---
name: "pdf123-sanitize"
description: "Remove JavaScript, embedded files, metadata and links from a PDF - you choose which. Runs the PDF123 \"Sanitize PDF\" tool (pdf123.xyz) over its REST API with curl, no account needed. Use when the user wants this done to their file. Also known as: 清理 PDF, Limpiar PDF, PDF साफ़ करें, تنظيف PDF, Limpar PDF, Bersihkan PDF, Nettoyer le PDF, Очистить PDF, PDFのクリーニング, PDF bereinigen, PDF 정리, Dọn PDF, PDF temizle, Pulisci PDF, ล้าง PDF, Oczyść PDF, Зачистити PDF, PDF opschonen, Rensa PDF, Καθαρισμός PDF, Почистване на PDF, Neteja el PDF, Safisha PDF."
compatibility: "Needs curl 7.76+ and outbound HTTPS to pdf123.xyz, or PDFX_API_BASE pointing at a self-hosted pdfx-server."
---

# Sanitize PDF (PDF123)

Remove JavaScript, embedded files, metadata and links from a PDF - you choose which.

Web version: https://pdf123.xyz/sanitize · All tools: https://pdf123.xyz/skills/pdf123.md

## When to use

- Clean a vendor PDF before forwarding internally
- Strip unexpected EmbeddedFiles before publishing
- Remove link annots from a file that should not stay clickable

## Run it

Replace the sample file names and values with the user's, then run:

```bash
API="${PDFX_API_BASE:-https://pdf123.xyz}"
curl -sS --fail-with-body -X POST "$API/api/v1/security/sanitize-pdf" \
  -F "fileInput=@input.pdf" \
  -F "removeJavaScript=true" \
  -F "removeEmbeddedFiles=true" \
  -F "removeXMPMetadata=true" \
  -F "removeMetadata=true" \
  -F "removeLinks=true" \
  -F "removeFonts=false" \
  --output-dir "pdf123-output/$(date +%Y%m%d-%H%M%S)" --create-dirs -OJ -w '%{filename_effective} %{content_type}\n'
```

## Inputs

Everything is `multipart/form-data`. The command above already sends each field with its default; keep them all and change only the values the user asked for, since some endpoints reject a missing optional field.

| Field | Type | Required | Default | Notes |
| --- | --- | --- | --- | --- |
| `fileInput` | file | yes | | .pdf (one file) |
| `removeJavaScript` | choice | no | `true` | Remove JavaScript. One of: `true` (Yes), `false` (No) |
| `removeEmbeddedFiles` | choice | no | `true` | Remove embedded files. One of: `true` (Yes), `false` (No) |
| `removeXMPMetadata` | choice | no | `true` | Remove XMP metadata. One of: `true` (Yes), `false` (No) |
| `removeMetadata` | choice | no | `true` | Remove metadata. One of: `true` (Yes), `false` (No) |
| `removeLinks` | choice | no | `true` | Remove links. One of: `true` (Yes), `false` (No) |
| `removeFonts` | choice | no | `false` | Remove embedded fonts. One of: `true` (Yes), `false` (No) |

## Result

curl saves the result in a new `pdf123-output/<timestamp>/` directory under the server's file name and prints its path and content type. Several output files come back as one ZIP. Tell the user where the file is.

## Limits

- Not a malware scanner
- May disable script-dependent features
- JavaScript in the named-scripts tree, form fields and annotations is not removed
- Visible secrets need redaction, not only sanitize
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.

## Errors

- A non-zero curl exit means the request failed. The saved file then holds `application/problem+json`; read it and report its `detail` to the user instead of retrying blindly.
- `413`: the upload exceeds 100 MiB. `429`: wait for `Retry-After` seconds, then retry once.
- Send `X-API-KEY: $PDFX_API_KEY` only if the user has a PDF123 API key; anonymous calls work without it.

## Privacy

Files are uploaded to the API host, processed, and deleted once the response is sent. For confidential files, ask before uploading, or use a self-hosted server via `PDFX_API_BASE`.

## Authorized use only

Sanitize only documents you are allowed to modify before sharing. Do not strip tracking or security features from files to conceal unauthorized changes or to evade monitoring you are required to preserve.
