Password-protect PDF API

Send a password with any PDFMint request and the document comes back encrypted with AES-256 — on every plan, the free one included. This page shows the exact request, what qpdf reports about the file that comes back, which permissions you can and cannot set, and the two things that surprise people.

How this page was checked. Every request and every qpdf output below was run on 26 September 2026 against a local build of the PDFMint code that serves pdf.mintapis.com (commit 83dddcb), with a free account. Timings on a laptop-class machine say nothing about the live service, so none are quoted.

The request #

Encryption is four optional fields on the ordinary POST /v1/pdf call. It works with every source — html, markdown, url or a saved template — and after a merge, so the whole joined document is covered.

curl -s -X POST https://pdf.mintapis.com/v1/pdf \
  -H "Authorization: Bearer $PDFMINT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
        "html": "<h1>Payslip, September 2026</h1><p>Net pay: €3,120.00</p>",
        "password": "8271-ada",
        "allowPrinting": true,
        "allowCopying": false,
        "filename": "payslip-2026-09.pdf"
      }' \
  -o payslip-2026-09.pdf -D - | grep -i x-pdfmint
FieldDefaultWhat it does
password—The user password, needed to open the file. Setting it is what turns encryption on.
ownerPasswordrandomThe owner password that governs permissions. Leave it out and a random secret is generated, so nobody can lift the restrictions — including you.
allowPrintingtrueFull-resolution printing, or none.
allowCopyingfalseWhether text and images may be extracted.

What comes back, checked with qpdf #

The response is the encrypted PDF itself. This is what qpdf reports about the file from the request above:

$ qpdf --show-encryption --password=8271-ada payslip-2026-09.pdf
R = 6
P = -20
User password = 8271-ada
Supplied password is user password
extract for accessibility: allowed
extract for any purpose: not allowed
print low resolution: allowed
print high resolution: allowed
modify document assembly: allowed
...
stream encryption method: AESv3
string encryption method: AESv3
file encryption method: AESv3

$ pdftotext payslip-2026-09.pdf -
Command Line Error: Incorrect password

R = 6 with AESv3 is the PDF 2.0 AES-256 security handler, which every current reader opens. Without the password the file cannot be read at all — not by a viewer, not by pdftotext. Under the hood the renderer hands the finished PDF to qpdf --encrypt … 256, the same tool you would reach for yourself.

Which permissions you control, and which you do not #

Two permissions are exposed, and they are the two that people actually ask for: printing (--print=full or none) and copying (--extract=y or n). Everything else stays at qpdf’s defaults, which is why the output above says modify document assembly: allowed. There is no field today to forbid editing, form filling or annotation, and we would rather say so than let the table imply it.

PDF permissions are honoured by well-behaved readers, not enforced by mathematics. The password is real encryption; the print/copy flags are a request to the reader. Anyone who can open the file with a tool that ignores the flags can print it. If a document must not leave a group of people, the user password is the control that matters.

Two things that surprise people #

  1. No page count on encrypted files. An encrypted PDF cannot be counted by the service, so X-PDFMint-Pages is omitted and pages is null in the JSON output modes. Duration, credits and size are still reported. If a downstream step branches on the page count, count before you encrypt, or keep a plain copy.
  2. Losing the owner password is permanent by design. When you do not send ownerPassword, the one that is generated is never stored or returned. That is the point — nobody can remove the restrictions — but it also means you cannot either. Send your own if you will ever need to.

Combine it with a watermark when the goal is that a leaked copy is traceable: the watermark is stamped on every page first, then the file is encrypted, so the stamp cannot be removed without the owner password.

fragment of the JSON body
"watermark": "CONFIDENTIAL · {{employee_id}}",
"password": "8271-ada",
"allowCopying": false

In n8n #

The PDFMint n8n node has a Password field under Options on the Generate PDF operation. It sets the user password; the permissions stay at the API defaults (printing allowed, copying not) and the owner password is random. If you need ownerPassword or different permissions in a workflow, an HTTP Request node pointed at /v1/pdf takes the full JSON body shown above.

Pick the password per document and send it through a different channel from the file. A birth date or a customer number is easy to guess and makes the encryption decorative.

What it costs elsewhere #

Password protection is on every PDFMint plan, from the free 10 documents a month up to Scale at $99 for 250,000. On 26 September 2026 CraftMyPDF’s pricing page listed PDF password protection only from its $99-a-month Professional plan — see the CraftMyPDF comparison, which quotes it with the date. If your documents are already built with another tool, qpdf --encrypt on your own machine is free and does exactly what our renderer does; you only need an API for it when the PDF is generated in the same call.

Try it #

A free account needs no card and includes this feature.

Get a free API key   Password reference