Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To require a recipient to enter a password before opening a generated PDF, encrypt it with a document-open (user) password. You can do this while generating the file with PDFKit, after generation with a library such as Apache PDFBox, or through a PDF service. A separate permissions password can restrict actions such as printing or copying, but those restrictions are not the same as preventing access to the document’s contents.

Choose the protection you actually need

PDF security settings commonly separate opening a document from limiting what someone can do after opening it. Decide which outcome matters before choosing an implementation.

Goal Setting What it means
Require a password to view the document Document-open or user password The recipient must enter the password to decrypt and open the PDF.
Limit printing, editing, copying, or other actions Permissions, commonly set with an owner password The PDF reader may restrict specified operations. This does not make the document inaccessible to someone who can open it.

Adobe distinguishes the open-password setting from permissions for printing, changes, copying, and accessibility-related text access. The PDFKit documentation cautions: “Note that PDF file itself cannot enforce access privileges.” After a document is decrypted, whether restrictions are respected depends on the reader application. Treat permissions as a compatibility feature for ordinary workflows, not a reliable way to keep sensitive content secret.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If confidentiality is the requirement, use an open password and design the separate delivery and password-sharing process carefully. Avoid logging passwords, and use a channel suited to the sensitivity of the document when sending credentials. The libraries’ password parameters do not decide how your application stores or delivers those credentials.

#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Protect a PDF as you generate it with Node.js and PDFKit

PDFKit documents generation-time encryption through options supplied when creating a PDFDocument. Set userPassword to require a password to open the output. You can also set ownerPassword and a permissions object when you need reader-enforced operation limits.

Here is a minimal runnable example that creates a one-page PDF. Install PDFKit in a Node.js project with npm install pdfkit, save this as create-protected-pdf.js, and run node create-protected-pdf.js. Replace the example credentials with values supplied securely by your application; do not put real passwords in source control.

const PDFDocument = require('pdfkit');
const fs = require('node:fs');

const doc = new PDFDocument({
  userPassword: process.env.PDF_USER_PASSWORD,
  ownerPassword: process.env.PDF_OWNER_PASSWORD,
  permissions: {
    printing: 'lowResolution',
    modifying: false,
    copying: false,
    annotating: false,
    fillingForms: false,
    contentAccessibility: true,
    documentAssembly: false
  }
});

doc.pipe(fs.createWriteStream('protected.pdf'));
doc.fontSize(18).text('Confidential report');
doc.fontSize(11).text('Share the opening password through a separate, controlled channel.');
doc.end();

Supply both environment variables before running the example. For example, in a Unix-like shell, you can run PDF_USER_PASSWORD='open-secret' PDF_OWNER_PASSWORD='manage-secret' node create-protected-pdf.js. Avoid using literal example values outside a local demonstration. If your application only needs an opening password, configure userPassword and omit permissions rather than implying that action restrictions add confidentiality.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Permissions and accessibility

PDFKit’s documented permission options cover printing, modifying, copying, annotating, filling forms, accessibility extraction, and document assembly. The example allows low-resolution printing and accessibility extraction while disabling several other operations. Select permissions based on your use case: blocking copying may interfere with legitimate assistive technology or downstream workflows. Even with restrictions configured, test the generated file in the PDF readers your recipients use.

Rank #2
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
  • There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
  • Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
  • Reorder SKU: LOG-100-M3CW-PP(Security-Report)

PDF version and password constraints

PDFKit says its encryption selection depends on the PDF version option, and its documentation lists both legacy RC4 modes and AES modes. The existence of a legacy option is not a recommendation to use it. Choose encryption deliberately based on your application’s security requirements and the readers you must support; the documentation cited here does not provide cross-viewer interoperability test results.

PDFKit documents a password representation limit that depends on the chosen PDF version. With PDF 1.7 ExtensionLevel 3, the UTF-8 password representation is truncated to 127 bytes. Older versions have a 32-byte limit and a Latin-1 character restriction. These are PDFKit-specific constraints: verify the behavior for the version you deploy, especially if passwords can contain non-ASCII characters or be longer than typical user-entered passwords.

Protect an existing PDF with Apache PDFBox

If your PDF already exists, Apache PDFBox provides a post-generation route. Its 2.0 cookbook demonstrates creating an AccessPermission, configuring permitted operations, creating a StandardProtectionPolicy with owner and user passwords, setting a key length, applying the policy, and saving the document. This is useful when PDF creation and security are separate stages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PDFBox also documents an encrypt command in its 3.0 command-line documentation, with -O and -U options for owner and user passwords and flags for permissions. That CLI documentation lists 256 bits as the default key length. The cookbook example is for PDFBox 2.0, while the CLI details are for 3.0; do not assume API calls, defaults, or command syntax are interchangeable between those versions. Consult documentation matching the PDFBox release installed in your project before using either approach.

For either version, the conceptual sequence is:

  1. Load or generate the PDF.
  2. Choose an opening password if access to the contents must be gated; set an owner password and permissions only if you also need action restrictions.
  3. Select and verify the encryption/key-length settings supported by the exact library version.
  4. Apply protection and save to a new output file.
  5. Open the result in the target readers with and without the opening password, then check any requested permissions.

Use the library’s version-specific examples for executable Java code rather than copying a snippet written for a different major version. The available documentation establishes that PDFBox supports this workflow, but it does not establish universal compatibility across PDF viewers.

Use a hosted PDF service or Acrobat

Adobe PDF Services

Adobe PDF Services documents a Protect PDF API workflow that supports a user password for opening, an owner/permissions password for restrictions, and AES-128 or AES-256. This can suit a system already using Adobe PDF Services. The documentation describes the capability; it is not a comparative assessment of price, privacy, or reliability against libraries.

Adobe Acrobat desktop workflow

For a PDF that does not need to be protected automatically in a generation pipeline, Adobe’s Acrobat guidance describes choosing Protect, selecting a password or certificate security method, configuring protection, and saving the file. Its help pages distinguish document-open password protection from controls for printing, permitted changes, copying, and screen-reader access. Interface labels can change and may vary by Acrobat version, so follow the labels shown in your installed edition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check archival and operational requirements

PDF/A

If the document must conform to PDF/A, check that requirement before adding encryption. PDFKit documents that PDF/A documents cannot be encrypted. Do not assume you can satisfy both requirements simply by enabling an encryption option; confirm the output’s required conformance with the tools and process used for your archival workflow.

Password recovery and delivery

Password loss is a real operational failure mode. Adobe Experience League’s tutorial, updated June 28, 2026, states: “Your password is not stored anywhere and cannot be retrieved if lost or forgotten.” Plan how authorized recipients will receive and retain the password before generating documents at scale. Avoid putting passwords in application logs, URLs, or the same unprotected message as the file.

Compatibility checks

The documentation for PDFKit, PDFBox, Adobe PDF Services, and Acrobat describes implementation options, not a comparative interoperability test. Validate the actual output in the readers and workflows used by your recipients. Check password entry, printing or editing behavior if configured, assistive-technology access, and any archival validation requirement.

How to choose an implementation

Approach Best fit Considerations
PDFKit generation-time encryption A Node.js application creating its own PDFs Protection is configured when constructing the document. Observe PDF-version and password-character limits documented by PDFKit.
Apache PDFBox post-generation encryption A Java workflow that needs to protect an existing or separately generated PDF Keep PDFBox 2.0 cookbook guidance distinct from PDFBox 3.0 CLI guidance.
Adobe PDF Services A workflow already using Adobe’s hosted PDF services Supports documented user/owner password paths and AES-128/AES-256; evaluate service requirements separately.
Acrobat desktop One-off or manual protection by an operator UI labels may vary by product version; manual steps are not a substitute for an automated pipeline at scale.

Choose based on where protection belongs in your pipeline, required encryption and PDF-version behavior, target-reader compatibility, accessibility needs, PDF/A requirements, and how credentials are handled. There is no universal best library established by these implementation documents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting generated PDFs

  • The recipient can open the file without a password. Confirm that the generation path sets the document-open/user password rather than only an owner password or permissions. Recreate the PDF and test it with a reader that prompts for an opening password.
  • The recipient is prompted, but restrictions do not work as expected. Check that the owner password and intended permissions were applied. Reader applications may interpret or enforce permissions differently, and the PDF itself cannot guarantee those restrictions after decryption.
  • A password with accented or non-Latin characters fails. Check the PDFKit version and selected PDF version: its documented character and byte limits differ. Test with the actual application’s password input and the recipient’s reader.
  • An archival validator rejects the file. Check whether the requirement is PDF/A. PDFKit documents that PDF/A cannot be encrypted; resolve the conformance and access-control requirements before choosing an output format.
  • A PDFBox example does not compile or its CLI flags differ. Confirm the installed major version and use the matching documentation. The referenced cookbook API is for 2.0; the command-line encryption page is for 3.0.
  • A recipient forgot the password. Adobe says its password cannot be retrieved if lost or forgotten. Follow your organization’s recovery and reissuance process; do not assume the PDF producer can recover it.

Or skip the browser setup

ScreenshotNeo is a website screenshot API, not a PDF password-protection service; it does not encrypt generated PDFs. For a separate website-capture task, its one-call API can return a screenshot or PDF. The following example captures a webpage as a PDF; it does not add an opening password to that PDF.

Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. It accepts cookie banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets, with each step configurable. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed; responses include X-Page-Verdict and X-Billed headers. Its MCP server offers screenshot and PDF-capture tools for AI agents. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Those are screenshot-service features, separate from PDF encryption.

For website screenshots, visit ScreenshotNeo. Sign up free for 1,000 screenshots a month with no card.

Frequently Asked Questions

Can I add a password to a PDF after generating it?

Yes. Apache PDFBox documents post-generation protection, and Adobe PDF Services documents a Protect PDF workflow. Choose a user/open password if recipients must enter a password to view the document.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a protected PDF password be recovered if it is forgotten?

Adobe Experience League says its password is not stored and cannot be retrieved if lost or forgotten. Establish a credential recovery or document reissue process before distributing protected files.

Quick Recap

Bestseller No. 1
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99
Bestseller No. 2
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business; Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
$9.99
SaleBestseller No. 5
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
Comes with secure packaging; It can be a gift item; Easy to read text
$26.79

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.