Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Generate the PDF first, then encrypt the finished file with pdfcpu. Its documented default is AES-256. Set an owner password to control permissions; add a separate user password if opening the PDF itself must require authentication. Keep both secrets out of source code and logs, and avoid making any unencrypted intermediate publicly accessible.

Choose the right kind of PDF protection

PDF encryption and PDF permissions address different needs. A user password (also called an open password) is required to open an encrypted file. An owner password is used to change permissions; it does not, by itself, require a reader to enter a password before opening the file. pdfcpu requires an owner password in its encryption interface, while the user password is optional. If you omit the user password, the PDF is encrypted but can be opened without one, subject to its configured restrictions.

Requirement Configuration What it does
Require a password to open the PDF Set a user password and an owner password Readers need the user password to open the document; the owner password is for full access and permission changes.
Open without a password, but set restrictions Set an owner password and omit the user password The document opens without an open-password prompt; supported readers may apply the configured restrictions.
Allow opening but limit an operation such as printing Set an owner password and a narrowly selected permission Permission handling depends on the PDF reader and is not a dependable DRM boundary.

For a confidential document, use a user password and deliver it to recipients through a channel separate from the PDF. Permission flags alone cannot stop someone from taking a screenshot, photographing a display, or using software that ignores the restrictions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect the completed PDF with pdfcpu

pdfcpu describes itself as “a PDF processing library and command-line tool written in Go.” It supports encryption as well as operations such as signing, validation, optimization, and extraction. Encrypt the completed artifact—not merely the data or template used to generate it—so the saved file is the protected deliverable.

#1 Best Overall
PDF Extra 2024| Complete PDF Reader and Editor | Create, Edit, Convert, Combine, Comment, Fill & Sign PDFs | Lifetime License | 1 Windows PC | 1 User [PC Online code]
  • EDIT text, images & designs in PDF documents. ORGANIZE PDFs. Convert PDFs to Word, Excel & ePub.
  • READ and Comment PDFs – Intuitive reading modes & document commenting and mark up.
  • CREATE, COMBINE, SCAN and COMPRESS PDFs
  • FILL forms & Digitally Sign PDFs. PROTECT and Encrypt PDFs
  • LIFETIME License for 1 Windows PC or Laptop. 5GB MobiDrive Cloud Storage Included.

Command-line workflow

Once the generator has written and closed input.pdf, encrypt it with the CLI. This example requires both the owner and user passwords, selects AES with a 256-bit key, and requests no permissions for a user-password opening:

pdfcpu encrypt input.pdf protected.pdf --mode aes --key 256 --opw "$PDF_OWNER_PASSWORD" --upw "$PDF_USER_PASSWORD" --perm none

Set PDF_OWNER_PASSWORD and PDF_USER_PASSWORD in your secret manager or protected runtime environment before running the command. Do not substitute real secrets into a committed script. If users should be able to open the PDF without a password, omit the --upw option; keep the owner password. The file is then encrypted but does not require an open password.

The documented encryption guide lists 40-, 128-, and 256-bit AES key-length options, with 256 bits as its default. The command makes the selection explicit. Whether a particular reader supports the resulting encryption depends on its PDF implementation; test the actual readers and workflows your recipients use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
MobiPDF Lifetime - Professional PDF Editor for Windows | Edit, Sign & Convert PDFs | Best Adobe Acrobat Pro Alternative | Lifetime License
  • Edit PDFs with Ease. Modify text, images, and layouts directly within your PDF documents.
  • Convert & Organize. Export PDFs to Word, Excel, or ePub, and organize files with ease.
  • Read & Annotate. Enjoy intuitive reading modes and powerful tools to comment, highlight, and mark up PDFs.
  • Create & Manage PDFs. Create new PDFs, combine multiple files, scan documents, and compress for easy sharing.
  • Fill & Sign Forms. Complete forms and digitally sign documents with secure e-signature tools.

Call the CLI safely from Go

Here is a complete Go helper that invokes the same CLI without building a shell command. It expects the generated input file to exist and be closed, and writes the encrypted output at the supplied path. Install pdfcpu for the deployment environment and make its pdfcpu executable available on PATH.

package main

import (
	"context"
	"errors"
	"fmt"
	"os"
	"os/exec"
	"strings"
)

func protectPDF(ctx context.Context, input, output, ownerPassword, userPassword string) error {
	if strings.TrimSpace(ownerPassword) == "" {
		return errors.New("owner password must not be empty")
	}
	if strings.TrimSpace(input) == "" || strings.TrimSpace(output) == "" {
		return errors.New("input and output paths are required")
	}

	args := []string{
		"encrypt", input, output,
		"--mode", "aes",
		"--key", "256",
		"--opw", ownerPassword,
		"--perm", "none",
	}
	if userPassword != "" {
		args = append(args, "--upw", userPassword)
	}

	cmd := exec.CommandContext(ctx, "pdfcpu", args...)
	// Avoid printing cmd.Args or environment values: the arguments contain secrets.
	cmd.Stdout = os.Stdout
	cmd.Stderr = os.Stderr
	if err := cmd.Run(); err != nil {
		return fmt.Errorf("pdfcpu encrypt failed: %w", err)
	}
	return nil
}

func main() {
	owner := os.Getenv("PDF_OWNER_PASSWORD")
	user := os.Getenv("PDF_USER_PASSWORD") // Leave unset for no open-password prompt.
	if err := protectPDF(context.Background(), "generated.pdf", "protected.pdf", owner, user); err != nil {
		fmt.Fprintln(os.Stderr, err)
		os.Exit(1)
	}
}

The helper sends passwords as process arguments because that is how this CLI invocation accepts them. On systems where other local users can inspect process arguments, that may expose the secrets. Prefer a deployment account and host configuration that restrict local process visibility, or use the library API and your established secret-handling patterns. Never log the command arguments. Use a unique output path and ensure the output directory is not publicly served before encryption completes.

Use the Go API directly

For applications that already use pdfcpu, the project’s API supports file encryption. The documented configuration pattern is:

Rank #3
Adobe Acrobat Pro | PDF Software | Convert, Edit, E-Sign, Protect | PC/Mac Online Code | Activation Required
  • Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go.
  • Edit text and images without jumping to another app.
  • E-sign documents or request e-signatures on any device. Recipients don’t need to log in to e-sign.
  • Convert PDFs to editable Microsoft Word, Excel, or PowerPoint documents.
  • Share PDFs for collaboration. Commenting features make it easy for reviewers to comment, mark up, and annotate.
conf := model.NewAESConfiguration(userPassword, ownerPassword, 256)
conf.Permissions = model.PermissionsNone
err := api.EncryptFileContext(ctx, inFile, outFile, conf)

Import the api and model packages from the pdfcpu module version pinned in your go.mod. Check that version’s exact function signature and error behavior before copying the snippet: API signatures can vary across releases. Pass secrets from a secret manager or protected runtime configuration, not literals in source control. If you need to change permissions on an already encrypted file, pdfcpu also exposes SetPermissionsFile; provide the current passwords and verify the signature for your pinned version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set permissions with their limits in mind

pdfcpu’s permissions command accepts none, all, print, and binary or hexadecimal permission masks. Select the narrowest setting that serves the actual use case. For example, a document intended to be printable but otherwise restricted calls for a print-only configuration rather than an unrestricted setting. Confirm the exact mask syntax against the installed pdfcpu version before using a custom mask.

These settings are not DRM. PDF permission flags are advisory, and reader software may enforce them differently or not at all. The gofpdf package likewise documents its print, modify, copy, annotations, and forms flags as advisory. If controlling who can obtain a document matters more than discouraging casual copying, combine encryption with access-controlled delivery, short-lived download authorization, and recipient-specific user passwords. Do not promise that permission bits can prevent copying or printing on every device.

Rank #4
PDF Extra Lifetime - Professional PDF Editor - Best Adobe Acrobat Pro Alternative - Lifetime License for Windows PC
  • Perfect Adobe Acrobat Pro alternative – lifetime license for Windows 10 and 11.
  • EDIT text, images, pages, hyperlinks, designs in PDF documents. ORGANIZE PDFs.
  • READ and Comment on PDFs – Intuitive reading modes & document commenting and mark up tools!
  • CREATE, COMBINE, SCAN and COMPRESS PDFs.
  • FILL forms & Digitally Sign PDFs. Work with Digital certificates

Reduce exposure of plaintext and passwords

  • Encrypt after generation, before delivery. Keep the unencrypted output in a private working area and do not expose a public URL until encryption has succeeded.
  • Limit temporary files. If generation and encryption use files, restrict the directory and permissions, clean up intermediates on both success and failure, and avoid long-lived plaintext copies.
  • Protect secrets. Store owner and user passwords in a secret manager or protected password files. Do not put them in source control, query strings, application logs, or diagnostic output.
  • Separate password roles. Give recipients the user password when they should open the PDF but not control its permissions. Keep the owner password under administrative control.
  • Consider streaming. pdfcpu supports stdin/stdout mode for encrypting a stream. That can let a service upload protected output without keeping a second long-lived plaintext file, but confirm the installed CLI’s stream syntax and your generator’s ability to supply a stream before adopting it.
  • Validate the artifact. Check that the produced PDF opens with the intended password behavior and test the required operations—such as printing, copying, and form filling—in the readers used by your organization.

Common failures and how to diagnose them

Symptom Likely cause What to check
CLI reports an unknown option or command The installed pdfcpu version uses different syntax or the executable is not the expected build. Check the installed version and that version’s encryption command help; keep deployment versions pinned.
Output is missing, incomplete, or cannot be opened The generator had not finished writing, the encryption command failed, or the output path was incorrect. Close or flush the generator’s file before encryption, check the process exit error, and validate the resulting PDF before publishing it.
The PDF opens without asking for a password No user/open password was supplied. Pass a non-empty user password if opening must require authentication; an owner password alone is not an open-password prompt.
Reader allows an operation that was meant to be restricted The reader does not enforce the permission flags, or the PDF was opened with owner-level access. Test with the user password in the target reader. Treat permissions as advisory and use controlled delivery for stronger access boundaries.
Secrets appear in diagnostics or process inspection The wrapper logged command arguments or the host exposes process command lines to other users. Remove argument logging, restrict local access, and assess whether direct API use or a protected password-file workflow better fits the environment.
Encryption works locally but recipients cannot open the file A recipient’s PDF reader may not support the encryption configuration or may handle permissions differently. Test the exact output with the recipients’ supported readers and confirm password delivery and entry steps.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When an in-process library is the wrong boundary

An in-process library keeps PDF processing within your Go service and avoids sending document contents to a third party. It also puts dependency updates, compute capacity, temporary-file hygiene, and operational monitoring in your hands. A hosted protection endpoint can reduce the amount of encryption code you operate, but it means transmitting the PDF and its password material outside your service. Before choosing a hosted service, assess data residency, retention, quotas, latency, authentication, and operational control. GoPDF documents a hosted POST /pdf/protect endpoint with userPassword and ownerPassword fields; no further service terms or limits are established here, so verify them directly before sending sensitive documents.

Or skip the browser setup

For a separate task—capturing a website screenshot rather than encrypting a generated PDF—ScreenshotNeo offers a one-request screenshot API and an MCP server. It does not protect PDFs. Its browser capture removes cookie banners, popups, and chat widgets before the shot; bot checks, blank pages, and failed loads are never billed. AI agents can take screenshots through its MCP server, and the Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Example cURL request, with the API details in the ScreenshotNeo documentation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.

Best Value
PDF Pro 3 - PDF editor to create, edit, convert and merge PDFs - 100% Compatible with Adobe Acrobat - for Windows 11, 10, 8.1, 7
  • ALL-IN-ONE SOLUTION – read, edit, convert, merge and protect your PDF files
  • MAXIMUM FUNCIONALITY – create interactive forms, compare PDFs, bates numbering, find and replace text or colors, convert documents, OCR engine, comment, highlight, fill out and print forms, document protection and others
  • EASY TO INSTALL AND USE – well-structured user-interface, in-program instructions, free tech support whenever you need it
  • GREAT VALUE FOR MONEY - why spend a fortune if you can have maximum functionality at a reasonable price - this also fits the requirements of companies very well

Frequently Asked Questions

Does encrypting a PDF also encrypt the original data or template used to generate it?

No. Encryption applies to the completed PDF artifact. Protect the generated output before making it available to readers.

Can I use the owner password as the reader’s opening password?

The passwords serve different roles in pdfcpu’s model: the user password is for opening the document, while the owner password controls permissions. Use a user password when opening must require authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
PDF Extra 2024| Complete PDF Reader and Editor | Create, Edit, Convert, Combine, Comment, Fill & Sign PDFs | Lifetime License | 1 Windows PC | 1 User [PC Online code]
PDF Extra 2024| Complete PDF Reader and Editor | Create, Edit, Convert, Combine, Comment, Fill & Sign PDFs | Lifetime License | 1 Windows PC | 1 User [PC Online code]
READ and Comment PDFs – Intuitive reading modes & document commenting and mark up.; CREATE, COMBINE, SCAN and COMPRESS PDFs
$99.99
Bestseller No. 2
MobiPDF Lifetime - Professional PDF Editor for Windows | Edit, Sign & Convert PDFs | Best Adobe Acrobat Pro Alternative | Lifetime License
MobiPDF Lifetime - Professional PDF Editor for Windows | Edit, Sign & Convert PDFs | Best Adobe Acrobat Pro Alternative | Lifetime License
Edit PDFs with Ease. Modify text, images, and layouts directly within your PDF documents.; Convert & Organize. Export PDFs to Word, Excel, or ePub, and organize files with ease.
$99.99
Bestseller No. 3
Adobe Acrobat Pro | PDF Software | Convert, Edit, E-Sign, Protect | PC/Mac Online Code | Activation Required
Adobe Acrobat Pro | PDF Software | Convert, Edit, E-Sign, Protect | PC/Mac Online Code | Activation Required
Edit text and images without jumping to another app.; Convert PDFs to editable Microsoft Word, Excel, or PowerPoint documents.
$239.88
Bestseller No. 4
PDF Extra Lifetime - Professional PDF Editor - Best Adobe Acrobat Pro Alternative - Lifetime License for Windows PC
PDF Extra Lifetime - Professional PDF Editor - Best Adobe Acrobat Pro Alternative - Lifetime License for Windows PC
Perfect Adobe Acrobat Pro alternative – lifetime license for Windows 10 and 11.; EDIT text, images, pages, hyperlinks, designs in PDF documents. ORGANIZE PDFs.
$99.99
Bestseller No. 5
PDF Pro 3 - PDF editor to create, edit, convert and merge PDFs - 100% Compatible with Adobe Acrobat - for Windows 11, 10, 8.1, 7
PDF Pro 3 - PDF editor to create, edit, convert and merge PDFs - 100% Compatible with Adobe Acrobat - for Windows 11, 10, 8.1, 7
ALL-IN-ONE SOLUTION – read, edit, convert, merge and protect your PDF files
$29.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.