Unlock PDF
Remove password protection from one PDF when you know the required password. Owner-restricted PDFs require owner authorization before those restrictions can be removed.
Upload a PDF to unlock
Remove password protection when you know the current password. Files become eligible for scheduled cleanup after 60 minutes.
Drag and drop a file here, or click to browse.
Remove PDF encryption only after the supplied password is authorized
Unlock PDF processes one uploaded PDF at a time. It verifies the supplied password, rewrites the file without encryption, reopens the generated output, and checks that the output no longer requires a password or reports permission restrictions before the job is returned as successful.
The authorization rule matters: a valid user/open password can unlock an encrypted PDF only when no restrictive owner permissions are present. If the PDF carries owner restrictions, the owner password is required before those restrictions are removed.
Upload one PDF
Choose one password-protected PDF. The site upload endpoint enforces a 100 MB per-file limit.
Enter the known password
The current API accepts a non-empty password up to 256 characters. It does not attempt password recovery.
Verify authorization
The worker distinguishes ordinary open-password access from owner-restricted PDFs and requires owner authorization when needed.
Verify and download
A successful output is reopened and checked for removed encryption, unrestricted permissions, and unchanged page count before download.
Tested through the live upload, queue, worker, status, and download path
Reviewed by PDF Toolbox. Tested September 29, 2026 (UTC) against the live production APIs and BullMQ worker using PyMuPDF 1.26.7. The published synthetic source contains two pages, a 90-degree rotation control, document metadata, and an embedded attachment.
Production job 720 completed using the valid user/open password and reported authorization as user-unrestricted. Job 721 rejected a wrong password on a permissions-only PDF. Job 722 rejected a restricted PDF when only its user password was provided. Job 723 completed after the owner password was supplied.

The live production source contained two pages, a 90-degree rotation control, document metadata, and an embedded attachment. This image is rendered after authenticating the synthetic source.

Production job 720 created this unlocked copy through the public upload, API, BullMQ worker, and download path. The downloaded file reopened without a password.

The second page remained rotated 90 degrees in the downloaded production output. This is a controlled observation, not a guarantee for every PDF structure.
The published encrypted source is synthetic. Its user/open test password is user-open-2026. Do not reuse that password for your own documents.
Production test results
These results describe the published synthetic control and the production jobs listed below. They document observed behavior rather than promising identical results for every PDF structure, viewer, or encryption configuration.
| Check | Observed result | Status |
|---|---|---|
| Public page | /unlock-pdf returned HTTP 200 after the Fix 6 production restart. | Passed |
| API path validation | Invalid session and stored-file identifiers were rejected with HTTP 400. | Passed |
| Open-password success | Job 720 completed through public upload, Unlock PDF API, BullMQ worker, status API, and public download. Authorization was user-unrestricted. | Passed |
| Output verification | The downloaded job 720 output reopened without a password, reported no encryption, had unrestricted permission bits, and retained the two-page count. | Passed |
| Rotation / selected structures | The live output retained rotations of 0 and 90 degrees, selected metadata, and the embedded attachment from the synthetic source. | Observed in test |
| Permissions-only wrong password | Job 721 failed as required; an arbitrary wrong password could not remove the owner restrictions. | Passed |
| Restricted PDF + user password | Job 722 failed and required the owner password before owner restrictions could be removed. | Passed |
| Restricted PDF + owner password | Job 723 completed and the downloaded output verified as unencrypted and unrestricted. | Passed |
| Persisted BullMQ data | After worker claim, all four tested jobs showed passwordRedacted=true with no plaintext password field in persisted job data. | Observed in test |
| Password transport to Python | The worker passes the password to the Python process through standard input instead of a command-line argument. | Verified in source + live path |
| Runtime stability | Web, worker, and janitor restart counts remained unchanged during live acceptance; Redis continued returning PONG. | Passed |
Password handling and file retention
Unlock PDF is not a zero-knowledge service. The password must be sent to the server so the task can authenticate the source PDF. In the September 29 production acceptance test, the worker removed the plaintext password from persisted BullMQ job data after claiming each tested job and passed the in-memory password to Python through standard input.
Uploaded PDFs and generated outputs become eligible for scheduled deletion after 60 minutes. Cleanup runs every five minutes, so removal may occur shortly after that threshold rather than at an exact minute.
Verify the unlocked copy before relying on it
- 1. Keep the original encrypted PDF until you have opened and reviewed the unlocked copy.
- 2. Check page count, rotations, forms, links, annotations, attachments, metadata, accessibility, and other structures that matter to your workflow.
- 3. Do not use Unlock PDF on a signed document when preservation of the digital signature matters; the current worker refuses signature indicators instead of rewriting them.
- 4. Only remove password protection from files you are authorized to access and modify.
Related PDF workflows
Need to add an open password instead? Use Protect PDF, which has its own published production evidence.
If you need to review document properties before sharing a PDF, use Remove Metadata. That tool should not be treated as a guarantee that every form of hidden or sensitive content has been removed.
FAQ
What does this Unlock PDF tool do?
It takes one uploaded password-protected PDF and, after the required password is verified, creates a separate unlocked copy for download. The current upload endpoint accepts files up to 100 MB.
Can this tool unlock a PDF if I forgot the password?
No. The current workflow requires a valid password and does not perform password guessing or brute-force recovery. If the supplied password is not authorized for the requested unlock, the job is rejected.
What is the difference between an open password and an owner password here?
A user/open password controls opening an encrypted PDF. An owner password can also authorize removal of permission restrictions such as printing, copying, or editing limits. The tested workflow accepts a user/open password only when the PDF has no restrictive owner permissions. If owner restrictions are present, the owner password is required before the tool will create an unrestricted output.
What did the live production test verify?
On September 29, 2026, production job 720 accepted the valid user/open password for an unrestricted encrypted PDF and produced an unlocked copy. Job 721 rejected a wrong password on a permissions-only PDF. Job 722 rejected a restricted PDF when only its user password was supplied, and job 723 succeeded when the owner password was supplied.
Does the unlocked file always remain identical to the source?
No universal preservation guarantee is made. In the published live synthetic control, the two-page count, a 90-degree page rotation, selected metadata, and an embedded attachment were preserved. The regression suite also covers additional controlled structures, but you should still inspect the downloaded PDF before relying on it.
What happens with signed or already-unlocked PDFs?
The current worker refuses PDFs containing a digital signature indicator because rewriting a signed PDF can invalidate its signature. It also refuses files that are already unencrypted instead of creating a redundant copy.
What happens to the password on the server?
Unlock PDF is not a zero-knowledge service. The password must reach the server so the unlock task can run. In the September 29 production test, after the worker claimed each tested job, persisted BullMQ job data showed passwordRedacted=true with no plaintext password field, and the Python process received the password through standard input rather than a command-line argument.
When are uploaded and generated files deleted?
Uploads and generated outputs become eligible for scheduled deletion after 60 minutes. Cleanup runs on a five-minute interval, so deletion is not guaranteed at the exact 60-minute mark.
Can I unlock several PDFs at once?
No. The current Unlock PDF interface processes one PDF per job. Upload and unlock additional PDFs separately.