# How to Handle Encrypted or Password-Protected PDF Documents with LiteParse

> Learn how LiteParse handles encrypted PDFs by passing passwords to PDFium, resolving PasswordRequired or InvalidPassword errors for seamless document processing.

- Repository: [LlamaIndex/liteparse](https://github.com/run-llama/liteparse)
- Tags: how-to-guide
- Published: 2026-06-24

---

**LiteParse handles encrypted PDFs by passing an optional password string through `LiteParseConfig` to PDFium's `FPDF_LoadDocument` API, returning specific errors like `PasswordRequired` or `InvalidPassword` if the credential is missing or incorrect.**

The `run-llama/liteparse` repository provides a unified document parsing engine that supports password-protected PDFs across Rust, Python, Node.js, and CLI interfaces. When working with encrypted documents, LiteParse leverages the underlying **PDFium** library to handle decryption transparently, requiring only that you supply the password through the configuration layer. This approach ensures consistent behavior whether you are extracting text, rendering pages to images, or converting document formats.

## Architecture of Password Handling in LiteParse

### Configuration Layer

In [`crates/liteparse/src/config.rs`](https://github.com/run-llama/liteparse/blob/main/crates/liteparse/src/config.rs), the `LiteParseConfig` struct defines the password field as `pub password: Option<String>`. This optional string stores the user-provided credential, accepting input from CLI flags, API parameters, or language binding options.

### Parser Integration

The parser implementation in [`crates/liteparse/src/parser.rs`](https://github.com/run-llama/liteparse/blob/main/crates/liteparse/src/parser.rs) forwards the password to the extraction layer. When loading a document, the code calls `extract::load_document_from_input` and passes `self.config.password.as_deref()`—converting the `Option<String>` to `Option<&str>` for the underlying PDFium wrapper.

### PDFium Integration

At the core of the operation, [`crates/pdfium/src/library.rs`](https://github.com/run-llama/liteparse/blob/main/crates/pdfium/src/library.rs) handles the actual decryption. The `Pdfium::load_document` method (and `load_document_from_bytes`) forwards the optional password pointer to the native `FPDF_LoadDocument` C function. When the password is `None`, LiteParse passes a null pointer to PDFium, triggering a password-required error for encrypted files.

### Error Handling

The error definitions in [`crates/pdfium/src/error.rs`](https://github.com/run-llama/liteparse/blob/main/crates/pdfium/src/error.rs) provide specific variants for authentication failures. LiteParse returns `PdfiumError::PasswordRequired` when attempting to open an encrypted PDF without supplying a password, and `PdfiumError::InvalidPassword` when the provided credential does not match the document's encryption key.

## Using Password Protection Across Language Bindings

### Command Line Interface

The CLI exposes password support through the `--password` flag defined in [`crates/liteparse/src/main.rs`](https://github.com/run-llama/liteparse/blob/main/crates/liteparse/src/main.rs). Supply the credential when parsing encrypted documents:

```bash
liteparse input.pdf --output json --password "mySecret123"

```

### Node.js and TypeScript

The Node.js wrapper in [`packages/node/src/lib.ts`](https://github.com/run-llama/liteparse/blob/main/packages/node/src/lib.ts) accepts a password in the constructor options:

```typescript
import { LiteParse } from "liteparse";

const parser = new LiteParse({
  password: "mySecret123",
  output: "json"
});

const result = await parser.parseFile("encrypted.pdf");
console.log(result);

```

### Python

The Python binding in [`packages/python/liteparse/parser.py`](https://github.com/run-llama/liteparse/blob/main/packages/python/liteparse/parser.py) maps the password argument to the Rust core:

```python
from liteparse import LiteParse

parser = LiteParse(password="mySecret123", output="json")
result = parser.parse_file("encrypted.pdf")
print(result)

```

### Direct Rust API

For Rust developers, instantiate `LiteParseConfig` with the password field populated:

```rust
use liteparse::{LiteParse, LiteParseConfig};

let cfg = LiteParseConfig {
    password: Some("mySecret123".to_string()),
    ..Default::default()
};

let parser = LiteParse::new(cfg);
let result = parser.parse_path("encrypted.pdf")?;
println!("{:?}", result);

```

## Extended Support for Rendering and Conversion

Beyond text extraction, encrypted PDF support extends to [`crates/liteparse/src/render.rs`](https://github.com/run-llama/liteparse/blob/main/crates/liteparse/src/render.rs) and [`crates/liteparse/src/conversion.rs`](https://github.com/run-llama/liteparse/blob/main/crates/liteparse/src/conversion.rs). These modules accept the same `Option<&str>` password argument, enabling OCR operations on encrypted pages and conversion workflows without requiring intermediate decryption steps.

## Summary

- LiteParse stores passwords in `LiteParseConfig.password` as an optional string across all language bindings.
- The credential flows through [`parser.rs`](https://github.com/run-llama/liteparse/blob/main/parser.rs) to [`pdfium/src/library.rs`](https://github.com/run-llama/liteparse/blob/main/pdfium/src/library.rs), where it reaches the native `FPDF_LoadDocument` API.
- Specific error variants (`PasswordRequired` and `InvalidPassword`) allow applications to handle authentication failures gracefully.
- Password support is consistent across extraction, rendering, and conversion operations.

## Frequently Asked Questions

### What happens if I don't provide a password for an encrypted PDF?

LiteParse returns a `PdfiumError::PasswordRequired` error from the PDFium layer, which propagates to your application as a clear authentication failure. The CLI displays a user-friendly error message, while library bindings throw exceptions or return error codes depending on the language.

### Can I use LiteParse to check if a PDF is encrypted without parsing it?

While LiteParse does not expose a dedicated "is encrypted" check, attempting to load a document without a password will return `PasswordRequired` immediately. You can catch this specific error to determine encryption status before attempting extraction with credentials.

### Does LiteParse support different encryption levels or certificate-based security?

LiteParse delegates all encryption handling to PDFium, which supports standard PDF password security (user and owner passwords). Certificate-based encryption or advanced DRM schemes depend on PDFium's capabilities; LiteParse passes the password string through but does not implement additional decryption logic itself.

### Is the password stored in memory after parsing completes?

The password exists in memory only as long as the `LiteParseConfig` instance persists. Once the parser is dropped or the configuration object goes out of scope, the `Option<String>` containing the password is deallocated. LiteParse does not write credentials to disk or cache them between sessions.