# Add a password to a PDF

Encrypt a PDF with an open password so it cannot be opened without one, choosing the encryption algorithm that matches your compliance requirements.

Encrypt a PDF document with an open password so it can't be opened without it.
This sets the password required just to open the file, distinct from
[adding restrictions](/docs/api/add-restrictions-to-pdf), which sets permission
flags for actions like printing and copying. Choose the encryption algorithm to
match your compliance needs. The API is stateless: your document is processed
in-region and never stored.

## Endpoint

<Endpoint method="POST" path="/v1/add_password" />

Available in every region. See [Regions & data residency](/docs/api/regions-and-data-residency)
for routing and data residency.

| Region         | URL                                            |
| -------------- | ---------------------------------------------- |
| Global         | `https://api.pdfblocks.com/v1/add_password`    |
| United States  | `https://us.api.pdfblocks.com/v1/add_password` |
| US HIPAA       | `https://hipaa.api.pdfblocks.com/v1/add_password` |
| European Union | `https://eu.api.pdfblocks.com/v1/add_password` |
| United Kingdom | `https://uk.api.pdfblocks.com/v1/add_password` |
| Canada         | `https://ca.api.pdfblocks.com/v1/add_password` |
| Australia      | `https://au.api.pdfblocks.com/v1/add_password` |
| Japan          | `https://jp.api.pdfblocks.com/v1/add_password` |
| India          | `https://in.api.pdfblocks.com/v1/add_password` |
| Brazil         | `https://br.api.pdfblocks.com/v1/add_password` |

## Authentication

Authenticate every request with your secret API key in the `X-API-Key` header,
over HTTPS. Create and manage keys from the
[dashboard](https://dashboard.pdfblocks.com). See
[Authentication](/docs/api/authentication) for details.

## Request

The endpoint accepts a `multipart/form-data` request body.

<ParamField name="file" type="file" required>
  The input PDF document.
</ParamField>

<ParamField name="password" type="string" required>
  The password required to open the document. 4–32 printable ASCII characters
  (`^[\x20-\x7e]{4,32}$`).
</ParamField>

<ParamField name="encryption_algorithm" type="string" default="AES-128">
  The encryption algorithm. One of `AES-128` or `AES-256`.
</ParamField>

<Note>
  This sets the open password, which encrypts the document so it can't be opened
  without the password. To limit what a reader can do (printing, copying,
  editing) without requiring a password to open, use
  [Add restrictions](/docs/api/add-restrictions-to-pdf) instead. For the full
  lifecycle, see [Protecting documents](/docs/api/protecting-documents).
</Note>

## Examples

Encrypt a PDF with AES-256 so it can't be opened without the password:

<CodeGroup>

```bash title="cURL"
curl https://api.pdfblocks.com/v1/add_password \
  -H 'X-API-Key: your_api_key' \
  -F file=@input.pdf \
  -F password='0pen-Sesame' \
  -F encryption_algorithm=AES-256 \
  -o encrypted.pdf
```

```python title="Python"
# pip install requests
import requests

with open('input.pdf', 'rb') as file:
    response = requests.post(
        'https://api.pdfblocks.com/v1/add_password',
        headers={'X-API-Key': 'your_api_key'},
        files={'file': file},
        data={
            'password': '0pen-Sesame',
            'encryption_algorithm': 'AES-256',
        },
    )

response.raise_for_status()
with open('encrypted.pdf', 'wb') as output:
    output.write(response.content)
```

```javascript title="Node.js"
// Node.js 18+
import { readFile, writeFile } from 'node:fs/promises';

const body = new FormData();
body.set('file', new Blob([await readFile('input.pdf')]), 'input.pdf');
body.set('password', '0pen-Sesame');
body.set('encryption_algorithm', 'AES-256');

const response = await fetch('https://api.pdfblocks.com/v1/add_password', {
  method: 'POST',
  headers: { 'X-API-Key': 'your_api_key' },
  body,
});

if (!response.ok) throw new Error(`Request failed: ${response.status}`);
await writeFile('encrypted.pdf', Buffer.from(await response.arrayBuffer()));
```

```php title="PHP"
<?php
$ch = curl_init('https://api.pdfblocks.com/v1/add_password');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => ['X-API-Key: your_api_key'],
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => [
        'file' => new CURLFile('input.pdf', 'application/pdf'),
        'password' => '0pen-Sesame',
        'encryption_algorithm' => 'AES-256',
    ],
]);

$pdf = curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) === 200) {
    file_put_contents('encrypted.pdf', $pdf);
}
```

```ruby title="Ruby"
# gem install http
require 'http'

response = HTTP
  .headers('X-API-Key' => 'your_api_key')
  .post('https://api.pdfblocks.com/v1/add_password', form: {
    file: HTTP::FormData::File.new('input.pdf'),
    password: '0pen-Sesame',
    encryption_algorithm: 'AES-256',
  })

File.write('encrypted.pdf', response.body) if response.status.success?
```

```go title="Go"
package main

import (
	"bytes"
	"io"
	"mime/multipart"
	"net/http"
	"os"
)

func main() {
	var buf bytes.Buffer
	form := multipart.NewWriter(&buf)

	file, _ := os.Open("input.pdf")
	defer file.Close()
	part, _ := form.CreateFormFile("file", "input.pdf")
	io.Copy(part, file)

	form.WriteField("password", "0pen-Sesame")
	form.WriteField("encryption_algorithm", "AES-256")
	form.Close()

	req, _ := http.NewRequest("POST", "https://api.pdfblocks.com/v1/add_password", &buf)
	req.Header.Set("Content-Type", form.FormDataContentType())
	req.Header.Set("X-API-Key", "your_api_key")

	res, _ := http.DefaultClient.Do(req)
	defer res.Body.Close()

	out, _ := os.Create("encrypted.pdf")
	defer out.Close()
	io.Copy(out, res.Body)
}
```

```csharp title="C#"
using var client = new HttpClient();
client.DefaultRequestHeaders.Add("X-API-Key", "your_api_key");

using var form = new MultipartFormDataContent
{
    { new ByteArrayContent(File.ReadAllBytes("input.pdf")), "file", "input.pdf" },
    { new StringContent("0pen-Sesame"), "password" },
    { new StringContent("AES-256"), "encryption_algorithm" },
};

var response = await client.PostAsync(
    "https://api.pdfblocks.com/v1/add_password", form);
response.EnsureSuccessStatusCode();
await File.WriteAllBytesAsync(
    "encrypted.pdf", await response.Content.ReadAsByteArrayAsync());
```

</CodeGroup>

## Response

On success, the response is `200 OK` with the encrypted PDF as the body:

```http
HTTP/1.1 200 OK
Content-Type: application/pdf
Content-Length: 48213
```

The output is the same document, now encrypted. Its pages and content are
unchanged. Stream the body straight to a file, as the examples above do; nothing
is stored on our side.

## Errors

Failed requests return an `application/problem+json` body. The most common one
for this endpoint is a `400`, returned when a parameter is invalid (for example
a `password` that isn't 4–32 printable ASCII characters), with the `errors`
object naming each field:

```json
{
  "type": "https://www.pdfblocks.com/docs/api/v1/error/400",
  "title": "One or more validation errors occurred.",
  "status": 400,
  "errors": {
    "password": ["The field password must match the regular expression '^[\\x20-\\x7e]{4,32}$'."]
  }
}
```

A missing or invalid `X-API-Key` returns a `401`. See
[Errors](/docs/api/errors) for every status code and the full response shape.

## Recipes

Common variations. Expand one to see it in every language.

<AccordionGroup>

<Accordion title="Encrypt with the default AES-128">

<CodeGroup>

```bash title="cURL"
curl https://api.pdfblocks.com/v1/add_password \
  -H 'X-API-Key: your_api_key' \
  -F file=@input.pdf \
  -F password='Tr0ub4dor' \
  -o encrypted.pdf
```

```python title="Python"
import requests

with open('input.pdf', 'rb') as file:
    response = requests.post(
        'https://api.pdfblocks.com/v1/add_password',
        headers={'X-API-Key': 'your_api_key'},
        files={'file': file},
        data={'password': 'Tr0ub4dor'},
    )

response.raise_for_status()
with open('encrypted.pdf', 'wb') as output:
    output.write(response.content)
```

```javascript title="Node.js"
import { readFile, writeFile } from 'node:fs/promises';

const body = new FormData();
body.set('file', new Blob([await readFile('input.pdf')]), 'input.pdf');
body.set('password', 'Tr0ub4dor');

const response = await fetch('https://api.pdfblocks.com/v1/add_password', {
  method: 'POST',
  headers: { 'X-API-Key': 'your_api_key' },
  body,
});

if (!response.ok) throw new Error(`Request failed: ${response.status}`);
await writeFile('encrypted.pdf', Buffer.from(await response.arrayBuffer()));
```

```php title="PHP"
<?php
$ch = curl_init('https://api.pdfblocks.com/v1/add_password');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => ['X-API-Key: your_api_key'],
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => [
        'file' => new CURLFile('input.pdf', 'application/pdf'),
        'password' => 'Tr0ub4dor',
    ],
]);

$pdf = curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) === 200) {
    file_put_contents('encrypted.pdf', $pdf);
}
```

```ruby title="Ruby"
require 'http'

response = HTTP
  .headers('X-API-Key' => 'your_api_key')
  .post('https://api.pdfblocks.com/v1/add_password', form: {
    file: HTTP::FormData::File.new('input.pdf'),
    password: 'Tr0ub4dor',
  })

File.write('encrypted.pdf', response.body) if response.status.success?
```

```go title="Go"
package main

import (
	"bytes"
	"io"
	"mime/multipart"
	"net/http"
	"os"
)

func main() {
	var buf bytes.Buffer
	form := multipart.NewWriter(&buf)

	file, _ := os.Open("input.pdf")
	defer file.Close()
	part, _ := form.CreateFormFile("file", "input.pdf")
	io.Copy(part, file)

	form.WriteField("password", "Tr0ub4dor")
	form.Close()

	req, _ := http.NewRequest("POST", "https://api.pdfblocks.com/v1/add_password", &buf)
	req.Header.Set("Content-Type", form.FormDataContentType())
	req.Header.Set("X-API-Key", "your_api_key")

	res, _ := http.DefaultClient.Do(req)
	defer res.Body.Close()

	out, _ := os.Create("encrypted.pdf")
	defer out.Close()
	io.Copy(out, res.Body)
}
```

```csharp title="C#"
using var client = new HttpClient();
client.DefaultRequestHeaders.Add("X-API-Key", "your_api_key");

using var form = new MultipartFormDataContent
{
    { new ByteArrayContent(File.ReadAllBytes("input.pdf")), "file", "input.pdf" },
    { new StringContent("Tr0ub4dor"), "password" },
};

var response = await client.PostAsync(
    "https://api.pdfblocks.com/v1/add_password", form);
response.EnsureSuccessStatusCode();
await File.WriteAllBytesAsync(
    "encrypted.pdf", await response.Content.ReadAsByteArrayAsync());
```

</CodeGroup>

</Accordion>

</AccordionGroup>

## Related actions

<CardGroup cols={2}>

<Card title="Remove the password" href="/docs/api/remove-password-from-pdf">
  Decrypt a password-protected PDF.
</Card>

<Card title="Add restrictions" href="/docs/api/add-restrictions-to-pdf">
  Set permission flags instead of an open password.
</Card>

<Card title="Remove restrictions" href="/docs/api/remove-restrictions-from-pdf">
  Clear permission flags.
</Card>

<Card title="Add a text watermark" href="/docs/api/add-text-watermark-to-pdf">
  Watermark the document before encrypting.
</Card>

</CardGroup>
