Recommended Free Tools
Use a user (open) password when the PDF must prompt for a password, and choose where encryption occurs: pass the password to ReportLab while creating the file, or encrypt the completed file with pypdf. For new ReportLab documents, encryption during generation is simplest. For PDFs produced by another library or already saved to disk, pypdf is the practical post-processing step.
Choose when to encrypt
| Approach | Best fit | Password and algorithm controls | What you need |
|---|---|---|---|
ReportLab canvas.Canvas(..., encrypt=...) |
You are creating the PDF with ReportLab now | A string sets the user password. StandardEncryption adds a separate owner password and permission flags. |
ReportLab; verify the installed version’s encryption behavior. |
| pypdf after generation | The PDF already exists or another library created it | Explicit algorithm selection, including AES choices and separate user/owner passwords. | pypdf; install the [crypto] extra for AES. |
There is no source-supported speed ranking between the two. Direct encryption avoids a second read/write pass, while pypdf lets you protect files created by virtually any PDF generator that produces a readable PDF.
Install the required packages
For pypdf with AES support, install the project’s crypto extra:
python -m pip install "pypdf[crypto]"
The installation syntax is documented in the official pypdf repository. The encryption API used below is documented for pypdf 6.3.0; check the documentation for the version pinned by your project before treating the code as version-independent.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- 【Strong Adsorption】The inspiration of the silicone phone suction case comes from the adhesive force of the octopus. Each suction cup phone mount is 3.15 inches long and 2.17 inches wide, with 24 independent suction cups providing a stronger and more stable suction force, so you don't have to worry about your phone falling during use.
- 【Back of Phone Suction Grip】Remove the adhesive film on the phone suction cup and stick it on the phone case. You can then fix the phone on any smooth surface, which is very convenient. (The phone suction cup cannot be removed and reused after being attached to the phone case. It is recommended to attach it to a regular phone case, not a valuable one.)
- 【Widely Used】Our non-slip silicone phone sticky grip mount attaches to almost any flat phone case and make it compatible with common mobile phones such as iPhone and Android.You can shoot, watch videos or video calls in the kitchen, gym, dance studio, bathroom and other places.
- 【Capture the Wonderful Picture】Whether you are a TikTok creator or just like to share videos and photos, this phone suction cup can help you hands-free capture wonderful videos and photos for sharing with friends.
- 【Note】You can fix the phone suction cup on a smooth surface such as a mirror or glass. If necessary, wipe the suction cup with a damp cloth to obtain stronger suction. Before releasing your hand, make sure the phone is firmly fixed. (Not applicable to rough walls, wooden surfaces, and other uneven surfaces)
ReportLab can be installed separately when you generate the PDF yourself:
python -m pip install reportlab
Encrypt an existing or completed PDF with pypdf
This is the most flexible method. It reads generated.pdf, applies an explicit AES algorithm, and writes protected.pdf.
import os
from pypdf import PdfReader, PdfWriter
password = os.environ["PDF_USER_PASSWORD"]
reader = PdfReader("generated.pdf")
writer = PdfWriter(clone_from=reader)
writer.encrypt(password, algorithm="AES-256")
writer.write("protected.pdf")
- Set the password in the runtime environment rather than in source control. For example, in a Unix-like shell:
export PDF_USER_PASSWORD='use-a-long-random-secret'. - Run the script in the directory containing
generated.pdf, or replace the paths with absolute or application-specific paths. - Distribute only
protected.pdf. Keep the original unencrypted file in a controlled location or remove it according to your retention policy.
The pypdf guide lists RC4-40, RC4-128, AES-128, AES-256-R5, and AES-256. Its documented recommendation is AES-256-R5, and it warns that omitting algorithm makes pypdf choose RC4 for compatibility; the same documentation calls RC4 insecure. Select an AES algorithm explicitly instead of relying on that default. AES operation requires the crypto extra shown above. See the pypdf 6.3.0 encryption and decryption guide for the supported names and API details.
Use a separate owner password
When you need distinct credentials for opening the document and changing its security settings, provide both passwords. The first positional argument is the user (open) password; the second is the owner password.
import os
from pypdf import PdfReader, PdfWriter
user_password = os.environ["PDF_USER_PASSWORD"]
owner_password = os.environ["PDF_OWNER_PASSWORD"]
reader = PdfReader("generated.pdf")
writer = PdfWriter(clone_from=reader)
writer.encrypt(
user_password,
owner_password=owner_password,
algorithm="AES-256-R5",
)
writer.write("protected.pdf")
Keep both values out of logs, exception messages, notebooks committed to a repository, and command histories. A secret manager, injected environment variable, or deployment configuration is preferable to a literal password in the script.
Rank #2
- SUPERIOR COMFORT — Unlike traditional circular ear buds, the design of EarPods is defined by the geometry of the ear. Which makes them more comfortable for more people than any other ear bud–style headphones.
- HIGH-QUALITY AUDIO — The speakers inside EarPods have been engineered to maximize sound output and minimize sound loss, which means you get high-quality audio.
- BUILT-IN REMOTE — EarPods with USB-C plug also include a built-in remote that lets you adjust the volume, control the playback of music and video, and answer or end calls with a pinch of the cord.
- COMPATIBILITY — Works with all devices that have a USB-C port.
- INTEGRATED MICROPHONE — A built-in microphone precisely captures your voice while you’re on the phone, taking a FaceTime call, or summoning Siri — so you’re always heard loud and clear.
Encrypt while generating with ReportLab
ReportLab accepts an encrypt argument on canvas.Canvas. Passing a string uses that value as the PDF user password.
import os
from reportlab.pdfgen import canvas
password = os.environ["PDF_USER_PASSWORD"]
pdf = canvas.Canvas("protected.pdf", encrypt=password)
pdf.drawString(72, 720, "Generated PDF")
pdf.showPage()
pdf.save()
save() finalizes the document and stores the encrypted output. The ReportLab graphics guide documents the Canvas constructor and its encrypt argument: ReportLab pdfgen guide.
Set an owner password and permissions
For printing, copying, modifying, and annotation controls, pass a StandardEncryption object instead of a string:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
import os
from reportlab.lib.pdfencrypt import StandardEncryption
from reportlab.pdfgen import canvas
user_password = os.environ["PDF_USER_PASSWORD"]
owner_password = os.environ["PDF_OWNER_PASSWORD"]
security = StandardEncryption(
userPassword=user_password,
ownerPassword=owner_password,
canPrint=0,
canModify=0,
canCopy=0,
canAnnotate=0,
)
pdf = canvas.Canvas("restricted.pdf", encrypt=security)
pdf.drawString(72, 720, "Restricted generated PDF")
pdf.showPage()
pdf.save()
ReportLab documents the StandardEncryption(userPassword, ownerPassword=..., canPrint=..., canModify=..., canCopy=..., canAnnotate=..., strength=...) interface. The cited guide shows a default strength of 40 for this API; it does not establish a modern AES mode for ReportLab’s constructor. Check the exact ReportLab version installed in your application before choosing or documenting a strength value. Details are in ReportLab’s PDF features and encryption guide.
User password, owner password, and permissions
User (open) password
This is the credential a viewer requests before displaying the document. If the requirement is “the recipient must enter a password to open the PDF,” set a user password.
Rank #3
- Secure Hold: Our PopSockets adhesive phone grip gives your cell phone a secure, comfortable hold in hand to help prevent drops while texting, taking photos, or scrolling on the go. Designed to stick firmly to most phone cases and devices.
- Hands-Free Made Easy: Easily turn your PopSocket into a phone stand to prop up your phone anywhere — perfect for watching videos, video calls, or following recipes. A must-have phone holder that keeps your device secure and ready for anything.
- Compatibility: Works with all phones, tablets, and Kindles. Sticks best to smooth, hard plastic cases and may not adhere to silicone or textured cases. Easily swap your PopTop to change up your style — just close the grip, press down, twist 90°, and snap on a new top.
- Black PopSockets: Simple, refined, and endlessly versatile — a timeless essential for any phone.
- PopSockets Ecosystem: Mix and match your favorite PopSockets products — from grips and wallets to cases and mounts — all designed to work together seamlessly.
Owner password
The owner password is associated with changing security settings and permission flags. ReportLab documents that supplying only an owner password does not require an opening prompt. Therefore, an owner password by itself is not a substitute for a user password when access must be gated.
Permission flags
Printing, copying, editing, and annotation flags tell a PDF viewer how to handle those actions after authentication. They are viewer-enforced permissions, not a replacement for encryption of the file’s contents. Test the resulting file in the viewers your recipients actually use, because behavior can vary by application.
Verify that the output is protected
Do not assume that a successful write means the intended password policy is present. Open the file manually in a PDF viewer and test both an incorrect and the correct password. You can also check decryption programmatically:
from pypdf import PdfReader
reader = PdfReader("protected.pdf")
if not reader.is_encrypted:
raise RuntimeError("The output is not encrypted")
result = reader.decrypt("the-password-used-by-your-test")
if not result:
raise RuntimeError("The test password was rejected")
print("Encrypted and decryptable with the test password")
Use a disposable test password in automated tests. Never print production secrets while diagnosing a failed decryption.
Operational and security guidance
- Generate a strong secret. Prefer a randomly generated value stored in a secret manager or deployment environment. Human-memorable passwords are easier to guess.
- Protect the plaintext source. Encryption added after generation cannot protect an unencrypted copy left in a temporary directory, backup, upload queue, or log.
- Use explicit algorithms. In pypdf, omitting
algorithminvokes the documented RC4 compatibility default. Choose AES explicitly and installpypdf[crypto]. - Plan password delivery separately. Sending the PDF and its password through the same channel reduces the benefit of access control.
- Test representative PDFs. Include fonts, images, attachments, forms, metadata, and unusually large files in your own compatibility tests. The supplied sources do not provide a universal viewer matrix or performance benchmark.
- Choose the insertion point deliberately. ReportLab encryption protects the file as it is finalized. pypdf is useful when a later pipeline stage creates, merges, or otherwise transforms the PDF, but that stage must write a new encrypted output and preserve the original securely.
Troubleshooting
“AES” causes an import or dependency error
Install the extra, not only the base package: python -m pip install "pypdf[crypto]". In a locked deployment, rebuild the environment so the cryptographic dependency is present in the same interpreter that runs the script.
Rank #4
- [360 ° Flexible Rotation Design] Comes with a rotatable lanyard ring that supports 360 ° free rotation, effectively solving the problem of twisted and tangled lanyards
- [Wide compatibility] The ultra-thin 0.02-inch design does not block the charging port at all, and both wired and wireless charging can be used directly without removing the pad. Compatible with most smartphones such as iPhone, compatible with various wristbands, lanyards, crossbody straps, and keychains
- [Durable and Portable Material] Premium rust-resistant stainless steel material with good flexibility, which not only avoids scratching the phone case, but also has excellent anti rust and anti fading performance
- [Multi scenario Practical] Paired with a lanyard or wristband, hands-free use can be achieved. The phone is within reach and not easily dropped, ideal for daily commuting and outdoor activities. Suitable for full coverage phone cases, does not support half coverage phone cases
- [Quality Service] If you find any damage or other issues with the product upon receipt, please contact us immediately. We will handle it quickly
The file opens without asking for a password
Confirm that you supplied a user password, not only an owner password. With ReportLab, passing a string to encrypt sets the user password; a StandardEncryption object must receive a non-empty userPassword when an opening prompt is required. Also verify that you are opening the newly written path rather than an older unencrypted copy.
Free tools Windows power users keep installed
One-click scans. No signup required.
pypdf reports that the input cannot be read
Check that the input is a complete PDF and that the process has read permission. If the file was truncated during an earlier download or upload, regenerate or transfer it again before attempting encryption. pypdf can only post-process a syntactically readable PDF.
The password works in one viewer but permissions differ in another
Permission flags are interpreted by the viewer. Reproduce the policy in the applications used by your audience and treat the user password as the access control that matters for confidentiality.
The generated file is still exposed
Search the job directory, temporary storage, artifact cache, and backups for the unencrypted source. Encrypt before handing the file to downstream systems, restrict file permissions, and delete temporary plaintext copies according to your retention requirements.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
If your workflow also needs a screenshot or PDF capture of a web page, ScreenshotNeo provides a one-request API. It is a website capture service, not a replacement for encrypting a local PDF with pypdf or ReportLab. Before capture it accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo documentation for request options. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Best Value
- 【PKYAA Double Sided Silicone Suction Phone Case Mount】PKYAA With Double Sided 40 Strong and Reliable individual suction cups, PKYAA provides a thicken and upgraded universal silicon suction mount for your phone.
- 【Friendly to Content Creators】If you are a content creator or an online influencer, you can create videos anywhere with this suction mount completely hands free with this silicone cell phone mount for cases.
- 【HANDS-FREE & Adhere to Mirrors】This Double Sided silicone suction phone case mount allows you to stick your phone to the mirror easily. No longer holding your phone in one hand to watch video tutorials while making up.
- 【Strong Grip on the Smooth Surface】You can easily hang your phone anywhere with a smooth surface. All you do is you clean off your phone and smooth surface. It is STURDY and it not only sticks to mirrors, it also sticks to windows, it sticks to refrigerators, tiles and other clean, flat surfaces.
- 【Press Down Firmly Every 30 Minutes】Use your palm or fingers to press the phone down firmly and check it's secure before letting go. Apply even pressure for a few seconds to allow the suction cup to adhere properly. To maintain the grip and prevent accidental falls, it's a good practice to periodically reapply pressure to the suction cup.
FAQ
How can I change the password on a protected PDF?
Use a workflow that can open the file with its current password, then write a new encrypted copy with the replacement credentials. Keep the old password available only for that controlled rotation step and securely remove intermediate plaintext files.
Does encrypting a PDF also encrypt its filename?
No. PDF encryption protects document content and security settings; the filename, directory metadata, and any surrounding transport or storage metadata remain visible unless you protect the containing system as well.
Should an application store the PDF password in its database?
A database column is not automatically a secret store. Restrict access, avoid logging the value, and prefer a dedicated secret-management facility or runtime-injected secret with an explicit rotation policy.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesFrequently Asked Questions
How can I change the password on a protected PDF?
Open it with the current password in a controlled process, then write a new encrypted copy with replacement credentials. Remove intermediate plaintext files securely.
Does encrypting a PDF also encrypt its filename?
No. PDF encryption protects document content and security settings, not filenames or surrounding storage metadata.
Should an application store the PDF password in its database?
Prefer a dedicated secret-management facility or runtime-injected secret, with restricted access, no logging, and a rotation policy.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

