---
name: "pdf123-protect"
description: "Encrypt your PDF document with a password. Runs the PDF123 \"Add Password\" tool (pdf123.xyz) over its REST API with curl, no account needed. Use when the user wants this done to their file. Also known as: 添加密码, Añadir contraseña, पासवर्ड लगाएँ, إضافة كلمة مرور, Adicionar senha, Tambah kata sandi, Ajouter un mot de passe, Задать пароль, パスワード設定, Passwort setzen, 비밀번호 설정, Thêm mật khẩu, Parola ekle, 加入密碼, Aggiungi password, ใส่รหัสผ่าน, Dodaj hasło, Поставити пароль, Wachtwoord zetten, Tambah kata laluan, Lägg till lösenord, Προσθήκη κωδικού, Добавяне на парола, Afegeix contrasenya, Weka nenosiri."
compatibility: "Needs curl 7.76+ and outbound HTTPS to pdf123.xyz, or PDFX_API_BASE pointing at a self-hosted pdfx-server."
---

# Add Password (PDF123)

Encrypt your PDF document with a password.

Web version: https://pdf123.xyz/protect · All tools: https://pdf123.xyz/skills/pdf123.md

## When to use

- Ship a salary PDF with an out-of-band password
- Protect a draft contract before email review
- Add a password before uploading to a shared folder

## Run it

Replace the sample file names and values with the user's, then run:

```bash
API="${PDFX_API_BASE:-https://pdf123.xyz}"
curl -sS --fail-with-body -X POST "$API/api/v1/security/add-password" \
  -F "fileInput=@input.pdf" \
  -F "password=your-password" \
  --output-dir "pdf123-output/$(date +%Y%m%d-%H%M%S)" --create-dirs -OJ -w '%{filename_effective} %{content_type}\n'
```

## Inputs

Everything is `multipart/form-data`. The command above already sends each field with its default; keep them all and change only the values the user asked for, since some endpoints reject a missing optional field.

| Field | Type | Required | Default | Notes |
| --- | --- | --- | --- | --- |
| `fileInput` | file | yes | | .pdf (one file) |
| `password` | text | yes |  | Password |

## Result

curl saves the result in a new `pdf123-output/<timestamp>/` directory under the server's file name and prints its path and content type. Several output files come back as one ZIP. Tell the user where the file is.

## Limits

- Lost passwords are unrecoverable here
- Offline guessing is still possible; use a long unique secret
- Not a substitute for access-controlled sharing
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.

## Errors

- A non-zero curl exit means the request failed. The saved file then holds `application/problem+json`; read it and report its `detail` to the user instead of retrying blindly.
- `413`: the upload exceeds 100 MiB. `429`: wait for `Retry-After` seconds, then retry once.
- Send `X-API-KEY: $PDFX_API_KEY` only if the user has a PDF123 API key; anonymous calls work without it.

## Privacy

Files are uploaded to the API host, processed, and deleted once the response is sent. For confidential files, ask before uploading, or use a self-hosted server via `PDFX_API_BASE`.

## Authorized use only

Only add passwords to documents you control. Do not use protection features to interfere with others' lawful access to shared records you are not authorized to restrict.
