3 Ways to Add Authorized Users to VeryPDF DRM Protector for PDF eBook Protection

When you use VeryPDF DRM Protector to sell protected PDF eBooks, you can create an authorized user for each customer.

For example, if you want each customer to read an eBook on a maximum of 2 devices, you can set the 2-device limit for that user.

There are three ways to add authorized users:

  1. Seller Adds Users Manually
  2. Let customers register themselves (Customer Self-Registration)
  3. Automatically create users with the VeryPDF DRM API

The best method depends on how many customers you have and how much work you want your customers or your staff to do.

Quick Comparison

Seller Adds Users Customer Self-Registration API Automation
Who creates the user? Seller Customer Your system
Customer needs to register? No Yes No
Customer enters email again? No Usually No
Seller needs to add users? Yes No No
Reading link generated automatically? No Yes Yes
Reading link emailed automatically? Optional Yes Yes
2-device limit Yes Yes Yes
Good for a few customers Yes Yes Yes
Good for many customers No Yes Yes
Fully automatic No Partly Yes
Customer experience Simple More steps Simple

3 Ways to Add Authorized Users to VeryPDF DRM Protector for PDF eBook Protection


1. Manually Add Authorized Users

The first method is to add each customer manually.

After a customer purchases your eBook, you create a user in VeryPDF DRM Protector and set the user’s device limit.

For example:

Customer: John Smith
Email: john@example.com
Device limit: 2 devices

You then generate a reading link for John and send it to him by email.

How it works

Customer purchases → Seller adds user → Set 2-device limit → Send reading link

This method is simple and does not require any technical integration.

Advantages

  • Easy to set up
  • No customer registration
  • No API integration required
  • Good when you have only a small number of customers

Disadvantages

The seller needs to process every order manually.

If you sell 3 eBooks, this is not a problem.

If you sell 300 eBooks, manually creating users and sending reading links can become a lot of work.


2. Let Customers Register Themselves (Customer Self-Registration)

The second method is to let the customer create their own DRM account.

After purchasing the eBook, the customer follows your instructions and registers an account.

The process may look like this:

Purchase → Register → Verify email → Sign in → Access eBook

The DRM user is created by the customer, so the seller does not need to manually create the account.

Advantages

  • Little work for the seller
  • No API integration required
  • Customers can manage their own accounts
  • Works well when you want users to have their own DRM accounts

Disadvantages

The main problem is that it adds more steps for the customer.

For example, the customer may have already entered their name and email address when buying the eBook.

After paying, they may be asked to enter the email address again during registration.

From the customer’s point of view, this can feel frustrating:

“I already paid for the eBook. Why do I have to register again?”

This is especially important when selling individual eBooks or other small digital products. Customers usually expect to receive their product quickly after payment.


3. Automatically Create Users with the VeryPDF DRM API

The third method is to automatically create the authorized user through the VeryPDF DRM API.

For an online eBook store, this is usually the best option.

Your ecommerce system already knows information such as:

  • Customer name
  • Customer email
  • Order ID
  • Product SKU
  • Payment status

After the payment is completed, your server can send this information to the VeryPDF DRM API.

VeryPDF DRM can then automatically:

  1. Create the authorized user.
  2. Set the user’s device limit, such as 2 devices.
  3. Generate a personal reading URL.
  4. Send the reading URL to the customer by email.

The customer does not need to register again.

The customer experience

The process can be as simple as:

Purchase → Payment completed → Receive reading link → Read

This avoids unnecessary registration steps and reduces the amount of work for the seller.


How the Three Methods Compare

Feature Seller Adds Users Customer Self-Registration API Automation
Create user Seller Customer Automatic
Enter customer information Seller Customer From order
Email verification Depends on setup Usually Can be automated
Set device limit Seller System Automatic
Generate reading URL Seller/System System Automatic
Send reading URL Seller System Automatic
Customer registration Not required Required Not required
Seller workload High Low Very low
Customer workload Very low Higher Very low
Technical work Low Low Higher
Best for Small sales Account-based services Growing stores

Which Method Should You Choose?

The choice is quite simple.

Choose Manual User Creation if:

  • You sell only a few eBooks.
  • You want to start quickly.
  • Your ecommerce system has no API.
  • You do not mind processing orders manually.

Choose Customer Registration if:

  • You want customers to manage their own accounts.
  • Your customers are comfortable with registration.
  • You do not have an ecommerce API integration.

Choose API Automation if:

  • You expect your eBook sales to grow.
  • You want to avoid manual work.
  • You do not want customers to register again.
  • Your ecommerce system supports Webhooks or APIs.
  • You want the entire delivery process to run automatically.

For most growing eBook stores, API automation is the preferred solution.


How API Automation Works

Suppose you sell an eBook called:

“Advanced Certification Training Guide”

Your ecommerce system receives an order:

Order Information Value
Customer John Smith
Email john@example.com
Product SKU CERT-001
Payment Captured
PDF ID 12345

After payment is completed, your system sends the information to the VeryPDF DRM API.

The system can then:

Create User → Set 2 Devices → Generate Reading URL → Send Email

The customer receives the reading link without having to create another account.

Example: Automatically Create a User and Limit Access to 2 Devices

You can use the VeryPDF DRM API to automatically create an authorized user and set the user to a maximum of 2 devices.

For example, the API request can include:

https://online.verypdf.com/app/pdfdrm/api.php?
action=user_add
&email=admin@yourdomain.com
&app_password=YOUR_APP_PASSWORD
&username=UserNameJohn
&password=123456
&useremail=john@example.com
&role=user
&phone=8589999988
&firstname=John
&lastname=Smith
&options=LockToFirstNDevicesForUser%3D2

The important parameter is:

LockToFirstNDevicesForUser=2

This tells VeryPDF DRM Protector to allow this authorized user to read the purchased PDF on a maximum of 2 devices.

The first two devices used by the customer will be registered for that user. The customer cannot use the same account to read the protected PDF on additional devices.

This API can be called automatically after a successful eBook purchase. Your ecommerce system can send the customer’s information to VeryPDF DRM, create the authorized user, set the 2-device limit, and then generate and send the customer’s personal reading link.

This allows you to keep the customer experience simple:

Purchase → Payment → Automatic user creation → 2-device protection → Receive reading link → Read the eBook

Where to Get Your App Password

The app_password is your VeryPDF DRM application password. You can get it from your VeryPDF DRM account profile page:

Get Your App Password

After logging in to your VeryPDF DRM account, open your profile page and find the Application Passwords section.

Copy the application password and use it as the app_password value in your API request.

For security, do not publish your application password or share it with customers.

PHP Example

You can also call the VeryPDF DRM API from your PHP application.

For example:

<?php

$apiUrl = 'https://online.verypdf.com/app/pdfdrm/api.php';

$params = [
    'action'       => 'user_add',
    'email'        => 'admin@yourdomain.com',
    'app_password' => 'YOUR_APP_PASSWORD',
    'username'     => 'UserNameJohn',
    'password'     => '123456',
    'useremail'    => 'john@example.com',
    'role'         => 'user',
    'phone'        => '8589999988',
    'firstname'    => 'John',
    'lastname'     => 'Smith',
    'options'      => 'LockToFirstNDevicesForUser=2'
];

$ch = curl_init($apiUrl);

curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($params));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_TIMEOUT, 30);

$response = curl_exec($ch);

if ($response === false) {
    die('API request failed: ' . curl_error($ch));
}

curl_close($ch);

echo $response;
?>

The important part is:

'options' => 'LockToFirstNDevicesForUser=2'

This tells VeryPDF DRM Protector to limit the user to 2 devices.

In a real ecommerce integration, you can replace the hard-coded customer information with information from the completed order. For example, the customer’s email, name, phone number, and purchased product can be read from your order system and then sent to the VeryPDF DRM API automatically.

This makes it possible to create the authorized user immediately after payment without asking the customer to register again.


What If I Already Have Customers?

You do not need to immediately move existing customers to the new system.

For example, if you have already sold 3 eBooks, you can continue using their existing reading links.

When the new user system is ready, you can choose between two options:

Option Existing Customers New Customers
Keep old users Keep existing links New automated system
Move everyone Create new users and send new links New automated system

Both approaches can work.

The important thing is that changing to a user-based DRM system does not mean your existing customers must suddenly lose access.


What If API Integration Is Not Available?

You can still use the manual method.

To make manual processing easier, VeryPDF DRM Protector can be designed around a simple workflow:

Add User → Send Reading Link

After you add the customer, you can click a button to send the personal reading link.

This is much easier than asking every customer to go through a registration process.


Which Is Best for a 2-Device eBook Limit?

If your main goal is:

“Each person who buys my eBook can use it on no more than 2 devices.”

Then the user-based approach is the right choice.

The three available methods are:

Method Best Use
Seller Adds Users Manually A small number of customers
Customer Self-Registration Customers manage their own accounts
Automatic User Creation via API Automation Automatic delivery for a growing business

For an eBook business that expects more sales, VeryPDF DRM API automation provides the simplest way to create authorized users without adding extra registration steps for paying customers.


Frequently Asked Questions

1. Why do I need to create an authorized user?

If you want to limit a customer to a certain number of devices, the device limit needs to be associated with the user.

2. Can I limit a customer to 2 devices?

Yes. You can configure the authorized user with a 2-device limit.

3. Does the device limit belong to the PDF?

The recommended setup is to associate the device limit with the authorized user.

4. Do customers have to register?

No. Manual user creation and API automation do not require the customer to register themselves.

5. Can customers register themselves?

Yes. Self-registration is one of the three ways to create an authorized user.

6. Can I create users manually?

Yes. This is useful when you have a small number of customers.

7. Can the customer use the same email from checkout?

Yes. With API automation, the email from the ecommerce order can be used to create the DRM user.

8. Does the customer need to enter their email twice?

With API automation, the customer does not need to manually enter the email address again.

9. Can the reading link be sent automatically?

Yes. The VeryPDF DRM API can be used to generate and deliver a personal reading URL.

10. Which method requires the least work from the seller?

API automation requires the least manual work after the integration is completed.

11. Which method is easiest to start with?

Manual user creation is usually the easiest because it does not require technical integration.

12. Which method is best for a growing eBook business?

API automation is generally the best choice when the number of orders is growing.

13. What happens to my existing customers?

You can keep their existing reading links or move them to the new user-based system.

14. What if my ecommerce system does not support Webhooks?

You can use manual user creation, or check whether your ecommerce platform provides another API integration method.

15. Can VeryPDF help with API integration?

Yes. VeryPDF can help you connect your ecommerce order system with the VeryPDF DRM API so that users and reading links can be created automatically.

16. Can I use this for PDF eBooks?

Yes. VeryPDF DRM Protector is designed to protect PDF eBooks and other paid PDF documents.


Summary

There are three ways to add authorized users in VeryPDF DRM Protector:

1. Seller Adds Users Manually: The seller creates the user.

2. Customer Self-Registration: The customer creates the user.

3. Automatic User Creation via API automation: The ecommerce system creates the user automatically.

If you sell only a few eBooks, manual user creation may be enough.

If you want customers to manage their own accounts, self-registration can work.

If you want to sell more eBooks without adding more manual work or asking customers to register again, API automation is the best choice.

VeryPDF DRM Protector can help you create authorized users, apply device limits, generate personal reading links, and connect PDF DRM protection with your online sales process.

How to Build an Automatic eBook Delivery System with PDF Device Limits

Selling PDF eBooks is easy. The difficult part starts after a customer pays.

You need to deliver the correct PDF, send the customer a private reading link, stop customers from sharing that link, and control how many devices can open the PDF.

For example, if a customer buys an eBook from your website, you may want this process:

Customer pays → your order system sends customer email + PDF ID → DRM system creates the user → customer receives a private reading link → PDF is locked to 2 devices

This can be built as a custom eBook automatic delivery system with the VeryPDF DRM API.

The seller does not need to manually create accounts or send PDF links after every order.

How to Build an Automatic eBook Delivery System with PDF Device Limits

What Is an Automatic eBook Delivery System?

An automatic eBook delivery system connects your online store or order system with a PDF DRM system.

After a successful payment, your website sends a small amount of information to the DRM server.

For example:

Customer Email: john@example.com
PDF ID: ebook-123

That is enough for the DRM system to handle the rest.

Step What happens
1 Customer buys an eBook
2 Your order system confirms payment
3 Your website sends the customer email to the DRM API
4 Your website sends the purchased PDF ID
5 DRM creates or updates the customer account
6 DRM gives the customer access to the correct PDF
7 A personal reading link is created
8 The reading link is sent to the customer
9 The PDF is limited to the allowed number of devices

The important point is that your order system does not need to send us the customer’s full order information.

It only needs to tell VeryPDF DRM:

This customer bought this PDF.


Why Use Customer Email + PDF ID?

Many online stores already have a lot of order information:

  • Order number
  • Product name
  • Product price
  • Payment method
  • Billing address
  • Shipping information
  • Customer email
  • Product ID
  • Transaction ID

A DRM delivery system normally does not need all of this.

For eBook delivery, two pieces of information may be enough:

Customer email + PDF ID

For example:

email = john@example.com
pdf_id = business-training-2026

This keeps the integration simple.

Your website does not need to give the DRM system access to your complete customer database or order database.


How Automatic PDF Delivery Works

Imagine that you sell three PDF books:

PDF ID eBook
ebook-001 Business English Guide
ebook-002 Sales Training Manual
ebook-003 Marketing Certification Guide

A customer purchases ebook-002.

Your order system sends:

Email: customer@example.com
PDF ID: ebook-002

VeryPDF DRM can then automatically identify the customer and the purchased PDF.

The customer receives a personal reading link instead of a common link that can be shared with other people.

This is especially useful if you sell:

  • eBooks
  • Training manuals
  • Course materials
  • Certification PDFs
  • Technical documents
  • Professional guides
  • Paid reports
  • Membership documents

Why a Shared PDF Link Is a Problem

Many websites use a simple link such as:

https://example.com/download/book.pdf

The problem is that the customer can forward the link to someone else.

You may also have a shared reading link such as:

https://drm.verypdf.com/r/tDA2r3

If everyone receives the same link, it becomes difficult to know who is actually allowed to read the PDF.

A customer can send the link to:

  • A friend
  • A colleague
  • A student
  • Another customer
  • A group chat
  • A website or forum

This creates a simple problem:

One purchase can become access for many people.

A personal DRM reading link is different. The link is connected to a specific customer and the PDF access rules.


Automatically Lock a PDF to 2 Devices

One of the most useful features is device limits.

For example, you can allow:

One customer → maximum 2 devices

The customer might use:

  • Windows PC
  • Mac
  • iPhone
  • iPad
  • Android device

Once the customer has reached the device limit, another device cannot simply be added and used to read the same protected PDF.

This helps reduce account sharing and PDF sharing.

Example

John purchases an eBook.

He opens the reading link on his Windows computer.

Device 1 is registered.

Later, he opens the same eBook on his iPad.

Device 2 is registered.

Now he has reached the limit of 2 devices.

If another person tries to use John’s account on another device, access can be blocked according to your DRM settings.


Automatic Device Locking vs. Sending a PDF

There is a big difference between these two delivery methods.

Traditional PDF delivery DRM eBook delivery
Send PDF file Send personal reading link
Easy to forward Access can be controlled
No device limit Device limit can be applied
Difficult to revoke access Access can be revoked
Same file can be shared User access is tied to DRM rules
Little control after delivery More control after purchase

If your PDF is a paid product, simply sending the original PDF file may give you very little control after the customer receives it.


Two Ways to Build the System

There are two practical ways to deliver protected eBooks.

Option 1: Automatic API Integration

This is best when you have many orders.

After the payment succeeds, your website calls the VeryPDF DRM API.

For example:

Customer purchases PDF
        ↓
Payment successful
        ↓
Order system calls DRM API
        ↓
Customer email + PDF ID
        ↓
VeryPDF DRM creates customer access
        ↓
Personal reading link created
        ↓
Email sent to customer
        ↓
Customer reads protected PDF

Your staff does not need to manually process every order.

Good for

  • Online bookstores
  • eBook websites
  • Course platforms
  • Training companies
  • Certification providers
  • Publishers
  • Websites with many daily orders

Option 2: Manual One-Click eBook Delivery

Not every seller needs API integration.

If you only sell a small number of eBooks each month, a simple manual system may be better.

For example, you could have an admin page like:

Customer Email PDF Action
john@example.com Sales Guide Send Reading Link
mary@example.com Training Manual Send Reading Link

You add the customer and select the PDF.

Then click:

Send Reading Link

The system automatically sends the customer’s private reading link.

The link can also have a device limit, such as 2 devices per customer.

This avoids the need to develop an API integration with your shopping cart.


Which Method Should You Choose?

The best choice depends on your order volume.

Situation Recommended method
Few eBook orders Manual one-click delivery
Dozens of orders API integration
Hundreds of orders API integration
Large online bookstore API integration
Training company API integration
Certification platform API integration
Small publisher Manual or API
Custom eCommerce website API integration

You do not need to build a complicated system if you only have a few orders.

But when order volume increases, manual delivery becomes a problem.


A Custom eBook Delivery System Can Be Very Simple

A common mistake is thinking that a DRM integration must exchange a lot of customer data.

It does not have to.

A simple custom integration can work like this:

Your Website
Customer buys PDF
       ↓
Payment confirmed
       ↓
Send:
customer email
+
PDF ID
       ↓
VeryPDF DRM API
       ↓
Create customer
       ↓
Assign PDF
       ↓
Create personal reading link
       ↓
Send email

The order system remains responsible for the sale.

VeryPDF DRM handles the protected PDF access.

This separation makes the system easier to maintain.


What Happens If a Customer Buys Multiple eBooks?

The PDF ID becomes important when you sell multiple books.

For example:

customer@example.com
ebook-001

means the customer purchased one book.

Another purchase might be:

customer@example.com
ebook-003

The DRM system can then give the same customer access to another protected PDF.

This is much better than creating a completely separate account for every book.


What If the Customer Buys the Same eBook Again?

Your system can also define how repeat purchases should work.

For example:

Situation Possible action
Customer already has access Keep existing access
Customer buys another PDF Add another PDF
Customer’s access was revoked Restore access
Customer changes email Update account
Customer reaches device limit Block new device
Customer needs a new device Admin can manage device access

The exact rules can be customized for your business.


Protecting eBooks Without Making the Customer Experience Difficult

Security should not make the buying process confusing.

A good eBook delivery system should look simple to the customer:

Buy → Receive email → Click reading link → Read

The security controls work in the background.

The customer does not need to understand how the DRM system works.

They simply know that their purchased eBook is available through their personal reading link.


Use VeryPDF DRM Protector for Automatic eBook Delivery

VeryPDF DRM Protector can be used as the protected PDF layer behind your eBook delivery system.

It can help you control:

  • Who can access a PDF
  • Which PDF a customer can read
  • How many devices can be used
  • PDF printing
  • PDF copying
  • PDF access
  • Reading links
  • User access
  • Access expiration
  • Access revocation

The important part is that you do not need to replace your existing order system.

Your website can continue handling:

Products → Payments → Orders → Customers

VeryPDF DRM can handle:

Protected PDFs → User access → Reading links → Device limits

This makes it possible to build a custom eBook delivery system around your existing website.


Example: Selling a Paid Training PDF

Suppose a training company sells a $99 PDF training manual.

A customer called Sarah buys it.

The order system sends:

Email: sarah@example.com
PDF ID: training-manual-001

VeryPDF DRM receives the information.

The system creates Sarah’s DRM account and gives her access to the correct PDF.

Sarah receives her personal reading link.

She opens the PDF on her laptop.

Later, she opens it on her iPad.

Now she has two registered devices.

If the account is limited to two devices, a third device cannot simply be used to access the same protected PDF.

The seller does not have to manually send the PDF.


What About a Small eBook Business?

If you sell only a few books every day, you may not need a complicated API system.

A simple admin tool can be enough.

For example:

Customer Email:
[ sarah@example.com ]
PDF:
[ Training Manual ▼ ]
[ Send Reading Link ]

After clicking the button, the system can create the user, assign the PDF, and send the protected reading link.

This can be much easier than integrating your entire shopping cart.


Automatic eBook Delivery Reduces Manual Work

Imagine receiving 50 eBook orders in one day.

With manual delivery, someone may need to:

  1. Check each order.
  2. Find the correct PDF.
  3. Create the customer.
  4. Generate a reading link.
  5. Send the email.
  6. Check whether the customer already exists.
  7. Handle device-limit problems.

This quickly becomes repetitive.

With an API integration, the process can happen automatically after payment.

That means your team can spend less time sending links and more time dealing with real customer questions.


Frequently Asked Questions

1. Can I automatically send an eBook after payment?

Yes. Your order system can call the VeryPDF DRM API after payment succeeds. The API can then create or update the customer and provide access to the purchased PDF.

2. What information does the DRM API need?

A simple integration can use the customer’s email address and the PDF ID they purchased. You do not need to send all order details.

3. Can one customer buy multiple PDFs?

Yes. Each PDF can have its own PDF ID, so one customer can have access to multiple protected eBooks.

4. Can I limit an eBook to two devices?

Yes. A device limit can be used to control how many devices a customer can use to read the protected PDF.

5. Can I use three devices instead of two?

Yes, if your business rules require it. The allowed device count can be configured according to your needs.

6. Do I have to send the PDF file to the customer?

No. Instead of sending the original PDF file, you can send a personal reading link to the protected PDF.

7. Can customers share their reading links?

A personal reading link can be combined with user and device controls to reduce unauthorized sharing. The exact protection depends on the DRM settings you choose.

8. What if I have very few orders?

You can use a manual delivery system. An admin can add the customer, select the PDF, and click a button to send the reading link.

9. Do I need to replace my current shopping cart?

Not necessarily. Your existing order system can remain in place. It only needs to notify the DRM system after a successful purchase.

10. Can this work with a custom website?

Yes. A custom website can call the VeryPDF DRM API after an order is completed.

11. Can this work with an eBook store selling many books?

Yes. The PDF ID lets the system identify exactly which eBook the customer purchased.

12. Can I revoke a customer’s PDF access?

Yes. DRM access can be managed after the purchase, which is useful when an account needs to be disabled.

13. Can I prevent customers from printing or copying the PDF?

VeryPDF DRM Protector provides controls for PDF printing and copying, depending on your selected protection settings.

14. Is API integration necessary?

No. API integration is useful when you have many orders. For a small eBook business, a manual one-click delivery system may be enough.

15. Can the whole process be automatic?

Yes. With an API integration, the basic process can be:

Payment → Customer Email + PDF ID → DRM → Personal Reading Link → Email → Protected PDF

That is the main idea behind a custom automatic eBook delivery system.


Final Takeaway

If you sell paid PDF eBooks, the most important question is not only “How do I deliver the PDF?”

It is also:

“How do I make sure the PDF is delivered to the right customer and does not become a freely shared file?”

A custom system using customer email + PDF ID + VeryPDF DRM API can keep this process simple.

For high-volume sales, the process can be fully automated.

For smaller businesses, a simple manual system with a Send Reading Link button may be enough.

In both cases, you can give each customer a personal reading link and limit the protected PDF to a specific number of devices, such as 2 devices per customer.

How to Protect VPDF Files, Stop Unauthorized Access, and Secure Online Book Sales with Allowed IP Rules for the VeryPDF DRM API

If you sell protected PDF books, training materials, or digital documents through your own website, protecting the file itself is only one part of the problem.

You also need to protect:

  • The server where the protected file is stored
  • The DRM API
  • Customer reading links
  • Payment and order records
  • Customer accounts
  • Your website source code
  • Access logs and reading activity

A common mistake is to protect the PDF but leave the server or API open. If someone gets access to the original .vpdf file or copies the sales system, they may create serious problems for your business.

How to Protect VPDF Files, Stop Unauthorized Access, and Secure Online Book Sales with Allowed IP Rules for the VeryPDF DRM API

This article explains a practical way to protect .vpdf files and build a safer sales system with VeryPDF DRM Protector.

1. Why protecting the .vpdf file is important

A protected .vpdf file may be stored on a separate server from your website.

For example:

Your Website
     |
     | Customer buys book
     v
VeryPDF DRM
     |
     | Reads protected file
     v
Your Superhosting Server
     |
     +-- book.vpdf

The important question is:

Can a normal visitor directly open or download book.vpdf from your server?

If the answer is yes, your server has an unnecessary security risk.

The .vpdf file should not be treated like a normal public PDF.

With VeryPDF DRM Protector, the protected file requires DRM authorization. However, it is still a good idea to add another security layer on the server.

2. Allow only the VeryPDF server to access the .vpdf file

If your .vpdf file is stored on an Apache server, you can restrict access to the file by IP address.

For example, in the case discussed with Superhosting, the VeryPDF server is:

Setting Value
Domain online.verypdf.com
IP address 173.255.248.140
Protected file .vpdf
Allowed access VeryPDF server
Other IP addresses Denied

You can ask your hosting company to configure the server so that the .vpdf file can only be accessed from the VeryPDF server IP.

This is better than relying only on a hostname rule if your hosting company does not support that configuration.

Why IP restriction helps

Without IP restriction:

Internet
   |
   +---- Visitor
   +---- Bot
   +---- Unknown server
   +---- Attacker
   |
   v
book.vpdf

With IP restriction:

Internet
   |
   v
book.vpdf
   |
   +---- VeryPDF server: ALLOWED
   |
   +---- Other IPs: BLOCKED

This means that even if somebody knows the location of your .vpdf file, they cannot simply request the file from another server.

3. Do not make the .vpdf file publicly downloadable

Another important rule is:

Do not place the protected file in a location where anyone can download it directly.

For example, avoid giving customers a direct URL such as:

https://example.com/files/book.vpdf

Instead, the customer should receive a reading link that goes through your website and VeryPDF DRM system.

The customer should see the protected document in the DRM reader rather than receiving the original file as a normal download.

This reduces the chance of people sharing the actual .vpdf file.

4. Protect the VeryPDF DRM API

Protecting the file is only half of the security problem.

You should also protect the VeryPDF DRM API.

Imagine that someone copies your website source code.

If the copied website can still call your VeryPDF DRM API from another server, the attacker may be able to create DRM users or perform other DRM operations.

VeryPDF DRM provides an Allowed IP Rules setting for this purpose.

You can add the public IP address of your own website server in:

VeryPDF DRM Settings → DRM API Security Settings → Allowed IP Rules

Then the system can work like this:

Your Website Server
       |
       | API request
       v
VeryPDF DRM API
       |
       +---- Authorized IP → ALLOW
       |
       +---- Other IP → DENY

This is especially useful if your website contains the code that creates customers and reading links.

5. What happens if someone copies your website?

There is a difference between copying a website and successfully operating a copied DRM system.

A developer may technically have access to website code, payment code, database records, and API integration.

But if the VeryPDF API accepts requests only from your authorized server IP, copying the website to another server does not automatically give that new server access to your VeryPDF DRM account.

For example:

Situation Result
Your real website calls VeryPDF API Allowed
Copied website on another server calls API Rejected
Unknown server calls API Rejected
Authorized server creates DRM user Allowed
Unauthorized server tries to create DRM user Rejected

This is why API IP restrictions are an important part of protecting an online DRM sales system.

6. Can someone copy and rename a .vpdf file?

Simply changing the filename does not remove DRM protection.

For example:

book.vpdf

could be renamed to:

newbook.vpdf

But changing the filename does not turn the protected document into a normal PDF.

The protected document still needs the DRM authorization required by the VeryPDF system.

Changing the file name, moving the file, or making a small change to the file size does not by itself remove the DRM protection.

7. What about copying an old version of the book?

This is a more realistic concern for digital publishers.

For example:

  1. You publish Book-A.vpdf.
  2. Your website sells it for several months.
  3. You temporarily stop sales.
  4. You correct some text.
  5. You upload a new version.
  6. Someone still has the old protected file.

The old .vpdf file does not automatically become an independent normal PDF just because somebody saved a copy.

The DRM protection remains important here.

However, you should also control access to old versions and use expiration, user restrictions, and access records where appropriate.

8. How to protect multiple reading links for one customer

Some digital book websites have a special sales model.

For example, one customer may buy four books and receive four reading links.

The website may create four different DRM identities:

customer+book1@example.com
customer+book2@example.com
customer+book3@example.com
customer+book4@example.com

The important point is that the website’s sales program decides that these four identities belong to one order.

VeryPDF can record the DRM users and their reading activity, but the commercial relationship between:

Order → Number of books → Number of links

is normally maintained by your website.

A good database structure is:

Order ID Customer Books DRM Accounts Payment
10001 user@example.com 1 1 Paid
10002 user@example.com 4 4 Paid
10003 another@example.com 2 2 Paid

This makes it much easier to compare your payment records with your DRM records.

9. Keep independent sales records

If you are worried that your website statistics may not be correct, do not rely on only one database.

Keep at least three sources of information:

Source What it tells you
Payment provider Who actually paid
Your website Which orders and links were created
VeryPDF DRM Which DRM users and documents were accessed

You can compare these numbers regularly.

For example:

Payment records:       100 paid orders
Website orders:        100 orders
VeryPDF DRM accounts:  100 accounts

If the numbers suddenly become:

Payment records:       100
Website orders:        100
VeryPDF accounts:      125

then something needs to be investigated.

The difference does not automatically mean fraud, because your website may intentionally create additional accounts or test accounts. But the difference gives you a reason to check the records.

10. Use Order IDs to connect payment and DRM records

One of the best improvements is to give every purchase a unique Order ID.

For example:

Order ID: 20260825-00125
Customer: customer@example.com
Books: 2
Payment: Paid
DRM User 1: customer+book1@example.com
DRM User 2: customer+book2@example.com

Now you can follow the complete process:

Customer
   ↓
Payment
   ↓
Order ID
   ↓
DRM User
   ↓
Reading Link
   ↓
VeryPDF DRM Reader
   ↓
Reading Activity

This is much easier to audit than simply counting links.

11. Monitor VeryPDF DRM Activity

A secure DRM system should not only protect the file. It should also record access activity.

VeryPDF DRM can record DRM activity such as user information, access time, IP address, and other available activity data.

This can help you find unusual behavior.

For example:

  • One account is accessed from many locations.
  • An account is accessed repeatedly from unexpected IP addresses.
  • A protected book suddenly receives many access attempts.
  • A customer account is being used in an unusual way.

These records do not automatically prove that somebody is stealing your book, but they give you useful information for investigation.

12. Use several security layers instead of one

There is no need to depend on one security feature.

A better approach is to use several layers:

Security layer Purpose
VeryPDF DRM protection Protect the document
Server IP restriction Protect the .vpdf file
DRM API IP restriction Protect API operations
User accounts Control customers
Reading links Control document access
Dynamic watermark Identify the customer
Expiration date Stop access after a certain time
Activity logs Investigate suspicious access
Payment records Verify real sales
Order IDs Connect payment and DRM data

If one layer has a problem, the other layers still provide protection.

13. Dynamic watermarks help identify shared documents

Dynamic watermarking is especially useful for paid digital books.

For example, the reader may see information such as:

Customer Name
customer@example.com

on the document.

If a protected book appears somewhere else, the watermark may help identify which customer originally received that copy.

This can discourage customers from sharing their reading access.

14. What if someone redirects customers to another website?

This is a different problem from stealing the .vpdf file.

Suppose your advertisement sends customers to:

yourwebsite.com

but somebody creates:

fakewebsite.com

and tries to sell the same book.

The fake website would still need to provide customers with a working protected reading experience.

If it tries to use your VeryPDF DRM API from an unauthorized server, the Allowed IP Rules can block those API requests.

This is why protecting the API is just as important as protecting the .vpdf file.

15. Recommended security setup for a digital book website

For a website selling DRM-protected books, I recommend this setup:

                     Customer
                        |
                        v
                Your Official Website
                        |
                  Payment System
                        |
                     Order ID
                        |
                        v
                Your Website Server
                        |
                  VeryPDF DRM API
                        |
                        v
                 VeryPDF DRM System
                        |
                        v
                  Protected Book
                    (.vpdf)
                        |
                        v
              Your Protected Server

At the same time:

Other Server
     |
     +---- DRM API → BLOCKED
     |
     +---- .vpdf → BLOCKED

This gives you control over both the file and the DRM API.

16. VeryPDF DRM Protector for secure digital content

If you sell paid PDF books, training courses, certification materials, or other valuable digital documents, VeryPDF DRM Protector can provide the DRM layer for your website.

It is designed for cases where you need more than simple PDF password protection.

Depending on your setup, you can use features such as:

  • Protected .vpdf files
  • Secure online document viewing
  • Dynamic watermarks
  • User-based access control
  • Device restrictions
  • Expiration dates
  • Reading activity tracking
  • Printing and copying controls
  • API-based user management

The best setup is not just “encrypt the PDF.”

It is:

Protect the file + protect the API + control users + protect the server + keep independent sales records.

That approach makes it much harder for an unauthorized person to copy your digital book business.

Frequently Asked Questions

1. Can someone rename a .vpdf file and remove the DRM?

No. Renaming the file does not remove its DRM protection.

2. Can I stop people from directly accessing my .vpdf file?

Yes. Your hosting company can configure IP-based access restrictions so that only the authorized VeryPDF server can access the file.

3. What IP address should be allowed for the VeryPDF server?

For the setup described here, the IP address is 173.255.248.140.

4. Can I block all other IP addresses?

Yes, your hosting provider can configure the server to allow the VeryPDF server and deny other IP addresses.

5. What happens if someone copies my website?

Copying the website code does not automatically give the copied website access to your VeryPDF DRM API.

You should use Allowed IP Rules to allow API requests only from your real website server.

6. Can someone use my VeryPDF API from another server?

If the API is restricted to your authorized server IP, requests from another server can be rejected.

7. Can VeryPDF know how many books my customer purchased?

VeryPDF can know the DRM users created through the API, but the number of books in a commercial order is normally controlled by your website’s sales system.

8. Can one customer have several DRM accounts?

Yes. Your website can create multiple DRM identities when a customer purchases multiple books or reading links.

9. How can I check whether my sales statistics are correct?

Compare your payment records, website order records, and VeryPDF DRM user/activity records.

10. Why should I use an Order ID?

An Order ID connects the payment, customer, book, DRM account, and reading link. It makes your sales system much easier to check.

11. Can dynamic watermarks help stop sharing?

Yes. A personalized watermark can make unauthorized sharing easier to trace and can discourage customers from sharing protected content.

12. Can I track who opened my protected book?

VeryPDF DRM can record DRM activity, including available user, time, IP, and access information.

13. Does DRM stop someone from copying the original .vpdf file?

DRM does not necessarily stop someone from copying the file itself. The important point is that copying the protected file does not by itself give the person the authorization needed to use the protected content normally.

14. Should I protect both the file and the API?

Yes. This is strongly recommended. Protecting only the .vpdf file leaves your API as another possible security risk.

15. Is PDF password protection enough for a paid digital book?

Usually, no. A PDF password can be shared with other people. A DRM system can provide user-based access control, expiration, watermarking, and activity tracking.

16. What is the best basic security setup?

For a paid digital book website, start with these four measures:

  1. Protect the book with VeryPDF DRM Protector.
  2. Allow .vpdf access only from the authorized VeryPDF server.
  3. Allow DRM API requests only from your own website server.
  4. Keep payment, order, DRM user, and reading activity records separately.

This gives you much better control over both your digital files and your online sales system.