Try it live: Remove Password from PDF → API Tester — send a real request from your browser.
POST /v1/pdf/security/remove
Attributes
Attributes are case-sensitive and should be inside JSON for POST request. for example:
{ "url": "https://example.com/file1.pdf" }| Attribute | Type | Required | Default | Description |
|---|---|---|---|---|
url | string | Yes | - | URL to the source file url attribute |
callback | string | No | - | The callback URL (or Webhook) used to receive the POST data. see Webhooks & Callbacks. This is only applicable when async is set to true. |
password | string | No | - | Password for the PDF file. |
async | boolean | No | false | Set async to true for long processes to run in the background, API will then return a jobId which you can use with the Background Job Check endpoint. Also see Webhooks & Callbacks |
name | string | No | - | File name for the generated output, the input must be in string format. |
expiration | integer | No | 60 | Set the expiration time for the output link in minutes. After this specified duration, any generated output file(s) will be automatically deleted from PDF.co Temporary Files Storage. The maximum duration for link expiration varies based on your current subscription plan. To store permanent input files (e.g. re-usable images, pdf templates, documents) consider using PDF.co Built-In Files Storage. |
profiles | object | No | - | See Profiles for more information. |
outputDataFormat | string | No | - | If you require your output as base64 format, set this to base64 |
DataEncryptionAlgorithm | string | No | - | Controls the encryption algorithm used for data encryption. See User-Controlled Encryption for more information. The available algorithms are: AES128, AES192, AES256. |
DataEncryptionKey | string | No | - | Controls the encryption key used for data encryption. See User-Controlled Encryption for more information. |
DataEncryptionIV | string | No | - | Controls the encryption IV used for data encryption. See User-Controlled Encryption for more information. |
DataDecryptionAlgorithm | string | No | - | Controls the decryption algorithm used for data decryption. See User-Controlled Encryption for more information. The available algorithms are: AES128, AES192, AES256. |
DataDecryptionKey | string | No | - | Controls the decryption key used for data decryption. See User-Controlled Encryption for more information. |
DataDecryptionIV | string | No | - | Controls the decryption IV used for data decryption. See User-Controlled Encryption for more information. |
Query parameters
No query parameters accepted.Responses
| Parameter | Type | Description |
|---|---|---|
url | string | Direct URL to the final PDF file stored in S3. |
outputLinkValidTill | string | Timestamp indicating when the output link will expire |
pageCount | integer | Number of pages in the PDF document. |
error | boolean | Indicates whether an error occurred (false means success) |
status | string | Status code of the request (200, 404, 500, etc.). For more information, see Response Codes. |
name | string | Name of the output file |
credits | integer | Number of credits consumed by the request |
remainingCredits | integer | Number of credits remaining in the account |
duration | integer | Time taken for the operation in milliseconds |
Example Payload
To see the request size limits, please refer to the Request Size Limits.
{
"url": "https://pdfco-test-files.s3.us-west-2.amazonaws.com/pdf-security/ProtectedPDFFile.pdf",
"password": "admin@123",
"name": "unprotected",
"async": false
}
Example Response
To see the main response codes, please refer to the Response Codes page.
{
"url": "https://pdf-temp-files.s3.amazonaws.com/9f2a754f76db46ac93781b3d2c6694c3/ProtectedPDFFile.pdf",
"pageCount": 1,
"error": false,
"status": 200,
"name": "ProtectedPDFFile.pdf",
"remainingCredits": 616187,
"credits": 21
}
Inconsistent URL Encoding in cURL Output: When using cURL to make API requests, the output JSON may show URL characters encoded as Unicode escape sequences. For example, the ampersand character (
&) may appear as \u0026 in the cURL output. This is normal JSON encoding behavior and does not affect the validity of the URL. The URL will function correctly when used, as JSON parsers automatically decode these escape sequences. If you’re parsing the response programmatically, your JSON parser will handle this conversion automatically.Code Samples
- CURL
- JavaScript/Node.js
- Python
- C#
- Java
- PHP
curl --location --request POST 'https://api.pdf.co/v1/pdf/security/remove' \
--header 'x-api-key: *******************' \
--header 'Content-Type: application/json' \
--data-raw '{
"url": "https://pdfco-test-files.s3.us-west-2.amazonaws.com/pdf-security/ProtectedPDFFile.pdf",
"password": "admin@123",
"name": "unprotected",
"async": false
}'
var https = require("https");
var path = require("path");
var fs = require("fs");
// The authentication key (API Key).
// Get your own by registering at https://app.pdf.co
const API_KEY = "***********************************";
// Direct URL of source password-protected PDF file.
const SourceFileUrl = "https://pdfco-test-files.s3.us-west-2.amazonaws.com/pdf-security/ProtectedPDFFile.pdf";
// Destination unprotected PDF file name
const DestinationFile = "./unprotected.pdf";
// Password for the PDF file
const Password = "admin@123";
// Runs processing asynchronously.
// Returns Use JobId that you may use with /job/check to check state of the processing (possible states: working, failed, aborted and success).
const async = false;
// Prepare request to `PDF Security Remove` API endpoint
var queryPath = `/v1/pdf/security/remove`;
// JSON payload for api request
var jsonPayload = JSON.stringify({
name: path.basename(DestinationFile),
url: SourceFileUrl,
password: Password,
async: async
});
var reqOptions = {
host: "api.pdf.co",
method: "POST",
path: queryPath,
headers: {
"x-api-key": API_KEY,
"Content-Type": "application/json",
"Content-Length": Buffer.byteLength(jsonPayload, 'utf8')
}
};
// Send request
var postRequest = https.request(reqOptions, (response) => {
response.on("data", (d) => {
// Parse JSON response
var data = JSON.parse(d);
if (data.error == false) {
// Download unprotected PDF file
var file = fs.createWriteStream(DestinationFile);
https.get(data.url, (response2) => {
response2.pipe(file)
.on("close", () => {
console.log(`Unprotected PDF file saved as "${DestinationFile}" file.`);
});
});
}
else {
// Service reported error
console.log(data.message);
}
});
}).on("error", (e) => {
// Request error
console.log(e);
});
// Write request data
postRequest.write(jsonPayload);
postRequest.end();
import os
import requests # pip install requests
# The authentication key (API Key).
# Get your own by registering at https://app.pdf.co
API_KEY = "********************************"
# Base URL for PDF.co Web API requests
BASE_URL = "https://api.pdf.co/v1"
# Direct URL of source password-protected PDF file.
SourceFileURL = "https://pdfco-test-files.s3.us-west-2.amazonaws.com/pdf-security/ProtectedPDFFile.pdf"
# Destination unprotected PDF file name
DestinationFile = ".\\unprotected.pdf"
# Password for the PDF file
Password = "admin@123"
# Runs processing asynchronously.
# Returns Use JobId that you may use with /job/check to check state of the processing (possible states: working, failed, aborted and success).
Async = False
def main(args = None):
removePdfPassword(SourceFileURL, DestinationFile)
def removePdfPassword(uploadedFileUrl, destinationFile):
"""Remove PDF password using PDF.co Web API"""
# Prepare requests params as JSON
# See documentation: https://developer.pdf.co
parameters = {"name": os.path.basename(destinationFile), "url": uploadedFileUrl, "password": Password,
"async": Async}
# Serializing json
import json
json_object = json.dumps(parameters, indent=4)
# Prepare URL for 'PDF Security Remove' API request
url = "{}/pdf/security/remove".format(BASE_URL)
# Execute request and get response as JSON
response = requests.post(url, data=json_object, headers={"x-api-key": API_KEY})
if (response.status_code == 200):
jsonResp = response.json()
if jsonResp["error"] == False:
# Get URL of result file
resultFileUrl = jsonResp["url"]
# Download result file
r = requests.get(resultFileUrl, stream=True)
if (r.status_code == 200):
with open(destinationFile, 'wb') as file:
for chunk in r:
file.write(chunk)
print(f"Result file saved as \"{destinationFile}\" file.")
else:
print(f"Request error: {response.status_code} {response.reason}")
else:
# Show service reported error
print(jsonResp["message"])
else:
print(f"Request error: {response.status_code} {response.reason}")
if __name__ == '__main__':
main()
using System;
using System.CodeDom;
using System.Collections.Generic;
using System.IO;
using System.Net;
using Newtonsoft.Json;
using Newtonsoft.Json.Linq;
namespace PDFcoApiExample
{
class Program
{
// The authentication key (API Key).
// Get your own by registering at https://app.pdf.co
const String API_KEY = "***********************************";
// Source password-protected PDF file
const string SourceFile = @".\ProtectedPDFFile.pdf";
// Destination unprotected PDF file name
const string DestinationFile = @".\unprotected.pdf";
// Password for the PDF file
const string Password = "admin@123";
static void Main(string[] args)
{
// Create standard .NET web client instance
WebClient webClient = new WebClient();
// Set API Key
webClient.Headers.Add("x-api-key", API_KEY);
// Upload file to the cloud
string uploadedFileUrl = UploadFile(SourceFile);
// REMOVE PASSWORD FROM UPLOADED PDF DOCUMENT
// Prepare requests params as JSON
// See documentation: https://developer.pdf.co/
Dictionary<string, string> parameters = new Dictionary<string, string>();
parameters.Add("name", Path.GetFileName(DestinationFile));
parameters.Add("url", uploadedFileUrl);
parameters.Add("password", Password);
// Convert dictionary of params to JSON
string jsonPayload = JsonConvert.SerializeObject(parameters);
try
{
// URL of "PDF Security Remove" endpoint
string url = "https://api.pdf.co/v1/pdf/security/remove";
// Execute POST request with JSON payload
string response = webClient.UploadString(url, jsonPayload);
// Parse JSON response
JObject json = JObject.Parse(response);
if (json["error"].ToObject<bool>() == false)
{
// Get URL of generated PDF file
string resultFileUrl = json["url"].ToString();
// Download generated PDF file
webClient.DownloadFile(resultFileUrl, DestinationFile);
Console.WriteLine("Unprotected PDF file saved as \"{0}\" file.", DestinationFile);
}
else
{
Console.WriteLine(json["message"].ToString());
}
}
catch (WebException e)
{
Console.WriteLine(e.ToString());
}
webClient.Dispose();
Console.WriteLine();
Console.WriteLine("Press any key...");
Console.ReadKey();
}
/// <summary>
/// Uploads file to the cloud and return URL of uploaded file to use in further API calls.
/// </summary>
/// <param name="file">Source file name (path).</param>
/// <returns>URL of uploaded file</returns>
static string UploadFile(string file)
{
// Create standard .NET web client instance
WebClient webClient = new WebClient();
// Set API Key
webClient.Headers.Add("x-api-key", API_KEY);
try
{
// 1. RETRIEVE THE PRESIGNED URL TO UPLOAD THE FILE.
// * If you already have a direct file URL, skip to the step 3.
// Prepare URL for `Get Presigned URL` API call
string query = Uri.EscapeUriString(string.Format(
"https://api.pdf.co/v1/file/upload/get-presigned-url?contenttype=application/octet-stream&name={0}",
Path.GetFileName(file)));
// Execute request
string response = webClient.DownloadString(query);
// Parse JSON response
JObject json = JObject.Parse(response);
if (json["error"].ToObject<bool>() == false)
{
// Get URL to use for the file upload
string uploadUrl = json["presignedUrl"].ToString();
// Get URL of uploaded file to use with later API calls
string uploadedFileUrl = json["url"].ToString();
// 2. UPLOAD THE FILE TO CLOUD.
webClient.Headers.Add("content-type", "application/octet-stream");
webClient.UploadFile(uploadUrl, "PUT", file); // You can use UploadData() instead if your file is in byte[] or Stream
return uploadedFileUrl;
}
else
{
// Display service reported error
Console.WriteLine(json["message"].ToString());
}
}
catch (Exception e)
{
Console.WriteLine(e);
throw;
}
finally
{
webClient.Dispose();
}
return null;
}
}
}
package com.company;
import com.google.gson.JsonObject;
import com.google.gson.JsonParser;
import okhttp3.*;
import java.io.*;
import java.net.*;
import java.nio.file.Path;
import java.nio.file.Paths;
public class Main
{
// The authentication key (API Key).
// Get your own by registering at https://app.pdf.co
final static String API_KEY = "***********************************";
// Direct URL of source password-protected PDF file.
final static String SourceFileUrl = "https://pdfco-test-files.s3.us-west-2.amazonaws.com/pdf-security/ProtectedPDFFile.pdf";
// Destination unprotected PDF file name
final static Path DestinationFile = Paths.get(".\\unprotected.pdf");
// Password for the PDF file
final static String Password = "admin@123";
// Runs processing asynchronously.
// Returns Use JobId that you may use with /job/check to check state of the processing (possible states: working, failed, aborted and success).
final static boolean async = false;
public static void main(String[] args) throws IOException
{
// Create HTTP client instance
OkHttpClient webClient = new OkHttpClient();
// Prepare URL for `PDF Security Remove` API call
String query = "https://api.pdf.co/v1/pdf/security/remove";
// Make correctly escaped (encoded) URL
URL url = null;
try
{
url = new URI(null, query, null).toURL();
}
catch (URISyntaxException e)
{
e.printStackTrace();
}
// Create JSON payload
String jsonPayload = String.format("{\n" +
" \"name\": \"%s\",\n" +
" \"url\": \"%s\",\n" +
" \"password\": \"%s\",\n" +
" \"async\": %s\n" +
"}",
DestinationFile.getFileName(), SourceFileUrl, Password, Boolean.toString(async)
);
// Prepare request body
RequestBody body = RequestBody.create(MediaType.parse("application/json"), jsonPayload);
// Prepare request
Request request = new Request.Builder()
.url(url)
.addHeader("x-api-key", API_KEY) // (!) Set API Key
.addHeader("Content-Type", "application/json")
.post(body)
.build();
// Execute request
Response response = webClient.newCall(request).execute();
if (response.code() == 200)
{
// Parse JSON response
JsonObject json = new JsonParser().parse(response.body().string()).getAsJsonObject();
boolean error = json.get("error").getAsBoolean();
if (!error)
{
// Get URL of generated PDF file
String resultFileUrl = json.get("url").getAsString();
// Download PDF file
downloadFile(webClient, resultFileUrl, DestinationFile.toFile());
System.out.printf("Unprotected PDF file saved as \"%s\" file.", DestinationFile.toString());
}
else
{
// Display service reported error
System.out.println(json.get("message").getAsString());
}
}
else
{
// Display request error
System.out.println(response.code() + " " + response.message());
}
}
public static void downloadFile(OkHttpClient webClient, String url, File destinationFile) throws IOException
{
// Prepare request
Request request = new Request.Builder()
.url(url)
.build();
// Execute request
Response response = webClient.newCall(request).execute();
byte[] fileBytes = response.body().bytes();
// Save downloaded bytes to file
OutputStream output = new FileOutputStream(destinationFile);
output.write(fileBytes);
output.flush();
output.close();
response.close();
}
}
<?php
// Note: For input files larger than 200 KB, we recommend using async mode by setting the "async" parameter to true.
// The authentication key (API Key).
// Get your own by registering at https://app.pdf.co
$API_KEY = "***********************************";
// Source password-protected PDF file
$SourceFile = "./ProtectedPDFFile.pdf";
// Password for the PDF file
$Password = "admin@123";
// Destination unprotected PDF file name
$DestinationFile = "./unprotected.pdf";
// 1. RETRIEVE THE PRESIGNED URL TO UPLOAD THE FILE.
// * If you already have the direct PDF file link, go to the step 3.
$presignedUrls = getPresignedUrl($API_KEY, $SourceFile);
if ($presignedUrls !== null) {
list($uploadUrl, $uploadedFileUrl) = $presignedUrls;
// 2. UPLOAD THE FILE TO CLOUD.
if (uploadFile($API_KEY, $SourceFile, $uploadUrl)) {
// 3. REMOVE PASSWORD FROM UPLOADED PDF
removePdfPassword($API_KEY, $uploadedFileUrl, $Password, $DestinationFile);
}
}
function getPresignedUrl($apiKey, $localFile)
{
// Prepare URL for `Get Presigned URL` API call
$url = "https://api.pdf.co/v1/file/upload/get-presigned-url"
. "?contenttype=application/octet-stream"
. "&name=" . urlencode(basename($localFile));
// Create request
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, $url);
curl_setopt($curl, CURLOPT_HTTPHEADER, array("x-api-key: " . $apiKey));
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
// Execute request
$result = curl_exec($curl);
$statusCode = curl_getinfo($curl, CURLINFO_HTTP_CODE);
$curlError = curl_error($curl);
curl_close($curl);
if ($result === false) {
// Display CURL error
echo "getPresignedUrl(): " . $curlError . PHP_EOL;
return null;
}
if ($statusCode != 200) {
// Display request error
echo "getPresignedUrl(): request error " . $statusCode . PHP_EOL . $result . PHP_EOL;
return null;
}
$json = json_decode($result, true);
if (!empty($json["error"])) {
// Display service reported error
echo "getPresignedUrl(): " . $json["message"] . PHP_EOL;
return null;
}
// Return the URL to use for the file upload, and the URL of the uploaded
// file to use with later API calls
return array($json["presignedUrl"], $json["url"]);
}
function uploadFile($apiKey, $localFile, $uploadUrl)
{
$fileHandle = fopen($localFile, "rb");
if ($fileHandle === false) {
echo "uploadFile(): unable to open " . $localFile . PHP_EOL;
return false;
}
// Create request. The presigned URL expects a raw PUT of the file bytes.
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, $uploadUrl);
curl_setopt($curl, CURLOPT_HTTPHEADER, array("x-api-key: " . $apiKey, "content-type: application/octet-stream"));
curl_setopt($curl, CURLOPT_PUT, true);
curl_setopt($curl, CURLOPT_INFILE, $fileHandle);
curl_setopt($curl, CURLOPT_INFILESIZE, filesize($localFile));
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
// Execute request
$result = curl_exec($curl);
$statusCode = curl_getinfo($curl, CURLINFO_HTTP_CODE);
$curlError = curl_error($curl);
curl_close($curl);
fclose($fileHandle);
if ($result === false) {
// Display CURL error
echo "uploadFile(): " . $curlError . PHP_EOL;
return false;
}
if ($statusCode != 200) {
// Display request error
echo "uploadFile(): request error " . $statusCode . PHP_EOL . $result . PHP_EOL;
return false;
}
return true;
}
function removePdfPassword($apiKey, $uploadedFileUrl, $password, $destinationFile)
{
// Prepare URL for `PDF Security Remove` API call
$url = "https://api.pdf.co/v1/pdf/security/remove";
// Prepare requests params
$parameters = array();
$parameters["url"] = $uploadedFileUrl;
$parameters["password"] = $password;
$parameters["name"] = basename($destinationFile);
// Create Json payload
$data = json_encode($parameters);
// Create request
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, $url);
curl_setopt($curl, CURLOPT_HTTPHEADER, array("x-api-key: " . $apiKey, "Content-Type: application/json"));
curl_setopt($curl, CURLOPT_POST, true);
curl_setopt($curl, CURLOPT_POSTFIELDS, $data);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
// Execute request
$result = curl_exec($curl);
$statusCode = curl_getinfo($curl, CURLINFO_HTTP_CODE);
$curlError = curl_error($curl);
curl_close($curl);
if ($result === false) {
// Display CURL error
echo "removePdfPassword(): " . $curlError . PHP_EOL;
return;
}
if ($statusCode != 200) {
// Display request error
echo "removePdfPassword(): request error " . $statusCode . PHP_EOL . $result . PHP_EOL;
return;
}
$json = json_decode($result, true);
if (!empty($json["error"])) {
// Display service reported error
echo "removePdfPassword(): " . $json["message"] . PHP_EOL;
return;
}
// Get URL of unprotected PDF file
$resultFileUrl = $json["url"];
// Download unprotected PDF file
if (downloadFile($resultFileUrl, $destinationFile)) {
echo "Unprotected PDF file saved as \"" . $destinationFile . "\" file." . PHP_EOL;
}
}
function downloadFile($url, $destinationFile)
{
// Create request
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, $url);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
curl_setopt($curl, CURLOPT_FOLLOWLOCATION, true);
// Execute request
$result = curl_exec($curl);
$statusCode = curl_getinfo($curl, CURLINFO_HTTP_CODE);
$curlError = curl_error($curl);
curl_close($curl);
if ($result === false) {
// Display CURL error
echo "downloadFile(): " . $curlError . PHP_EOL;
return false;
}
if ($statusCode != 200) {
// Display request error
echo "downloadFile(): request error " . $statusCode . PHP_EOL . $result . PHP_EOL;
return false;
}
// Write the file only after a successful response so failures leave no file behind
if (file_put_contents($destinationFile, $result) === false) {
echo "downloadFile(): unable to create " . $destinationFile . PHP_EOL;
return false;
}
return true;
}
?>