Protect sensitive PDF documents with a secure PDF API for enterprise workflows. Add password protection, disable printing, restrict copying, and apply access controls for secure document delivery, regulated workflows, and enterprise document handling.
Add passwords, disable printing, and restrict copying so only authorized users can access or interact with protected PDFs.
Use PDF permissions and password protection as part of a broader DWS platform with built-in security, privacy, and SOC 2 Type 2 controls for enterprise evaluations.
Select a package that suits your needs according to the number of credits you wish to spend. Each API tool and action has a specific credit cost.
This example protects a document with a password.
Try it out in three steps
document.pdf to your project folder.result.pdf to see the output.curl -X POST https://api.nutrient.io/build \ -H "Authorization: Bearer your_api_key_here" \ -o result.pdf \ --fail \ -F document=@document.pdf \ -F instructions='{ "parts": [ { "file": "document" } ], "output": { "type": "pdf", "owner_password": "owner-password", "user_password": "user-password", "user_permissions": [ "printing", "modification", "extract", "annotations_and_forms", "fill_forms", "extract_accessibility", "assemble", "print_high_quality" ] } }'curl -X POST https://api.nutrient.io/build ^ -H "Authorization: Bearer your_api_key_here" ^ -o result.pdf ^ --fail ^ -F document=@document.pdf ^ -F instructions="{\"parts\": [{\"file\": \"document\"}], \"output\": {\"type\": \"pdf\", \"owner_password\": \"owner-password\", \"user_password\": \"user-password\", \"user_permissions\": [\"printing\", \"modification\", \"extract\", \"annotations_and_forms\", \"fill_forms\", \"extract_accessibility\", \"assemble\", \"print_high_quality\"]}}"package com.example.pspdfkit;
import java.io.File;import java.io.IOException;import java.nio.file.FileSystems;import java.nio.file.Files;import java.nio.file.StandardCopyOption;
import org.json.JSONArray;import org.json.JSONObject;
import okhttp3.MediaType;import okhttp3.MultipartBody;import okhttp3.OkHttpClient;import okhttp3.Request;import okhttp3.RequestBody;import okhttp3.Response;
public final class PspdfkitApiExample { public static void main(final String[] args) throws IOException { final RequestBody body = new MultipartBody.Builder() .setType(MultipartBody.FORM) .addFormDataPart( "document", "document.pdf", RequestBody.create( MediaType.parse("application/pdf"), new File("document.pdf") ) ) .addFormDataPart( "instructions", new JSONObject() .put("parts", new JSONArray() .put(new JSONObject() .put("file", "document") ) ) .put("output", new JSONObject() .put("type", "pdf") .put("owner_password", "owner-password") .put("user_password", "user-password") .put("user_permissions", new JSONArray() .put("printing") .put("modification") .put("extract") .put("annotations_and_forms") .put("fill_forms") .put("extract_accessibility") .put("assemble") .put("print_high_quality") ) ).toString() ) .build();
final Request request = new Request.Builder() .url("https://api.nutrient.io/build") .method("POST", body) .addHeader("Authorization", "Bearer your_api_key_here") .build();
final OkHttpClient client = new OkHttpClient() .newBuilder() .build();
final Response response = client.newCall(request).execute();
if (response.isSuccessful()) { Files.copy( response.body().byteStream(), FileSystems.getDefault().getPath("result.pdf"), StandardCopyOption.REPLACE_EXISTING ); } else { // Handle the error throw new IOException(response.body().string()); } }}using System;using System.IO;using System.Net;using RestSharp;
namespace PspdfkitApiDemo{ class Program { static void Main(string[] args) { var client = new RestClient("https://api.nutrient.io/build");
var request = new RestRequest(Method.POST) .AddHeader("Authorization", "Bearer your_api_key_here") .AddFile("document", "document.pdf") .AddParameter("instructions", new JsonObject { ["parts"] = new JsonArray { new JsonObject { ["file"] = "document" } }, ["output"] = new JsonObject { ["type"] = "pdf", ["owner_password"] = "owner-password", ["user_password"] = "user-password", ["user_permissions"] = new JsonArray { "printing", "modification", "extract", "annotations_and_forms", "fill_forms", "extract_accessibility", "assemble", "print_high_quality" } } }.ToString());
request.AdvancedResponseWriter = (responseStream, response) => { if (response.StatusCode == HttpStatusCode.OK) { using (responseStream) { using var outputFileWriter = File.OpenWrite("result.pdf"); responseStream.CopyTo(outputFileWriter); } } else { var responseStreamReader = new StreamReader(responseStream); Console.Write(responseStreamReader.ReadToEnd()); } };
client.Execute(request); } }}// This code requires Node.js. Do not run this code directly in a web browser.
const axios = require('axios')const FormData = require('form-data')const fs = require('fs')
const formData = new FormData()formData.append('instructions', JSON.stringify({ parts: [ { file: "document" } ], output: { type: "pdf", owner_password: "owner-password", user_password: "user-password", user_permissions: [ "printing", "modification", "extract", "annotations_and_forms", "fill_forms", "extract_accessibility", "assemble", "print_high_quality" ] }}))formData.append('document', fs.createReadStream('document.pdf'))
;(async () => { try { const response = await axios.post('https://api.nutrient.io/build', formData, { headers: formData.getHeaders({ 'Authorization': 'Bearer your_api_key_here' }), responseType: "stream" })
response.data.pipe(fs.createWriteStream("result.pdf")) } catch (e) { const errorString = await streamToString(e.response.data) console.log(errorString) }})()
function streamToString(stream) { const chunks = [] return new Promise((resolve, reject) => { stream.on("data", (chunk) => chunks.push(Buffer.from(chunk))) stream.on("error", (err) => reject(err)) stream.on("end", () => resolve(Buffer.concat(chunks).toString("utf8"))) })}import requestsimport json
response = requests.request( 'POST', 'https://api.nutrient.io/build', headers = { 'Authorization': 'Bearer your_api_key_here' }, files = { 'document': open('document.pdf', 'rb') }, data = { 'instructions': json.dumps({ 'parts': [ { 'file': 'document' } ], 'output': { 'type': 'pdf', 'owner_password': 'owner-password', 'user_password': 'user-password', 'user_permissions': [ 'printing', 'modification', 'extract', 'annotations_and_forms', 'fill_forms', 'extract_accessibility', 'assemble', 'print_high_quality' ] } }) }, stream = True)
if response.ok: with open('result.pdf', 'wb') as fd: for chunk in response.iter_content(chunk_size=8096): fd.write(chunk)else: print(response.text) exit()<?php
$FileHandle = fopen('result.pdf', 'w+');
$curl = curl_init();
curl_setopt_array($curl, array( CURLOPT_URL => 'https://api.nutrient.io/build', CURLOPT_CUSTOMREQUEST => 'POST', CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => '', CURLOPT_POSTFIELDS => array( 'instructions' => '{ "parts": [ { "file": "document" } ], "output": { "type": "pdf", "owner_password": "owner-password", "user_password": "user-password", "user_permissions": [ "printing", "modification", "extract", "annotations_and_forms", "fill_forms", "extract_accessibility", "assemble", "print_high_quality" ] } }', 'document' => new CURLFILE('document.pdf') ), CURLOPT_HTTPHEADER => array( 'Authorization: Bearer your_api_key_here' ), CURLOPT_FILE => $FileHandle,));
$response = curl_exec($curl);
curl_close($curl);
fclose($FileHandle);POST https://api.nutrient.io/build HTTP/1.1Content-Type: multipart/form-data; boundary=--customboundaryAuthorization: Bearer your_api_key_here
--customboundaryContent-Disposition: form-data; name="instructions"Content-Type: application/json
{ "parts": [ { "file": "document" } ], "output": { "type": "pdf", "owner_password": "owner-password", "user_password": "user-password", "user_permissions": [ "printing", "modification", "extract", "annotations_and_forms", "fill_forms", "extract_accessibility", "assemble", "print_high_quality" ] }}--customboundaryContent-Disposition: form-data; name="document"; filename="document.pdf"Content-Type: application/pdf
(document data)--customboundary--Use the PDF security guide for passwords and permissions. Then continue to Processor pricing and DWS security documentation for broader enterprise evaluation.
Most common next steps
Use the following:
Get started:
Platform resources:
No input or resulting documents are stored on our infrastructure. All files are deleted as soon as a request finishes. Alternatively, check out our self-hosted product.
All communication between your application and Nutrient is done via HTTPS to ensure your data is encrypted when it’s sent to us.
All payments are handled by Paddle. Nutrient DWS Processor API never has direct access to any of your payment data.
The PDF security API adds password protection and permission controls to PDF documents over a REST endpoint. It’s one action in the Nutrient DWS Processor API, so you can combine it with conversion, OCR, redaction, and other document actions in a single request.
Send the document with an owner password, a user password, or both, and the API returns the protected PDF. The PDF security guide covers passwords and permissions with ready-to-use examples in JavaScript, Python, Java, PHP, and HTTP (curl).
You can disable printing, restrict copying and content extraction, and control modification so only authorized users can interact with protected documents. Permissions are applied per request, which makes them easy to automate for document delivery workflows.
Yes. The API runs on the Nutrient DWS platform, which is SOC 2 Type 2-audited. See the security documentation for the full compliance and document-handling review.
No. Input and output files are deleted as soon as a request finishes, and all communication uses HTTPS. Nothing is retained on Nutrient’s infrastructure after the protected PDF is returned.
Yes. If the workflow also needs certificate-based signing, use the digital signatures API alongside password protection and permissions in the same Processor pipeline.
Yes. Sign up to receive free processing credits and test password protection before choosing a plan. Per-credit rates are listed on the Processor API pricing page.
Create an account to get your DWS Processor API key and start making API calls.