The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →To make a generated PDF ask for a password before it opens, use the PDF encryption support in your Ruby PDF library and set a real user (open) password. With Prawn, call encrypt_document(user_password: ..., owner_password: ...) inside the document-generation block. With HexaPDF, encryption is exposed through HexaPDF::Document#encrypt; check the API documentation for the exact options supported by your installed version. Do not encrypt the finished PDF bytes with OpenSSL and expect that to create a standard password-protected PDF.
For a new PDF, this guide shows Prawn’s documented interface and explains its important security limitation. If you need modern AES options or need to manipulate existing PDFs, HexaPDF is the stronger fit in the documentation covered here. In either library, an opening password is different from an owner password and from restrictions on printing or copying.
How PDF passwords work
PDF password protection is implemented by the PDF format’s encryption machinery, not by adding an ordinary password field to a file. A PDF library must write the security information into the document structure. This is why encrypting the completed PDF as an arbitrary byte stream does not produce a normal PDF that readers can open by entering a password.
- User password: also called the open password. A reader must enter it to open the PDF. This is the password to give the intended recipient.
- Owner password: provides owner-level access and can permit changing or overriding document restrictions. It is not a substitute for an opening password.
- Permissions: flags can request limits on printing, copying, or modification. PDF reader applications may enforce these differently, and some do not enforce them. Treat them as compatibility or usability settings, not dependable confidentiality controls.
A document can be encrypted while having no user password. That does not block ordinary opening, so it does not meet the goal of requiring a password to view the PDF.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Transform audio playing via your speakers and headphones
- Improve sound quality by adjusting it with effects
- Take control over the sound playing through audio hardware
Choose Prawn or HexaPDF
Start with the library already used by your application, then account for the kind of PDFs you handle, the encryption options you require, Ruby compatibility, and licensing. The two libraries are not equivalent in the encryption strength their documentation describes.
| Consideration | Prawn | HexaPDF |
|---|---|---|
| Typical fit | Generating PDFs, particularly when the application already uses Prawn. | Creating and manipulating PDFs, including when existing PDFs must be handled. |
| Encryption documented in the cited material | Prawn 2.5.0 documents a 40-bit password-derived key. | The guide describes AES 128-bit as the default and broad-compatibility choice; it also discusses AES 256-bit. |
| Passwords and permissions | Supports user and owner passwords, plus permission options. | Standard security handler supports a user password, owner password, and permission settings. |
| Runtime and licensing | Check the Prawn documentation and the requirements of the version installed in your application. | The project repository states Ruby 3.0 or newer is required. It is distributed under AGPL and a commercial license; some proprietary distribution or network-access deployments may require a commercial license. |
Prawn’s 2.5.0 security API warns, “In short, you have no security at all against a moderately motivated person.” That warning is specifically about Prawn’s documented 40-bit encryption and PDF permissions; it is not a claim about every PDF encryption implementation. Do not select Prawn’s documented encryption for sensitive material without a separate security review and, if your threat model requires stronger protection, a different solution.
HexaPDF’s encryption guide says RC4 is old and insecure and should be avoided. It describes AES 128-bit as the current best choice for broad compatibility and HexaPDF’s default. The guide states that AES 256-bit was standardized with PDF 2.0, while earlier use was an Adobe extension. These are documented implementation options, not guarantees about how every reader or workflow behaves. Check the installed version’s API reference and test in the PDF readers your recipients use.
Generate an encrypted PDF with Prawn
Install Prawn in the project using its normal dependency-management workflow, then put encrypt_document inside the document block before writing the PDF. The following example uses the API shown in Prawn’s manual and writes a new PDF to disk:
Recommended Free Tools
Rank #2
- Create, edit and style DOCUMENTS, SPREADSHEETS & PRESENTATIONS – all the features that you need to get work done
- Included PDF functions to FILL & SIGN forms, ANNOTATE and password PROTECT your PDF documents
- Compatibility with the most popular file formats - OPEN, EDIT & CREATE new and existing documents
- Manage all your email accounts and efficiently schedule with the inlcuded MAIL & CALENDAR apps
- Lifetime License for 1 Windows PC or Laptop
require "prawn"
Prawn::Document.generate("confidential.pdf") do |pdf|
pdf.encrypt_document(
user_password: ENV.fetch("PDF_USER_PASSWORD"),
owner_password: ENV.fetch("PDF_OWNER_PASSWORD")
)
pdf.text "Confidential report"
pdf.move_down 12
pdf.text "Only share this file with its intended recipient."
end
Set PDF_USER_PASSWORD and PDF_OWNER_PASSWORD in the execution environment or your secrets manager before running the script. Do not put production passwords directly in source code or commit them to version control. The user password is what the recipient enters to open the document; the owner password serves a different administrative purpose.
Prawn’s API says that if the user password is omitted or empty, the document remains encrypted but can be read without a password. Therefore, verify that your application supplies a non-empty user password whenever the requirement is password-gated opening. Prawn permission options default to true in its 2.5.0 API reference; changing such options does not strengthen the opening password or turn permissions into a robust access boundary.
The code uses the interface shown by the Prawn manual, while the security caveat above is tied to the Prawn 2.5.0 security API. Confirm the method and behavior against the version in your bundle before shipping. The cited documentation does not establish that every Prawn version has identical behavior.
Use HexaPDF when AES or PDF manipulation matters
HexaPDF is a full PDF library for creating and manipulating PDFs, and its encryption entry point is HexaPDF::Document#encrypt. Its official guide and API reference cover the standard security handler, user and owner passwords, permissions, and encryption algorithms. Because option names and accepted values are version-specific, use the reference matching the HexaPDF version in your application rather than copying a guessed argument list.
Rank #3
- EXCLUSIVE AMAZON BUNDLE - Securely create, edit, and share PDFs with Adobe Acrobat Pro. Secure your pc and personal information against advanced threats, frauds, and scams with McAfee Total Protection. Introductory offer for new users
- ULTIMATE TOOL FOR CREATIVING – Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go
- REVISIONS - Edit text and images without jumping to another app.
- ELECTRONIC SIGNATURES - E-sign documents or request e-signatures on any device. Recipients don’t need to log in to esign.
- CONVERT PDFs - Convert your pdf files to editable Microsoft Word, Excel, or PowerPoint documents.
- Confirm the installed HexaPDF version and the Ruby runtime. The project repository states that Ruby 3.0 or newer is required.
- Open the HexaPDF encryption guide and the matching StandardSecurityHandler API reference.
- Configure an actual user/open password and choose a supported encryption option appropriate to recipient compatibility. The guide identifies AES 128-bit as the default and broad-compatibility choice; avoid RC4.
- If owner access or permissions are needed, configure them separately from the user password, following the installed version’s API.
- Test the saved document in the readers and environments your application supports, using both the intended password and an incorrect password.
HexaPDF’s repository describes distribution under AGPL and a commercial license. It documents a commercial-license requirement for some proprietary distribution or network-access deployments, including serving PDFs from a web application without providing the application source under AGPL. Review the project repository and current vendor terms for the way your application is deployed; do not assume that a license suitable for local development is automatically suitable for a proprietary web service.
Deliver passwords and verify the result
Encryption is only one part of a password-protected document workflow. The application must make the password available to the right recipient without exposing it alongside the file. Deliver the PDF and its password through appropriately separate channels for your use case, and avoid logging either value in request logs, job output, or error reports.
- Generate: provide a non-empty user password to the PDF library and save the resulting document.
- Open correctly: use a supported PDF reader to confirm that the intended password opens the file.
- Reject an incorrect password: confirm that a deliberately incorrect value does not open the document.
- Check downstream handling: test any preview, indexing, archival, email, or document-management systems that will process the PDF. Encrypted files may require those systems to receive credentials or may not be usable by them.
- Review restrictions separately: if printing, copying, or modification settings matter for workflow reasons, check the behavior in the actual readers in scope. Do not use those settings as a replacement for encryption or an opening password.
Troubleshooting common problems
The PDF opens without asking for a password
Check that the library received a non-empty user password, not just an owner password or permission settings. In Prawn, an omitted or empty user password can leave an encrypted document readable without a password. Regenerate the PDF after correcting the input.
The reader rejects the intended password
Confirm which password your application supplied as the user/open password, and check for environment-variable mistakes, whitespace, or mismatched values between generation and delivery. Recreate the file with a controlled test password and verify it in the target reader before investigating other causes.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- Simple shift planning via an easy drag & drop interface
- Add time-off, sick leave, break entries and holidays
- Email schedules directly to your employees
Recipients can still print or copy content
Restrictions are requests to the reader application, not reliable barriers. Prawn’s documentation explicitly cautions that readers are not technologically required to honor permissions and many do not. If your requirement is confidentiality, use an opening password and assess encryption strength against your threat model instead of relying on permission flags.
HexaPDF examples do not match the installed gem
Use documentation for the exact installed version. The encryption entry point is HexaPDF::Document#encrypt, but consult that version’s API reference for option names and accepted values rather than assuming examples from a different release apply.
A web deployment raises a licensing question
HexaPDF’s repository describes both AGPL and commercial licensing and notes deployments that may require commercial terms, including some proprietary web applications serving PDFs without providing application source under AGPL. Review the current license conditions for your distribution model before deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server, not a Ruby PDF-encryption library; use the Ruby methods above when the task is to password-protect a generated PDF. If you separately need to capture a web page as an image or PDF, one GET request can return the capture. See the ScreenshotNeo API documentation.
Best Value
- Mix an audio, music and voice tracks
- Record single or multiple tracks simultaneously
- Intuitive tools to split, trim, join, and many other editing features
- Loaded with audio effects including EQ, compression, reverb, and more.
- Load an audio file and export to all popular audio formats from studio quality wav to high compression formats
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
- Cookie/consent banners, newsletter popups, and chat widgets are removed before the shot; each step can be turned off.
- Bot checks, blank pages, and failed loads are not billed; response headers indicate the page verdict and billing status.
- An MCP server provides the
take_screenshot,get_page_info, andcapture_pdftools for AI agents. - The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.
Frequently Asked Questions
Can I encrypt an existing PDF with Prawn’s generation method?
Prawn’s documented example is for encrypting a document as it is generated. For workflows that need to manipulate existing PDFs, HexaPDF is the more relevant library to evaluate.
Does an owner password make the PDF ask for a password when opened?
No. The opening requirement is controlled by the user/open password. The owner password is a separate access level.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

