Remove a PDF Password
Remove Password decrypts a password-protected PDF when you enter the password that opens it, and returns an unprotected copy. It does not guess, crack or recover forgotten passwords.
Drag and drop files here, or click to choose
Accepts PDF · up to 500.0 MB per file · up to 20 files at once
You can also paste a file with Ctrl/Cmd+V, or from the clipboard menu.
Unlock decrypts a passworded PDF with qpdf `--decrypt` when you supply the password that actually opens it. Use it on your own export, or on a file a client gave you with the password. It does not brute-force, recover, or guess lost secrets.
If the PDF does not declare encryption, the same bytes are returned under the same base name with a `.pdf` extension, after a check that the file parses as a PDF. The decision is made on whether the file declares encryption, not on whether your viewer happened to ask you for a password.
A wrong password fails closed with an error. There is no partial file. After a successful decrypt, Merge, OCR, and Convert see an ordinary PDF. The unlocked copy is easier to read if it leaks; store it accordingly.
The portal sends one `password` field. qpdf uses it as the decrypt secret. Owner-password permission flags and user-password open locks are different PDF modes; send the password that matches how the file was encrypted.
Unlock is not certificate signature removal. Use the Remove Certificate Signature page to strip signature fields from a PDF; Unlock only removes password encryption.
Only decrypt files you are allowed to open. The yellow notice on this page is the boundary. API clients should pass the password once per request and must not log it.
If policy forbids sending plaintext-after-decrypt through a hosted service, self-host. After unlock, Protect can put a new password on if the file still has to travel encrypted.
A realistic job: your accounting system exports a 14-page quarterly report with an open password, and you want to put a cover page in front of it. Upload the export, type the password you set, and download the result. It should have the same 14 pages and open without a prompt, so Merge can take it as an ordinary file. Note that the download keeps the uploaded file's name, so rename it before it lands next to the encrypted original.
What you see when it goes wrong is specific. A password that does not match comes back as a 400 response with the reason `wrong_password`. An empty password on a file that needs one comes back as `password_required`. Both mean nothing was produced; re-enter the password exactly, watching for keyboard layout and trailing spaces, and if you genuinely do not have it, ask whoever issued the file. A file that is not a readable PDF at all is rejected with an invalid-PDF error; Repair is the next step for a damaged but wanted file.
Choose by goal. To remove the password and keep everything else, use Unlock. To send only some pages of the unlocked file, run Extract Pages or Remove Pages afterwards. To clear metadata, run Sanitize. To lock the file again with a different password, run Protect.
Features
- qpdf `--decrypt` with the password you provide
- Unencrypted files are returned unchanged
- Does not crack or recover unknown passwords
- Anonymous API at /api/v1/security/remove-password
When to use this tool
- Open your own passworded export for editing
- Prepare an authorized shared file for Merge
- Decrypt a known-password file before OCR
- Remove the password from a client file once the client has confirmed it can be stored unencrypted
How do I remove the password from a PDF?
- Confirm you are authorized to remove encryption from this file, for example because you set the password or the sender gave it to you.
- Upload the PDF and type the password exactly as it was set; the field is required on the form.
- Click Process. A wrong password stops the run with `wrong_password` and produces no file, so retry with the correct one.
- Download the decrypted PDF, open it once to confirm it no longer asks for a password, and rename it so it does not overwrite the original.
- Store the unlocked copy carefully, or run Protect on it if it has to travel encrypted again.
Limits and edge cases
- Cannot crack passwords
- Wrong password fails closed
- Schemes that are not qpdf-decryptable are out of scope
- One file and one password per run
- A file that does not parse as a PDF is rejected with an invalid-PDF error
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.
Examples
- The correct user password yields an open PDF you can copy text from
- A wrong password returns an error instead of a partial file
- A 14-page encrypted report with the right password comes back as a 14-page file that Merge accepts
- An export that was never encrypted comes back with its pages untouched
Privacy for this tool
Files are uploaded over HTTPS, processed in memory or a short-lived temporary directory on our servers, and deleted when your result is ready. We do not keep copies for later browsing, training, or advertising profiles. See the Privacy Policy for retention details and AdSense cookie disclosures.
Frequently asked questions
- I forgot the password. Can you recover it?
- No. Unlock only works with the password you already know.
- Why did the file come back unchanged?
- If the bytes have no /Encrypt token, there is nothing to decrypt. The tool returns the original file.
- Is this the same as removing a digital signature?
- No. Signatures use certificates. Unlock only removes password encryption.
- Will metadata be wiped?
- No. Unlock decrypts. Use Sanitize or Update Metadata for other cleanup.
- What error do I get if the password is wrong?
- A 400 response with the reason `wrong_password`. If no password was sent for a file that needs one, the reason is `password_required`. Neither returns a file.
- Will the unlocked file keep its name?
- It keeps the uploaded file's base name with a `.pdf` extension, so rename it before saving next to the original.
- How do I add a password again afterwards?
- Run the unlocked file through Protect, which lets you set a new password.
- Can I unlock several files in one go?
- No. The page handles one PDF per run; repeat it for each file, entering that file's own password.
Last updated:
Call this from code
Every tool on this site is a plain REST endpoint - no account or API key needed for anonymous use. Built for AI agents and developers as much as for browsers.
curl -X POST "https://pdf123.xyz/api/v1/security/remove-password" \
-F "[email protected]" \
-F "password=your-password" \
-o output.pdfAlso available as an MCP tool for agent clients that speak Model Context Protocol (JSON-RPC 2.0 over POST /mcp). Full API reference
Use it from an AI agent
SkillClaude Code, Codex, Cursor and other AI agents can run Remove Password for you with this skill: /skills/pdf123-unlock.md
Files are used only for this processing job and deleted automatically afterward.