PDF encryption
Papyra encrypts PDF output with AES-256 using the PDF 2.0 standard security handler (ISO 32000-2, /V 5 /R 6) - the current, non-deprecated encryption scheme. Older schemes (RC4, AES-128) are deliberately not offered.
byte[] pdf = document.RenderAsPdf(new PdfRenderOptions{ Standard = PdfStandard.Pdf20, Encryption = new PdfEncryption { UserPassword = "open-me", OwnerPassword = "admin-only", Permissions = PdfPermissions.Print | PdfPermissions.ExtractForAccessibility, },});Encryption requires plain PDF 2.0
Section titled “Encryption requires plain PDF 2.0”PDF/A forbids encryption, and Papyra’s default output is PDF/A. Encryption therefore requires Standard = PdfStandard.Pdf20 - the plain (non-archival) PDF 2.0 mode, which carries none of the PDF/A scaffolding (no XMP packet, output intent, or embedded ICC profile; document metadata lives in the Info dictionary, encrypted like everything else).
Any other standard throws at render time, and the bundled analyzer flags the literal-initializer case at compile time as PAPY106, with a code fix that sets the standard for you.
Encryption and Factur-X e-invoicing are mutually exclusive - Factur-X requires PDF/A-3. Plain attachments work under Pdf20 and are encrypted along with the rest of the file.
Passwords
Section titled “Passwords”UserPassword |
Required to open the document. When null or empty, the document opens without a password, but Permissions still apply. |
OwnerPassword |
Grants full access regardless of Permissions. When null, the user password also acts as the owner password. |
At least one password must be non-empty. Passwords are Unicode-normalized (NFC), UTF-8 encoded, and truncated to 127 bytes per the spec. Full RFC 4013 SASLprep is not applied - everyday passwords (including non-ASCII letters like umlauts) interoperate with mainstream readers, but passwords built from exotic control or format characters may not round-trip against a strictly conforming reader.
Permissions
Section titled “Permissions”PdfPermissions is a flags enum mapped to the standard permission bits (ISO 32000-2 Table 22). The default is All.
| Flag | Allows |
|---|---|
Print |
Printing (possibly degraded without PrintHighResolution) |
PrintHighResolution |
Full-resolution printing |
CopyContent |
Copying/extracting text and graphics |
ExtractForAccessibility |
Extraction for accessibility (PDF 2.0 readers always allow this; the bit still matters to older readers) |
ModifyContents |
Editing document content |
Annotate |
Adding annotations and filling forms |
FillForms |
Filling forms even when Annotate is denied |
AssembleDocument |
Inserting/rotating/deleting pages, creating bookmarks |
Permissions restrict readers opened with the user password; the owner password is never restricted. Note that permissions are an instruction to the viewer, not cryptography - a viewer can simply ignore them; only the passwords are cryptographically enforced.
Non-deterministic output
Section titled “Non-deterministic output”Papyra’s unencrypted output is byte-identical for identical documents. Encrypted output deliberately is not: the file encryption key, salts, and per-string/stream initialization vectors are freshly random on every render, as sound cryptographic practice requires. Rendering the same document twice produces different bytes that decrypt to identical content.
See also
Section titled “See also”- PDF render options
- PDF/A output - why the archival standards and encryption exclude each other
© 2026 Stefan Nikolei. Payments are processed by Paddle.com as merchant of record.