---
name: "pdf123-unlock"
description: "Remove password protection from your PDF document. Runs the PDF123 \"Remove Password\" tool (pdf123.xyz) over its REST API with curl, no account needed. Use when the user wants this done to their file. Also known as: 移除密码, Quitar contraseña, पासवर्ड हटाएँ, إزالة كلمة المرور, Remover senha, Hapus kata sandi, Retirer le mot de passe, Снять пароль, パスワード解除, Passwort entfernen, 비밀번호 해제, Gỡ mật khẩu, Parolayı kaldır, 移除密碼, Rimuovi password, ถอดรหัสผ่าน, Usuń hasło, Зняти пароль, Wachtwoord verwijderen, Buang kata laluan, Ta bort lösenord, Αφαίρεση κωδικού, Премахване на парола, Treu la contrasenya, Ondoa nenosiri."
compatibility: "Needs curl 7.76+ and outbound HTTPS to pdf123.xyz, or PDFX_API_BASE pointing at a self-hosted pdfx-server."
---

# Remove Password (PDF123)

Remove password protection from your PDF document.

Web version: https://pdf123.xyz/unlock · All tools: https://pdf123.xyz/skills/pdf123.md

## When to use

- Open your own passworded export for editing
- Prepare an authorized shared file for Merge
- Decrypt a known-password file before OCR

## Run it

Replace the sample file names and values with the user's, then run:

```bash
API="${PDFX_API_BASE:-https://pdf123.xyz}"
curl -sS --fail-with-body -X POST "$API/api/v1/security/remove-password" \
  -F "fileInput=@input.pdf" \
  -F "password=your-password" \
  --output-dir "pdf123-output/$(date +%Y%m%d-%H%M%S)" --create-dirs -OJ -w '%{filename_effective} %{content_type}\n'
```

## Inputs

Everything is `multipart/form-data`. The command above already sends each field with its default; keep them all and change only the values the user asked for, since some endpoints reject a missing optional field.

| Field | Type | Required | Default | Notes |
| --- | --- | --- | --- | --- |
| `fileInput` | file | yes | | .pdf (one file) |
| `password` | text | yes |  | Password |

## Result

curl saves the result in a new `pdf123-output/<timestamp>/` directory under the server's file name and prints its path and content type. Several output files come back as one ZIP. Tell the user where the file is.

## Limits

- Cannot crack passwords
- Wrong password fails closed
- Schemes that are not qpdf-decryptable are out of scope
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.

## Errors

- A non-zero curl exit means the request failed. The saved file then holds `application/problem+json`; read it and report its `detail` to the user instead of retrying blindly.
- `413`: the upload exceeds 100 MiB. `429`: wait for `Retry-After` seconds, then retry once.
- Send `X-API-KEY: $PDFX_API_KEY` only if the user has a PDF123 API key; anonymous calls work without it.

## Privacy

Files are uploaded to the API host, processed, and deleted once the response is sent. For confidential files, ask before uploading, or use a self-hosted server via `PDFX_API_BASE`.

## Authorized use only

Only unlock PDFs you own or are explicitly authorized to open. Entering a password you are not entitled to use, or attempting to bypass someone else's encryption, may be unlawful. This tool verifies the password you provide; it does not crack or guess passwords.
