Most online PDF mergers upload your file to a server. For sensitive documents, that's a problem.
Approach
Use pdf-lib in the browser:
- Read files with
File.arrayBuffer() -
PDFDocument.load()each source -
copyPages()into a newPDFDocument -
save()and download via a Blob URL
The PDF never needs to leave the user's device for this flow.
Verify privacy
Open DevTools → Network, merge a test PDF, and confirm there's no upload request carrying the file body. After the app loads, you can even try offline.
Try it
I packaged this (merge, split, and more) in PDFCraftify:
- Merge tool: https://pdfcraftify.com/merge-pdf
- Guide: https://pdfcraftify.com/guides/merge-pdf-without-uploading
Tradeoffs
- Browser memory limits very large jobs
- Password-protected PDFs must be unlocked first
- Not a replacement for full desktop DTP
If you build similar tools, what edge cases bite you most? Comments welcome.
Top comments (1)
I'd separate "the output opens" from "the document survived the merge". A useful fixture pair would have identical form field names in both sources, plus an internal link from page 1 to page 2 in the second source. After adding the first source ahead of it, check the form behavior and where that link lands, not just the page count.
If the page-copy flow intentionally drops forms, bookmarks or document-level attachments, a visible warning before download would be better than silently producing a readable but incomplete result. I haven't tested PDFCraftify; these are suggested preservation checks for the copyPages flow described here.