unpassword

Open source · MIT license · by Nullthrone

Remove passwords you already know.

unpassword removes the password protection of PDF, Office and ZIP files in your browser, so you can archive them under protection you control. The password never leaves your device. Neither does the file.

No serverDecryption runs in a web worker on your device. There is no backend to trust.
No guessingOne typed password per attempt. Failed attempts slow down and lock.
No trackingNo analytics, no cookies, no third-party fonts. This page loads no scripts.

How it works

Three steps. One password. Your archive.

  1. 01

    Select the file

    Drop it into the web app, pick it from Google Drive, use Open with in Drive, or open a Gmail attachment through the add-on.

  2. 02

    Enter the password

    Use the password you were given. unpassword checks it against the file’s own encryption. It does not try alternatives.

  3. 03

    Archive your way

    Download the unlocked file, or save it next to the original in Drive. Protect it with your account security instead of a sender’s file password.

Architecture

Zero knowledge, by construction.

unpassword is a static web app. Its provider hosts files and nothing else. No server receives your document, your password or the decrypted result.

  • Decryption runs in an isolated web worker: qpdf compiled to WebAssembly for PDF, the ECMA-376 algorithms for Office, zip.js for archives.
  • A Content Security Policy lets the app talk only to its own origin and to Google’s APIs. The browser blocks everything else.
  • Drive access uses the drive.file scope: only files you select or that unpassword creates.
  • The Gmail add-on handles the encrypted attachment only. It never sees a password.

Read the security model

Data flow The browser decrypts locally and exchanges files only with Google Drive. The Gmail add-on stores the encrypted attachment in Drive. The unpassword provider only serves static files and receives no data. Your browser Web worker password · decryption plaintext in memory only UI · download CSP: own origin + Google APIs Google Drive API OAuth · Picker your files Gmail add-on encrypted only unpassword provider serves static files (GitHub Pages) receives no files, passwords or results code only

Guardrails

Not a cracking tool.

unpassword exists for files you are entitled to open. It is built to be useless against files you are not.

  • One password per attempt. Typed by you. No lists, no imports, no generators.
  • Rate limited. Two free failures, then 5 s, 10 s, 20 s … and a lock after ten.
  • Restrictions are kept. A PDF’s open password removes the open protection only. Print and copy restrictions stay unless you enter the owner password.
  • Nothing to crack offline. Hashes, verifiers and salts are never exported.
  • No bypassing. DRM, certificate protection and sheet protection are refused.
  • Stated plainly. These limits run on your device and are not a cryptographic boundary. unpassword adds no attack capability: the work an attacker faces is the same with or without it.

Formats

What unpassword unlocks.

Format Protection Result
PDF Standard security handler: RC4, AES-128, AES-256 Open password removed. Restrictions kept unless the owner password is supplied.
DOCX · XLSX · PPTX ECMA-376 Agile and Standard encryption Unencrypted Office document, integrity-checked
ZIP ZipCrypto, WinZip AES-128/192/256 Unencrypted ZIP with the same entries, every entry verified

Not supported: legacy .doc/.xls/.ppt, 7z and RAR, DRM, certificate-based protection, worksheet protection.

Get it

Where unpassword runs.

Web app

In any browser

Open the app and drop a file. No account needed. Nothing is uploaded.

Open the web app

Google Drive

Open with unpassword

After installing from the Google Workspace Marketplace, right-click a protected file in Drive and choose Open with → unpassword.

Requires the drive.file scope

Gmail

From an attachment

The add-on lists protected attachments of the open message and hands the still-encrypted file to the web app via Drive.

Reads the open message only

Administrators and self-hosters: see the setup guide.

Verify

Check what you run.

Every deployment is built by GitHub Actions from a tagged commit. The checksums of all published files are listed in SHA256SUMS.txt. Build the same tag yourself, with the same public Google identifiers, and compare the app/ entries.

git clone https://github.com/nullthrone/unpassword
cd unpassword/web && npm ci && npm run build
sha256sum dist/assets/*