Short answer
Open Protect & Clean in PDF Tools and add a copy of the PDF. Set a strong open password and add an owner password only if you need its supported restrictions.
Save the result under a new name, then check the password prompt and the document in a second PDF reader.
Open password and owner password
An open password is needed to view the file. An owner password can request restrictions on actions such as changing or copying the document. Reader support varies, and permission flags are not robust digital rights management. Use the open password when access control is the real need.
Before you start
- Keep the unprotected source in an authorized safe location.
- Choose a long unique password and store it in a trusted password manager.
- Decide how the recipient will receive the password through a separate channel.
- Use a new filename so the protected and unprotected files cannot be confused.
Protect the copy
Add the PDF
Open Protect & Clean and select the local copy you are allowed to protect.
Enter and confirm the password
Set the open password carefully. Add an owner password only when the intended reader and workflow use it.
Create separate output
Choose a clear name and destination, then run the protection task.
Test before sending
Close the file, reopen it in another reader and enter the new open password.
Verify access and content
- The file refuses to open without the new password.
- The stored password opens it in another reader.
- All expected pages, links and forms still work.
- The intended recipient can use the chosen password method.
Recovery and security limits
Osenpa PDF Tools can remove protection only when you know the current password. It does not recover an unknown password. PDF readers enforce owner-password permission flags differently, so test the protected file in the recipient's reader. Password protection also does not remove metadata or visible sensitive content. Use the separate cleanup and redaction workflows those jobs require.
Osenpa PDF Tools
Add or remove a known PDF password locally and inspect a separate output.