How to remove the password from a PDF you own with an API
POST an encrypted PDF and its password to /v1/pdf/unlock. It returns the decrypted PDF and says whether the user or owner password opened it.
Request
password is the user or owner password; use "" for a file restricted by an owner password only (it opens without a password but limits printing or copying). The PDF is a URL or pdf_base64.
base64 -w0 locked.pdf | jq -Rn --arg pw "$PDF_PASSWORD" '{pdf_base64: input, password: $pw}' \
| curl -s -X POST https://tanod.dev/v1/pdf/unlock \
-H 'X-Tanod-Free: 1' -H 'content-type: application/json' -d @-The file comes back as base64 in the JSON. To save it, pipe the response through jq and base64:
base64 -w0 locked.pdf | jq -Rn --arg pw "$PDF_PASSWORD" '{pdf_base64: input, password: $pw}' \
| curl -s -X POST https://tanod.dev/v1/pdf/unlock \
-H 'X-Tanod-Free: 1' -H 'content-type: application/json' -d @- \
| jq -r '.file.data_base64' | base64 -d > unlocked.pdfResponse
{
"operation": "unlock",
"input_bytes": 14183,
"input_pages": 1,
"opened_with": "user",
"file": {
"name": "unlocked.pdf",
"content_type": "application/pdf",
"bytes": 13257,
"pages": 1,
"data_base64": "JVBERi0xLjcKJb/3"
},
"output_bytes": 13257,
"active_content_removed": {},
"untrusted_content": true
}Limits and caveats
You need the password. This endpoint decrypts with a password you supply. It does not guess, crack or bypass one. Only unlock files you are entitled to open.
Errors. A wrong password is a 422 invalid_password, an unencrypted file a 422 not_encrypted and public-key encryption a 422 unsupported_encryption.
Passwords are never logged, stored or echoed. Keep yours in an environment variable, not on the command line.
Active content is stripped. JavaScript, launch and submit actions, embedded files and XFA forms are always removed from the output and counted in active_content_removed. Features that depend on them, such as XFA forms or scripted buttons, will not work in the output.
Price and free allowance
USD 0.005 per call, paid in USDC on Base with x402. 3 free calls per IP per UTC day with the header X-Tanod-Free: 1. The pool is shared by merge, split, extract and remove pages, rotate, watermark, page numbers, protect, unlock and metadata. MCP tool: pdf_unlock at https://tanod.dev/mcp, where the free tier is automatic.
Related guides: How to password-protect a PDF with an API, How to read, edit or strip PDF metadata with an API, How to extract text from a PDF URL. Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.