PDF Permissions
View and change PDF permissions for printing, copying, editing, form filling, and page assembly with AES-256 encryption — processed locally in your browser.
How to Use
View or change PDF permissions in four steps:
- Upload your PDF -- Drag and drop a PDF or click the dropzone to browse. The tool inspects the encryption dictionary locally and reports the current security state. Nothing is uploaded to a server.
- Review the current state -- The status card shows whether the document is encrypted, which algorithm and revision it uses (for example AES-256 at revision 6), and which of the seven permission flags are currently allowed or restricted. If the file requires a password to open, enter it to continue.
- Configure permissions and passwords -- Choose a printing level (full, low-resolution only, or none) and toggle the remaining flags: content changes, copy and extract, annotations, form filling, accessibility, and page assembly. Optionally set an open password (required to view the file) and an owner password (required to change permissions later). Leave the owner field blank to auto-generate one.
- Apply and download -- Click "Apply permissions" to rewrite the file with AES-256 encryption and your chosen flags, or "Remove restrictions" to strip encryption entirely and produce an unprotected copy. Download the result -- the original file on your device is never modified.
Everything runs in your browser using qpdf compiled to WebAssembly. Your document and your passwords never leave the device, which makes this tool safe for contracts, medical records, and other confidential files.
About This Tool
PDF permissions are usage rules stored in the document's encryption dictionary. The PDF 1.7 specification (ISO 32000) defines a 32-bit integer called the P value in which individual bits grant or deny specific actions: bit 3 controls printing, bit 4 modification, bit 5 text and image extraction, bit 6 annotations, bit 9 form filling, bit 10 accessibility extraction, bit 11 document assembly, and bit 12 high-resolution printing. A conforming PDF reader checks these bits before allowing the corresponding action. Because the flags live inside the /Encrypt dictionary, changing them always means re-encrypting the file -- there is no such thing as an unencrypted PDF with restrictions.
Two passwords govern this system, and confusing them is the most common source of frustration. The user password (also called the open or document password) is required to open the file at all -- without it, a conforming reader cannot even render page one. The owner password (also called the permissions or master password) does not gate viewing; it gates changing the security settings. A very common configuration is an empty user password plus a non-empty owner password: the document opens freely for anyone, but printing, copying, or editing are restricted, and only someone holding the owner password can alter those flags. When you leave the owner field blank here, the tool generates a strong random one so the restrictions you set remain enforceable -- it is displayed once so you can store it somewhere safe.
This tool always writes AES-256 encryption (revision 6), the strongest scheme in the standard. It is worth understanding what permission flags actually do: they are policy hints enforced by the reader, not cryptography on the content itself. Adobe Acrobat, Preview, Chrome, and every other mainstream reader honors them, which makes them effective for everyday distribution control -- preventing casual copying, accidental edits, or low-quality prints of artwork. But because the content remains readable, a determined recipient with the right software can disregard the flags. For genuinely sensitive material, an open password (which encrypts every stream so the file cannot be read without the secret) is the meaningful barrier. Permissions complement, rather than replace, password protection.
Each flag has practical nuance. Low-resolution printing permits output at roughly 150 dpi -- enough for proofing but not for reproduction. Content changes covers edits not governed by the more specific flags. Annotations controls comments, markup, and digital signing, while form filling is a separate bit so a form can stay fillable while other edits stay locked. Accessibility extraction exists so assistive technology like screen readers can keep working even when copying is otherwise denied -- disabling it is legal in most jurisdictions but hostile to users who rely on it, and most real-world documents leave it on. Page assembly governs inserting, rotating, deleting, and bookmarking pages -- the flag a viewer needs to reorganize a document.
Removing restrictions is the inverse operation: qpdf rewrites the file without an Encrypt dictionary, producing a clean copy with every flag implicitly allowed. This works on any file you can open, including the classic "opens fine but refuses to print" document that carries only an owner password. For files that demand a password before they will open, you must supply it first -- the tool decrypts with your password, it does not crack or bypass unknown credentials.
Why Use This Tool
Permission control sits at the center of several everyday document workflows:
- Distributing drafts and proofs -- Designers and agencies send proofs with printing limited to low resolution and copying disabled, so clients can review but not appropriate the work. The document still opens without friction.
- Protecting fillable forms -- HR teams distribute contracts and onboarding forms with form filling and signing allowed but content edits locked, so recipients can complete the document without altering its terms.
- Compliance and records control -- Legal and finance teams restrict modification and page assembly on filed documents, preserving page integrity for audits while leaving reading and printing unrestricted.
- Stripping forgotten owner passwords -- You own a PDF that opens but refuses to print or copy because an old workflow restricted it. Remove the restrictions outright and keep a clean copy.
- Pre-publish hardening -- Before posting a paper, dataset description, or resume publicly, authors block text extraction to slow down scraping while keeping the file readable for humans.
- Fixing over-restricted archives -- Scanned document archives sometimes carry pointless restrictions inherited from capture software. Unlocking them restores printing and copying for legitimate use.
Related tools: PDF Permissions Viewer inspects flags read-only without changing the file. PDF Remove Restrictions is a dedicated one-click unlocker. PDF Unlock removes open passwords you know. PDF Encrypt & Decrypt focuses on password protection itself. PDF Edit Metadata covers document properties like title and author.