Guides / How-to
How to password protect a PDF for free in your browser
Updated 2026-08-14 · pdfmend team
Some PDFs should not open for just anyone: a contract with salary figures, a scan of an ID, financial statements headed for an email thread you do not fully control. Password-protecting the file is the standard answer — the PDF format has built-in encryption, and any mainstream PDF reader can open a protected file once the password is entered.
Here is the part that should give you pause: most free "protect a PDF" websites ask you to upload the document and type the password on their site. You hand a third party the sensitive file and the key to it in the same breath. The pdfmend editor does neither — the document is encrypted in your browser, and the password you type never leaves it.
What you need
- The PDF on your device (up to 100 MiB and 250 pages during the free launch).
- A strong password you can store safely — more on choosing one below.
- Any modern desktop or mobile browser. No account, no install, and no watermark on the export.
Password protect a PDF step by step
- Open the editor and choose your PDF. Your browser reads the file locally — nothing is sent to a server.
- Make any edits first — fill fields, sign, remove pages — because protection is applied to the exported copy as it stands.
- Open More export options and choose Protect.
- Enter the password you want the file to require. It is used for encryption right there in your browser and is never transmitted anywhere.
- Export. The protected copy is saved to your device; anyone opening it will be prompted for the password in their PDF reader.
- Share the password through a different channel than the file — if both travel in the same email, the protection is theater.
Your original file on disk is untouched. The protected file is a new copy, so you keep an unprotected original for your own records — store it somewhere appropriate for its contents.
The protection is only as strong as the password
Protect applies standard PDF encryption to the exported file. That is the honest headline, and it cuts both ways: standard encryption is solid, but the password is the whole game. A short or guessable password can be attacked by simple trial and error, and no encryption scheme can save a password like the company name plus the year. A few practical rules:
- Length beats cleverness. A passphrase of several unrelated words is both strong and typeable — the recipient has to enter this, possibly on a phone.
- Do not reuse a password the recipient or anyone else already knows from another context.
- Never send the password alongside the file. Use a separate channel: a message app, a phone call, in person.
- Decide how you will remember it. A protected PDF with a forgotten password is effectively lost — pdfmend cannot recover or remove a password for you, precisely because it never had it.
Protection is not redaction
One distinction matters enough to get its own section: a password controls who can open the file. It does nothing about what is inside. The moment someone legitimate opens the PDF, everything in it is visible — and they can save, copy, or forward an unprotected version.
So if the real goal is that a recipient must never see a particular name, number, or paragraph, a password is the wrong tool. That content has to be removed, not locked. See the redaction guide for how pdfmend's Delete text (exp.) tool handles true content removal and, just as importantly, where it fails safely. Use Protect for transport and storage; use redaction for content you are cutting out; use both when both apply.
Why protecting locally matters
Encryption is meant to shrink the set of people who can read a document. Uploading the file and its password to a web service does the opposite first: it briefly expands that set to include a server you do not control. Whatever the service's intentions, you cannot audit its retention, its logs, or its breaches.
Local protection has no such gap. The document is encrypted on your device with a password that exists only in your browser and your head. There is no upload operation and no server-side copy — the privacy page details exactly what pdfmend does and does not process.
Try it now — the editor runs entirely in your browser. No upload, no account, no watermark.
Open the free editorFAQ
Will the protected PDF open in other PDF readers?
Yes. Protect uses standard PDF encryption, so mainstream readers on desktop and mobile will prompt for the password and open the file normally once it is entered.
Is my password sent to pdfmend's servers?
No. The password is used for encryption inside your browser and is never transmitted. That also means pdfmend cannot recover it — if you lose the password, the protected copy cannot be unlocked.
Can I remove a password I added earlier?
Keep your unprotected original — since protection is applied to the exported copy, the original on your disk never had a password. Exporting a fresh copy from it is the practical way to get an unprotected version.
Does a password hide sensitive text inside the PDF?
No. A password only controls opening the file; anyone who has the password sees everything. To make content permanently unreadable, it must be removed with redaction, which is a different operation with its own limits.