Web app
In any browser
Open the app and drop a file. No account needed. Nothing is uploaded.
Open source · MIT license · by Nullthrone
unpassword removes the password protection of PDF, Office and ZIP files in your browser, so you can archive them under protection you control. The password never leaves your device. Neither does the file.
How it works
Drop it into the web app, pick it from Google Drive, use Open with in Drive, or open a Gmail attachment through the add-on.
Use the password you were given. unpassword checks it against the file’s own encryption. It does not try alternatives.
Download the unlocked file, or save it next to the original in Drive. Protect it with your account security instead of a sender’s file password.
Architecture
unpassword is a static web app. Its provider hosts files and nothing else. No server receives your document, your password or the decrypted result.
drive.file scope: only files you
select or that unpassword creates.
Guardrails
unpassword exists for files you are entitled to open. It is built to be useless against files you are not.
Formats
| Format | Protection | Result |
|---|---|---|
| Standard security handler: RC4, AES-128, AES-256 | Open password removed. Restrictions kept unless the owner password is supplied. | |
| DOCX · XLSX · PPTX | ECMA-376 Agile and Standard encryption | Unencrypted Office document, integrity-checked |
| ZIP | ZipCrypto, WinZip AES-128/192/256 | Unencrypted ZIP with the same entries, every entry verified |
Not supported: legacy .doc/.xls/.ppt, 7z and RAR, DRM, certificate-based protection, worksheet protection.
Get it
Web app
Open the app and drop a file. No account needed. Nothing is uploaded.
Google Drive
After installing from the Google Workspace Marketplace, right-click a protected file in Drive and choose Open with → unpassword.
Requires the drive.file scope
Gmail
The add-on lists protected attachments of the open message and hands the still-encrypted file to the web app via Drive.
Reads the open message only
Administrators and self-hosters: see the setup guide.
Verify
Every deployment is built by GitHub Actions from a tagged commit. The
checksums of all published files are listed in
SHA256SUMS.txt. Build the same tag yourself, with the same public Google identifiers,
and compare the app/ entries.
git clone https://github.com/nullthrone/unpassword
cd unpassword/web && npm ci && npm run build
sha256sum dist/assets/*