Sanitize PDF
Strip metadata, JavaScript and other hidden content from a PDF.
A PDF carries more than its pages. There is the document information block with the author and the software that made it, an XMP metadata stream that often repeats and extends it, annotations, embedded files, document-level actions and JavaScript that runs when the file opens. None of it is visible on the page, and all of it travels when you send the document.
This tool removes those, each as a separate choice so you can see what you are stripping, and reports the size before and after. Understand what it is not: it removes the hidden apparatus around the pages, not the content printed on them. A name in the body text is still there, and only Redact removes that. Sanitising an internal draft does not make it safe to publish — it makes it stop carrying the parts you did not know about.
How it works
- Drop in a PDF.
- Choose what to strip: metadata, XMP, annotations, attachments, actions and JavaScript.
- Decide whether the interactive form should go too.
- Sanitize and download, checking the before-and-after size.
What people use it for
- Cleaning a document of internal metadata before publishing it on a website.
- Removing JavaScript and actions from a PDF received from outside.
- Stripping an author name and revision traces from a document going to a client.
Frequently asked questions
- Is my file uploaded to a server?
- No. The file is opened by JavaScript and WebAssembly running inside your own browser tab. It is never uploaded, there is no server-side processing and nothing is stored — closing the tab discards everything.
- Does this make my document anonymous?
- It removes the hidden apparatus: document info, XMP, annotations, attachments, actions and scripts. It does not touch what is printed on the pages. A name in the text, in a header or in a signature block is still there — use Redact for content.
- Why remove JavaScript?
- Because a PDF can carry scripts that run when it opens, and document-level actions that fire on events. They are almost never needed and are a well-known vector for unpleasant behaviour in files from unknown sources.
- Should I remove the interactive form?
- Only if you do not need it. Removing the AcroForm takes the fields away entirely; if what you want is to keep the values but stop them being edited, use Flatten instead.
- How is this different from the Metadata tool?
- Metadata edits the visible information fields — title, author, subject. This strips the whole hidden layer, including XMP, scripts, actions and embedded files. Clearing metadata is not sanitising.
Related tools
- 087087Digital signatureCryptographically sign a PDF with your P12/PFX certificate (PAdES) — the certificate never leaves your browser. Optional visible signature.
- 088088Protect PDFAdd a password (AES-256), remove a known password, or repair a damaged PDF — with optional fast web view.
- 089089Unlock PDFRemove the password from a PDF you can already open — you must know the current one. It doesn't crack protected files.
- 090090Redact PDFBlack out sensitive content with permanent rectangles you draw on the page.