honor permissions and many do not. Treat those limits seriously: this is not a strong confidentiality boundary for sensitive files. See the Prawn manual encryption example and Prawn 2.5.0 security API.
Set permissions without mistaking them for protection
Prawn’s security API documents permission options for printing, modifying content, copying, and modifying annotations, and says they default to true. Exact option names and behavior should be checked in the documentation for the Prawn version you use. HexaPDF likewise exposes permissions through its standard security handler. In both cases, these flags express restrictions for PDF readers, not a dependable way to prevent a recipient from extracting content.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →If your goal is to stop ordinary opening without a password, configure a non-empty user password. Use permission settings only as a reader-compatibility or usability control. If the document’s confidentiality matters, assess the full threat model rather than relying on permissions or on a weak encryption implementation.
Rank #4
- Simple shift planning via an easy drag & drop interface
- Add time-off, sick leave, break entries and holidays
- Email schedules directly to your employees
Store and deliver passwords safely
- Keep production passwords out of source files, version control, logs, and error messages. Load them from an appropriate secret store or protected environment configuration.
- Do not send the PDF and its opening password in the same unprotected message or channel. Give the recipient the password separately.
- Plan how authorized recipients will recover access if a password is lost. The libraries cannot make a forgotten password recoverable by the recipient.
- Keep access to owner credentials especially limited if they permit changing restrictions or accessing the document with owner-level rights.
Verify the result before shipping
Verification is an application workflow, not a guarantee supplied by setting an encryption option. Test the output in the PDF readers and environments your application supports.
- Generate a file with a non-empty user password.
- Open it in a supported PDF reader and confirm that it requests a password.
- Enter the intended password and confirm the expected pages and content are available.
- Try an incorrect password and confirm it does not open normally.
- If you set permission restrictions, check behavior in each reader you support, but do not infer that another reader or tool will enforce the same limits.
- Repeat after library upgrades and review the versioned API documentation and licensing terms before deploying.
Troubleshooting common problems
The PDF opens without asking for a password
Check that you set a non-empty user/open password, not only an owner password or permissions. Prawn specifically documents that an omitted or empty user password can leave an encrypted file readable without a password.
The recipient can still print or copy the PDF
Permission enforcement depends on the reader, and PDF applications are not required to enforce those limits. Do not treat printing, copying, or modification flags as strong security controls.
The library rejects an encryption option
Check the API reference for the exact version in your bundle. In particular, HexaPDF’s entry point is HexaPDF::Document#encrypt, but the exact option names and values should come from the installed version’s documentation rather than a copied example for another release.
Best Value
- Mix an audio, music and voice tracks
- Record single or multiple tracks simultaneously
- Intuitive tools to split, trim, join, and many other editing features
- Loaded with audio effects including EQ, compression, reverb, and more.
- Load an audio file and export to all popular audio formats from studio quality wav to high compression formats
An encrypted source PDF cannot be loaded
When opening an encrypted document with HexaPDF, supply the correct source password in decryption_opts as documented by its API. Confirm that you are providing the password for the input file and not confusing it with the new output user or owner password.
The output is encrypted but not suitable for the security need
Check the encryption algorithm and implementation limitations, not just whether a password prompt appears. HexaPDF documents AES options; Prawn 2.5.0 documents a 40-bit password-derived key and warns about its security. For sensitive material, seek a solution appropriate to the threat model and review it separately.
Deployment raises a licensing question
HexaPDF’s repository lists AGPL and commercial licensing and identifies some proprietary distribution and network-access use cases that may require a commercial license. Check the current vendor terms for the way your application is deployed instead of assuming that a local development use and a hosted production service have identical obligations.
Or skip the browser setup
If your Ruby workflow also needs to capture a web page as a screenshot or PDF, ScreenshotNeo provides a one-call website screenshot API and an MCP server. It does not encrypt or password-protect a PDF generated by your Ruby application, so use the Ruby library above for PDF encryption.
Quick Recap
For a screenshot of a URL, the cURL request is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request options. ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots, and the free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Learn about ScreenshotNeo or sign up for 1,000 free screenshots a month with no card.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

