You set a password on the PDF in Acrobat or Preview, and now you have a second problem: how to get the password to them. Text it? Put it in the same email as the file, which defeats the point? And if they open it on a phone, in a browser, or in a mail client's preview pane, they may not get a password prompt at all — just an error. Putting the lock on the link instead solves the delivery problem and the phone problem at once: they click, type one passphrase in the browser, and read. No PDF app, no account, nothing installed. The file itself stays exactly as you made it.
Try it now
Drop a file — get a private link in seconds. No sign-up.
Drop an HTML, ZIP, PDF, PNG or JPEG file, or click to choose.
One file, or a ZIP bundle. Max 3 MB.
Up to 3 MB, link self-destructs after 7 days. Sign up free to keep links forever, password-protect them, and store more.
First, know which of the two PDF passwords you set, because they behave completely differently. An open password (sometimes called a user or document-open password) means the file cannot be read at all without it — every reader, every app, every time. A permissions password (owner password) leaves the file readable and only restricts printing, copying or editing. Both are 'password-protected' in everyday speech, and Acrobat sets them in the same dialog, which is why people are surprised by what happens next.
An open-password PDF does not survive being shared as a link, anywhere. A browser-based viewer renders the pages; it has nowhere to ask your reader for the PDF's own password. So the link opens and shows one line of error instead of your document — and you find out from them, after you sent it. We measured this on our own viewer and then made it refuse the upload rather than hand you a link that is broken for every reader: drop an open-password PDF here and you get told at the upload step, not after. A permissions-password PDF is fine and uploads normally, because it still opens.
So the working shape is: upload the PDF as it is, and put the password on the link. The passphrase is checked before anything loads, so the document is never sent to a browser that has not answered it. Your reader types it once, in the browser, on any device — no Acrobat, no account, no app. The PDF's own bytes are stored unchanged; we do not re-save it, strip anything, or convert it.
Two things you get that a locked file cannot do. You can change your mind: rotate the passphrase, set an expiry so access ends after the review window, or delete the link and it stops opening immediately — none of which is possible once a locked PDF is sitting in somebody's inbox. And you can see whether it was opened at all, rather than guessing. Passwords and expiry are free on any account; the anonymous upload at /try has neither, because there is no account for those settings to belong to.
When you should still lock the file itself: if the PDF has to live inside their systems after the meeting — filed, archived, forwarded into a document store, or signed — then the protection has to travel with the bytes, and that is Acrobat's job, not ours. A link password protects the delivery; a file password protects the file wherever it ends up. Those are different jobs and it is reasonable to want both.
It depends which password. If it needs a password just to open, no — we stop it at the upload step and tell you why. That is deliberate: a browser viewer has no way to ask your reader for the PDF's own password, so the link would load and show an error instead of your document, and you would only hear about it from the person you sent it to. If the password only restricts printing or copying, the file still opens, so it uploads and renders normally.
Put the password on the link rather than inside the file. They click the link, type one passphrase in their browser, and the document is there — no Acrobat, no plugin, no account, and it works the same on a phone as on a laptop. A locked file asks them to have the right software and to handle a password inside an app they may not use, which is where these hand-offs usually fall over.
They protect different things, so it is worth being precise rather than reassuring. Encrypting the file protects the bytes wherever they travel, including after someone downloads or forwards them. A link password gates access to the page: the passphrase is checked before the document is served, so it is never sent to a browser that has not answered, and wrong guesses are rate-limited. What a link adds is control after the fact — you can change the passphrase, set an expiry, or revoke it entirely, which a file that has already been sent will never let you do. If the file must stay protected once it is inside their systems, encrypt the file too.
For the link, yes and there is nothing to install: upload the PDF and set a passphrase on it here. For the file itself, macOS Preview can export a password-protected PDF, and most PDF tools offer it — but check whether you are setting an open password or a permissions password, because only the first one actually stops someone reading it, and only the first one breaks link sharing.
No. Setting a password on a link is free on any account — it is a field on the upload form and a setting on each page in your dashboard, with no plan check in front of it. The one place it is not offered is the no-account upload at /try, which has neither passwords nor expiry control, because there is no account for those settings to belong to. Signing in is free and turns both on.
Yes — each link records views, which is usually the thing you actually wanted to know when you sent a proposal or a report. Per-day detail and last-opened time come with the paid tiers. We do not do page-by-page reading analytics on the PDF; the honest limit is that we can tell you the document was opened, not how far they read.
They can — it is a PDF in a browser, so the browser's own save and print controls are there. If the point of the exercise is that the file must not leave the page at all, no link host can promise that honestly: anything a person can read on screen can be captured. What a link gives you is control over access and a record of it, not control over what happens on their machine afterwards.
No card to try, no sign-up to get a link. Sign up free to keep links forever, password-protect them, and store more.