This page gathers the three things people do to a PDF’s security layer. Protect adds a password and decides what readers may do. Unlock removes a password you already know. Metadata edits or clears the hidden properties that travel with the file. Every mode works on the file inside your browser tab, so a contract, statement or HR document is never uploaded to be locked, unlocked or cleaned.
Protect: encryption is only as strong as the passphrase
Password-protecting a PDF wraps it in AES-128 encryption (the PDF 1.7 Standard Security Handler), so the content is unreadable without the key. AES is the same class of encryption that secures banking and messaging. The part people get wrong is the password: “1234” or a pet’s name falls to a brute-force guess in moments regardless of the cipher. A long, unique passphrase is what turns strong encryption into real protection. The Generate Strong button creates a 16-character password, shows it, and copies it so you can store it before encrypting.
PDF supports two passwords. The user password is required to open the document. The owner password allows full access and bypasses the permission restrictions — print, copy, edit, annotate, fill forms, assemble pages, and screen-reader access. Setting both lets you share the user password with readers who can only do what you allow, while keeping the owner password for yourself.
- Use a real passphrase — length beats complexity; several unrelated words are strong and memorable.
- Deliver out-of-band — send the PDF and the password through different channels so one intercepted message isn’t enough.
- Know the limits — a password stops opening, but anyone you give it to can remove it; encryption controls access, not what an authorized reader does next.
- Store it somewhere safe — there is no recovery. A lost password means a lost document.
Unlock: two kinds of lock, and only one of them is yours to remove
PDF protection comes in two flavors that people often confuse. Some files demand a password before they’ll open — the content is genuinely encrypted and unreadable without it. Others open freely but mark printing, copying text, or editing as not allowed; that’s a permissions layer aimed at controlling what you do with a document you can already read.
The first is protection on you. Remove it with the password you were given and you’ve simply stopped re-entering something you already know — a bank statement you must upload to a portal that rejects encrypted files, or an archive you open every day. The second is the owner’s instruction to you, and it is famously weak: the content isn’t encrypted against the reader, so most PDF libraries will drop those flags on request, no password involved. That weakness is not permission. Circumventing it is what anti-circumvention law in the US, EU and UK is written about.
So the Unlock mode only does the first thing. Hand it a document that opens freely and it tells you there is nothing to decrypt and stops. The restrictions panel shows you what a file limits, so you know what you’re dealing with; it will not offer to remove it. Use it on your own files, or on files whose owner gave you the password and the go-ahead — knowing a password is not the same as being authorized to remove it.
One trade-off to plan for: PDF.js checks your password, decrypts the content, and each page is rendered into a fresh, unencrypted file. The output looks and prints identically, but it is an image of each page — text is no longer selectable or searchable, and the file usually grows. If you need the text itself, run the original encrypted file through the PDF Converter with the password instead.
Metadata: the information you didn’t know you were sending
Every PDF carries a layer of metadata most people never look at: title, author, subject, keywords, the creating application, and timestamps. It’s what lets a library or search index identify a document — and it’s also a quiet leak. An Author field can name a colleague who never meant to be associated with a file; a title pulled from a template can reveal an internal codename or a prior client; timestamps can contradict a claimed timeline.
- Set it right — give a finished document an accurate title, author and keywords so it’s findable and properly credited.
- Clean it up — clear author names, software fingerprints and stale titles before sending a file outside your organization.
Because metadata sits apart from page content, editing it never changes a word or image on the pages. And since the editing happens locally, you’re not handing the very metadata you want to remove to a third-party server in the process.
A sensible order when you need more than one
If a document needs clean properties and a password, edit the metadata first and protect it last — encryption covers the metadata too, and a protected file has to be unlocked before its properties can be changed. To edit a file that is already protected, unlock it with its password, make your change, then protect it again with a fresh password.