Go to Page

Add a password to a PDF

Encrypt a PDF with an open password so it cannot be opened without one, choosing the encryption algorithm that matches your compliance requirements.

Encrypt a PDF document with an open password so it can’t be opened without it. This sets the password required just to open the file, distinct from adding restrictions, which sets permission flags for actions like printing and copying. Choose the encryption algorithm to match your compliance needs. The API is stateless: your document is processed in-region and never stored.

Endpoint

POST
/v1/add_password

Available in every region. See Regions & data residency for routing and data residency.

Region URL
Global https://api.pdfblocks.com/v1/add_password
United States https://us.api.pdfblocks.com/v1/add_password
US HIPAA https://hipaa.api.pdfblocks.com/v1/add_password
European Union https://eu.api.pdfblocks.com/v1/add_password
United Kingdom https://uk.api.pdfblocks.com/v1/add_password
Canada https://ca.api.pdfblocks.com/v1/add_password
Australia https://au.api.pdfblocks.com/v1/add_password
Japan https://jp.api.pdfblocks.com/v1/add_password
India https://in.api.pdfblocks.com/v1/add_password
Brazil https://br.api.pdfblocks.com/v1/add_password

Authentication

Authenticate every request with your secret API key in the X-API-Key header, over HTTPS. Create and manage keys from the dashboard. See Authentication for details.

Request

The endpoint accepts a multipart/form-data request body.

filefilerequired

The input PDF document.

passwordstringrequired

The password required to open the document. 4–32 printable ASCII characters (^[\x20-\x7e]{4,32}$).

encryption_algorithmstringdefault:AES-128

The encryption algorithm. One of AES-128 or AES-256.

This sets the open password, which encrypts the document so it can’t be opened without the password. To limit what a reader can do (printing, copying, editing) without requiring a password to open, use Add restrictions instead. For the full lifecycle, see Protecting documents.

Examples

Encrypt a PDF with AES-256 so it can’t be opened without the password:

cURLbash
curl https://api.pdfblocks.com/v1/add_password \
  -H 'X-API-Key: your_api_key' \
  -F file=@input.pdf \
  -F password='0pen-Sesame' \
  -F encryption_algorithm=AES-256 \
  -o encrypted.pdf
Pythonpython
# pip install requests
import requests

with open('input.pdf', 'rb') as file:
    response = requests.post(
        'https://api.pdfblocks.com/v1/add_password',
        headers={'X-API-Key': 'your_api_key'},
        files={'file': file},
        data={
            'password': '0pen-Sesame',
            'encryption_algorithm': 'AES-256',
        },
    )

response.raise_for_status()
with open('encrypted.pdf', 'wb') as output:
    output.write(response.content)
Node.jsjavascript
// Node.js 18+
import { readFile, writeFile } from 'node:fs/promises';

const body = new FormData();
body.set('file', new Blob([await readFile('input.pdf')]), 'input.pdf');
body.set('password', '0pen-Sesame');
body.set('encryption_algorithm', 'AES-256');

const response = await fetch('https://api.pdfblocks.com/v1/add_password', {
  method: 'POST',
  headers: { 'X-API-Key': 'your_api_key' },
  body,
});

if (!response.ok) throw new Error(`Request failed: ${response.status}`);
await writeFile('encrypted.pdf', Buffer.from(await response.arrayBuffer()));
PHPphp
<?php
$ch = curl_init('https://api.pdfblocks.com/v1/add_password');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => ['X-API-Key: your_api_key'],
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => [
        'file' => new CURLFile('input.pdf', 'application/pdf'),
        'password' => '0pen-Sesame',
        'encryption_algorithm' => 'AES-256',
    ],
]);

$pdf = curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) === 200) {
    file_put_contents('encrypted.pdf', $pdf);
}
Rubyruby
# gem install http
require 'http'

response = HTTP
  .headers('X-API-Key' => 'your_api_key')
  .post('https://api.pdfblocks.com/v1/add_password', form: {
    file: HTTP::FormData::File.new('input.pdf'),
    password: '0pen-Sesame',
    encryption_algorithm: 'AES-256',
  })

File.write('encrypted.pdf', response.body) if response.status.success?
Gogo
package main

import (
	"bytes"
	"io"
	"mime/multipart"
	"net/http"
	"os"
)

func main() {
	var buf bytes.Buffer
	form := multipart.NewWriter(&buf)

	file, _ := os.Open("input.pdf")
	defer file.Close()
	part, _ := form.CreateFormFile("file", "input.pdf")
	io.Copy(part, file)

	form.WriteField("password", "0pen-Sesame")
	form.WriteField("encryption_algorithm", "AES-256")
	form.Close()

	req, _ := http.NewRequest("POST", "https://api.pdfblocks.com/v1/add_password", &buf)
	req.Header.Set("Content-Type", form.FormDataContentType())
	req.Header.Set("X-API-Key", "your_api_key")

	res, _ := http.DefaultClient.Do(req)
	defer res.Body.Close()

	out, _ := os.Create("encrypted.pdf")
	defer out.Close()
	io.Copy(out, res.Body)
}
C#csharp
using var client = new HttpClient();
client.DefaultRequestHeaders.Add("X-API-Key", "your_api_key");

using var form = new MultipartFormDataContent
{
    { new ByteArrayContent(File.ReadAllBytes("input.pdf")), "file", "input.pdf" },
    { new StringContent("0pen-Sesame"), "password" },
    { new StringContent("AES-256"), "encryption_algorithm" },
};

var response = await client.PostAsync(
    "https://api.pdfblocks.com/v1/add_password", form);
response.EnsureSuccessStatusCode();
await File.WriteAllBytesAsync(
    "encrypted.pdf", await response.Content.ReadAsByteArrayAsync());

Response

On success, the response is 200 OK with the encrypted PDF as the body:

HTTP/1.1 200 OK
Content-Type: application/pdf
Content-Length: 48213

The output is the same document, now encrypted. Its pages and content are unchanged. Stream the body straight to a file, as the examples above do; nothing is stored on our side.

Errors

Failed requests return an application/problem+json body. The most common one for this endpoint is a 400, returned when a parameter is invalid (for example a password that isn’t 4–32 printable ASCII characters), with the errors object naming each field:

{
  "type": "https://www.pdfblocks.com/docs/api/v1/error/400",
  "title": "One or more validation errors occurred.",
  "status": 400,
  "errors": {
    "password": ["The field password must match the regular expression '^[\\x20-\\x7e]{4,32}$'."]
  }
}

A missing or invalid X-API-Key returns a 401. See Errors for every status code and the full response shape.

Recipes

Common variations. Expand one to see it in every language.

Encrypt with the default AES-128
cURLbash
curl https://api.pdfblocks.com/v1/add_password \
  -H 'X-API-Key: your_api_key' \
  -F file=@input.pdf \
  -F password='Tr0ub4dor' \
  -o encrypted.pdf
Pythonpython
import requests

with open('input.pdf', 'rb') as file:
    response = requests.post(
        'https://api.pdfblocks.com/v1/add_password',
        headers={'X-API-Key': 'your_api_key'},
        files={'file': file},
        data={'password': 'Tr0ub4dor'},
    )

response.raise_for_status()
with open('encrypted.pdf', 'wb') as output:
    output.write(response.content)
Node.jsjavascript
import { readFile, writeFile } from 'node:fs/promises';

const body = new FormData();
body.set('file', new Blob([await readFile('input.pdf')]), 'input.pdf');
body.set('password', 'Tr0ub4dor');

const response = await fetch('https://api.pdfblocks.com/v1/add_password', {
  method: 'POST',
  headers: { 'X-API-Key': 'your_api_key' },
  body,
});

if (!response.ok) throw new Error(`Request failed: ${response.status}`);
await writeFile('encrypted.pdf', Buffer.from(await response.arrayBuffer()));
PHPphp
<?php
$ch = curl_init('https://api.pdfblocks.com/v1/add_password');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => ['X-API-Key: your_api_key'],
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => [
        'file' => new CURLFile('input.pdf', 'application/pdf'),
        'password' => 'Tr0ub4dor',
    ],
]);

$pdf = curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) === 200) {
    file_put_contents('encrypted.pdf', $pdf);
}
Rubyruby
require 'http'

response = HTTP
  .headers('X-API-Key' => 'your_api_key')
  .post('https://api.pdfblocks.com/v1/add_password', form: {
    file: HTTP::FormData::File.new('input.pdf'),
    password: 'Tr0ub4dor',
  })

File.write('encrypted.pdf', response.body) if response.status.success?
Gogo
package main

import (
	"bytes"
	"io"
	"mime/multipart"
	"net/http"
	"os"
)

func main() {
	var buf bytes.Buffer
	form := multipart.NewWriter(&buf)

	file, _ := os.Open("input.pdf")
	defer file.Close()
	part, _ := form.CreateFormFile("file", "input.pdf")
	io.Copy(part, file)

	form.WriteField("password", "Tr0ub4dor")
	form.Close()

	req, _ := http.NewRequest("POST", "https://api.pdfblocks.com/v1/add_password", &buf)
	req.Header.Set("Content-Type", form.FormDataContentType())
	req.Header.Set("X-API-Key", "your_api_key")

	res, _ := http.DefaultClient.Do(req)
	defer res.Body.Close()

	out, _ := os.Create("encrypted.pdf")
	defer out.Close()
	io.Copy(out, res.Body)
}
C#csharp
using var client = new HttpClient();
client.DefaultRequestHeaders.Add("X-API-Key", "your_api_key");

using var form = new MultipartFormDataContent
{
    { new ByteArrayContent(File.ReadAllBytes("input.pdf")), "file", "input.pdf" },
    { new StringContent("Tr0ub4dor"), "password" },
};

var response = await client.PostAsync(
    "https://api.pdfblocks.com/v1/add_password", form);
response.EnsureSuccessStatusCode();
await File.WriteAllBytesAsync(
    "encrypted.pdf", await response.Content.ReadAsByteArrayAsync());