How to password-protect a PDF with an API
POST a PDF and a password to /v1/pdf/protect. It returns the PDF encrypted with AES-256, which needs the user password to open.
Request
user_password is needed to open the file. owner_password lifts the permissions (print, modify, copy_text, annotate, fill_forms, accessibility, assemble, print_high_quality; all allowed by default). Without an owner password a random one that nobody knows is used.
jq -n --arg pw "$PDF_PASSWORD" '{url: "https://www.w3.org/WAI/ER/tests/xhtml/testfiles/resources/pdf/dummy.pdf", user_password: $pw}' \
| curl -s -X POST https://tanod.dev/v1/pdf/protect \
-H 'X-Tanod-Free: 1' -H 'content-type: application/json' -d @-The file comes back as base64 in the JSON. To save it, pipe the response through jq and base64:
jq -n --arg pw "$PDF_PASSWORD" '{url: "https://www.w3.org/WAI/ER/tests/xhtml/testfiles/resources/pdf/dummy.pdf", user_password: $pw}' \
| curl -s -X POST https://tanod.dev/v1/pdf/protect \
-H 'X-Tanod-Free: 1' -H 'content-type: application/json' -d @- \
| jq -r '.file.data_base64' | base64 -d > protected.pdfResponse
{
"operation": "protect",
"input_bytes": 13264,
"input_pages": 1,
"encryption": "AES-256",
"permissions": {
"print": true,
"modify": true,
"copy_text": true,
"annotate": true,
"fill_forms": true,
"accessibility": true,
"assemble": true,
"print_high_quality": true
},
"owner_password_set": false,
"file": {
"name": "protected.pdf",
"content_type": "application/pdf",
"bytes": 14183,
"pages": 1,
"data_base64": "JVBERi0xLjcKJb/3"
},
"output_bytes": 14183,
"active_content_removed": {},
"untrusted_content": true
}Limits and caveats
Passwords. Tanod does not log, store or echo them, and the example reads yours from an environment variable so it never appears on a command line or in shell history. It still travels in the request body over HTTPS; use a password you can afford to share with the service for that call.
Permissions are advisory. Print and copy limits are honoured by well-behaved viewers; some tools ignore them. Strength comes from the user password, so make it long.
No recovery. If you lose the password, the file cannot be opened. The unlock endpoint needs the password too.
Active content is stripped. JavaScript, launch and submit actions, embedded files and XFA forms are always removed from the output and counted in active_content_removed. Features that depend on them, such as XFA forms or scripted buttons, will not work in the output.
Price and free allowance
USD 0.005 per call, paid in USDC on Base with x402. 3 free calls per IP per UTC day with the header X-Tanod-Free: 1. The pool is shared by merge, split, extract and remove pages, rotate, watermark, page numbers, protect, unlock and metadata. MCP tool: pdf_protect at https://tanod.dev/mcp, where the free tier is automatic.
Related guides: How to remove the password from a PDF you own with an API, How to add a text watermark to a PDF with an API, How to read, edit or strip PDF metadata with an API. Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.