Add a password to a PDF
Encrypt a PDF with an open password so it cannot be opened without one, choosing the encryption algorithm that matches your compliance requirements.
Encrypt a PDF document with an open password so it can’t be opened without it. This sets the password required just to open the file, distinct from adding restrictions, which sets permission flags for actions like printing and copying. Choose the encryption algorithm to match your compliance needs. The API is stateless: your document is processed in-region and never stored.
Endpoint
/v1/add_passwordAvailable in every region. See Regions & data residency for routing and data residency.
| Region | URL |
|---|---|
| Global | https://api.pdfblocks.com/v1/add_password |
| United States | https://us.api.pdfblocks.com/v1/add_password |
| US HIPAA | https://hipaa.api.pdfblocks.com/v1/add_password |
| European Union | https://eu.api.pdfblocks.com/v1/add_password |
| United Kingdom | https://uk.api.pdfblocks.com/v1/add_password |
| Canada | https://ca.api.pdfblocks.com/v1/add_password |
| Australia | https://au.api.pdfblocks.com/v1/add_password |
| Japan | https://jp.api.pdfblocks.com/v1/add_password |
| India | https://in.api.pdfblocks.com/v1/add_password |
| Brazil | https://br.api.pdfblocks.com/v1/add_password |
Authentication
Authenticate every request with your secret API key in the X-API-Key header,
over HTTPS. Create and manage keys from the
dashboard. See
Authentication for details.
Request
The endpoint accepts a multipart/form-data request body.
filefilerequiredThe input PDF document.
passwordstringrequiredThe password required to open the document. 4–32 printable ASCII characters
(^[\x20-\x7e]{4,32}$).
encryption_algorithmstringdefault:AES-128The encryption algorithm. One of AES-128 or AES-256.
This sets the open password, which encrypts the document so it can’t be opened without the password. To limit what a reader can do (printing, copying, editing) without requiring a password to open, use Add restrictions instead. For the full lifecycle, see Protecting documents.
Examples
Encrypt a PDF with AES-256 so it can’t be opened without the password:
curl https://api.pdfblocks.com/v1/add_password \
-H 'X-API-Key: your_api_key' \
-F file=@input.pdf \
-F password='0pen-Sesame' \
-F encryption_algorithm=AES-256 \
-o encrypted.pdf# pip install requests
import requests
with open('input.pdf', 'rb') as file:
response = requests.post(
'https://api.pdfblocks.com/v1/add_password',
headers={'X-API-Key': 'your_api_key'},
files={'file': file},
data={
'password': '0pen-Sesame',
'encryption_algorithm': 'AES-256',
},
)
response.raise_for_status()
with open('encrypted.pdf', 'wb') as output:
output.write(response.content)// Node.js 18+
import { readFile, writeFile } from 'node:fs/promises';
const body = new FormData();
body.set('file', new Blob([await readFile('input.pdf')]), 'input.pdf');
body.set('password', '0pen-Sesame');
body.set('encryption_algorithm', 'AES-256');
const response = await fetch('https://api.pdfblocks.com/v1/add_password', {
method: 'POST',
headers: { 'X-API-Key': 'your_api_key' },
body,
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
await writeFile('encrypted.pdf', Buffer.from(await response.arrayBuffer()));<?php
$ch = curl_init('https://api.pdfblocks.com/v1/add_password');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ['X-API-Key: your_api_key'],
CURLOPT_POST => true,
CURLOPT_POSTFIELDS => [
'file' => new CURLFile('input.pdf', 'application/pdf'),
'password' => '0pen-Sesame',
'encryption_algorithm' => 'AES-256',
],
]);
$pdf = curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) === 200) {
file_put_contents('encrypted.pdf', $pdf);
}# gem install http
require 'http'
response = HTTP
.headers('X-API-Key' => 'your_api_key')
.post('https://api.pdfblocks.com/v1/add_password', form: {
file: HTTP::FormData::File.new('input.pdf'),
password: '0pen-Sesame',
encryption_algorithm: 'AES-256',
})
File.write('encrypted.pdf', response.body) if response.status.success?package main
import (
"bytes"
"io"
"mime/multipart"
"net/http"
"os"
)
func main() {
var buf bytes.Buffer
form := multipart.NewWriter(&buf)
file, _ := os.Open("input.pdf")
defer file.Close()
part, _ := form.CreateFormFile("file", "input.pdf")
io.Copy(part, file)
form.WriteField("password", "0pen-Sesame")
form.WriteField("encryption_algorithm", "AES-256")
form.Close()
req, _ := http.NewRequest("POST", "https://api.pdfblocks.com/v1/add_password", &buf)
req.Header.Set("Content-Type", form.FormDataContentType())
req.Header.Set("X-API-Key", "your_api_key")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
out, _ := os.Create("encrypted.pdf")
defer out.Close()
io.Copy(out, res.Body)
}using var client = new HttpClient();
client.DefaultRequestHeaders.Add("X-API-Key", "your_api_key");
using var form = new MultipartFormDataContent
{
{ new ByteArrayContent(File.ReadAllBytes("input.pdf")), "file", "input.pdf" },
{ new StringContent("0pen-Sesame"), "password" },
{ new StringContent("AES-256"), "encryption_algorithm" },
};
var response = await client.PostAsync(
"https://api.pdfblocks.com/v1/add_password", form);
response.EnsureSuccessStatusCode();
await File.WriteAllBytesAsync(
"encrypted.pdf", await response.Content.ReadAsByteArrayAsync());Response
On success, the response is 200 OK with the encrypted PDF as the body:
HTTP/1.1 200 OK
Content-Type: application/pdf
Content-Length: 48213The output is the same document, now encrypted. Its pages and content are unchanged. Stream the body straight to a file, as the examples above do; nothing is stored on our side.
Errors
Failed requests return an application/problem+json body. The most common one
for this endpoint is a 400, returned when a parameter is invalid (for example
a password that isn’t 4–32 printable ASCII characters), with the errors
object naming each field:
{
"type": "https://www.pdfblocks.com/docs/api/v1/error/400",
"title": "One or more validation errors occurred.",
"status": 400,
"errors": {
"password": ["The field password must match the regular expression '^[\\x20-\\x7e]{4,32}$'."]
}
}A missing or invalid X-API-Key returns a 401. See
Errors for every status code and the full response shape.
Recipes
Common variations. Expand one to see it in every language.
Encrypt with the default AES-128
curl https://api.pdfblocks.com/v1/add_password \
-H 'X-API-Key: your_api_key' \
-F file=@input.pdf \
-F password='Tr0ub4dor' \
-o encrypted.pdfimport requests
with open('input.pdf', 'rb') as file:
response = requests.post(
'https://api.pdfblocks.com/v1/add_password',
headers={'X-API-Key': 'your_api_key'},
files={'file': file},
data={'password': 'Tr0ub4dor'},
)
response.raise_for_status()
with open('encrypted.pdf', 'wb') as output:
output.write(response.content)import { readFile, writeFile } from 'node:fs/promises';
const body = new FormData();
body.set('file', new Blob([await readFile('input.pdf')]), 'input.pdf');
body.set('password', 'Tr0ub4dor');
const response = await fetch('https://api.pdfblocks.com/v1/add_password', {
method: 'POST',
headers: { 'X-API-Key': 'your_api_key' },
body,
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
await writeFile('encrypted.pdf', Buffer.from(await response.arrayBuffer()));<?php
$ch = curl_init('https://api.pdfblocks.com/v1/add_password');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ['X-API-Key: your_api_key'],
CURLOPT_POST => true,
CURLOPT_POSTFIELDS => [
'file' => new CURLFile('input.pdf', 'application/pdf'),
'password' => 'Tr0ub4dor',
],
]);
$pdf = curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) === 200) {
file_put_contents('encrypted.pdf', $pdf);
}require 'http'
response = HTTP
.headers('X-API-Key' => 'your_api_key')
.post('https://api.pdfblocks.com/v1/add_password', form: {
file: HTTP::FormData::File.new('input.pdf'),
password: 'Tr0ub4dor',
})
File.write('encrypted.pdf', response.body) if response.status.success?package main
import (
"bytes"
"io"
"mime/multipart"
"net/http"
"os"
)
func main() {
var buf bytes.Buffer
form := multipart.NewWriter(&buf)
file, _ := os.Open("input.pdf")
defer file.Close()
part, _ := form.CreateFormFile("file", "input.pdf")
io.Copy(part, file)
form.WriteField("password", "Tr0ub4dor")
form.Close()
req, _ := http.NewRequest("POST", "https://api.pdfblocks.com/v1/add_password", &buf)
req.Header.Set("Content-Type", form.FormDataContentType())
req.Header.Set("X-API-Key", "your_api_key")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
out, _ := os.Create("encrypted.pdf")
defer out.Close()
io.Copy(out, res.Body)
}using var client = new HttpClient();
client.DefaultRequestHeaders.Add("X-API-Key", "your_api_key");
using var form = new MultipartFormDataContent
{
{ new ByteArrayContent(File.ReadAllBytes("input.pdf")), "file", "input.pdf" },
{ new StringContent("Tr0ub4dor"), "password" },
};
var response = await client.PostAsync(
"https://api.pdfblocks.com/v1/add_password", form);
response.EnsureSuccessStatusCode();
await File.WriteAllBytesAsync(
"encrypted.pdf", await response.Content.ReadAsByteArrayAsync());