Chmod Calculator

Calculate Linux file permissions with an interactive chmod calculator. Convert between numeric (755) and symbolic (rwxr-xr-x) notation. Free online tool.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Special Bits
Open Special Bits to add Setuid (4), Setgid (2) or Sticky (1) as the leading octal digit. They use s or t when execute is also set, and S or T when it is not.
Enter three or four octal digits, using 0–7, such as 644 or 2775. Complete input updates the checkboxes and commands. An incomplete entry shows an error and keeps the last valid result.
Enter a nine-character mode such as rwxr-xr-x, including s/S and t/T for special bits. You can paste ls -l forms such as drwxrwxrwt or -rw-r--r--@; the file type and trailing marker are removed.
Permissions Toggle Read, Write and Execute for Owner, Group and Others. Numeric and symbolic values and all three commands update immediately. Ctrl/⌘+L inside the tool clears every permission, field and result.
Read
Write
Execute
Owner
Group
Others
Command Copy the numeric value, symbolic mode or a command. Replace filename with your path. Symbolic cmd includes special bits; Sticky uses a separate +t, which works on both GNU and macOS chmod.
chmod 755 filename
Symbolic cmd
chmod u=rwx,g=rx,o=rx filename
find -perm
find . -type f -perm 0755
Read the full guide chmod 755 Explained: Octal Modes, Directories, umask and Special Bits
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Common Permissions

NumericSymbolicUse Case
755rwxr-xr-xDirectories, executable scripts, web server root
644rw-r—r—Regular files, HTML/CSS, config files
600rw-------Private files (SSH keys, .env)
700rwx------Private directories, ~/.ssh
777rwxrwxrwxWorld-writable (avoid in production)
444r—r—r—Read-only for everyone
750rwxr-x---Owner full, group read/execute, others none
664rw-rw-r—Shared files where group members can edit

Worked Examples

Setting up a web server file

Your web server serves static HTML. The web server process (running as www-data) only needs to read the files, while you as the owner need to edit them:

chmod 644 index.html   # Owner: read+write, Group/Others: read

This gives you rw-r—r— — you can edit, the server can read, and no one can execute the file.

Making a script executable

You’ve written a deployment script and need to run it. Others on the team should be able to run it too but not modify it:

chmod 755 deploy.sh    # Owner: full, Group/Others: read+execute

This gives you rwxr-xr-x. Now you can run ./deploy.sh directly.

Protecting SSH keys

SSH refuses to use a private key if its permissions are too open. Lock it down to owner-only:

chmod 600 ~/.ssh/id_rsa   # Owner: read+write, no one else

Result: rw-------. OpenSSH refuses a private key that group or others have any access to; 600, 400 and 700 all pass.

Special Bits: Setuid, Setgid and Sticky

The optional first digit adds 4 for setuid, 2 for setgid and 1 for the sticky bit. In the mode string they replace the execute position: s when execute is also set, S when it is not (for others, t and T). These are real values from a Debian system with GNU coreutils 9.1, and the tool gives the same strings:

Pathls -lNumericSymbolic cmd from the tool
/tmpdrwxrwxrwt1777chmod u=rwx,g=rwx,o=rwx,+t
/usr/bin/passwd-rwsr-xr-x4755chmod u=rwxs,g=rx,o=rx
a team directorydrwxrwsr-x2775chmod u=rwx,g=rwxs,o=rx

The sticky bit on /tmp lets everyone create files but only the owner delete them. Setuid on passwd makes it run as its owner (root) so users can change their own password. Setgid on a directory makes new files take the directory’s group; on Linux a new subdirectory inherits the setgid bit too, so a shared project folder stays shared. The sticky bit is written as a separate +t because BSD and macOS chmod ignore o+t; +t works on both. The symbolic commands for all eight combinations of special bits were run through GNU and macOS chmod to confirm the resulting mode.

Limits and Gotchas

  • Absolute modes only. The tool outputs the full mode (u=…,g=…,o=…). It does not build relative changes such as chmod g+w or a-x, and it does not show X (execute only for directories).
  • chmod 755 does not clear setgid on a directory with GNU chmod. The coreutils manual says the setuid and setgid bits of a directory are kept unless you clear them explicitly. On GNU coreutils 9.1, a 2755 directory stays 2755 after chmod 755; chmod 00755 or chmod g-s clears it. The same applies to the u=…,g=… command.
  • Numeric input needs 3 or 4 digits from 0 to 7. Spaces at the ends and a 0o prefix, as in Python’s 0o644, are ignored. Any other character, such as the 8 in 7558, fewer than 3 digits or more than 4 shows “Invalid octal” and keeps the last valid result.
  • The find command matches exactly. find . -type f -perm 0644 lists files whose mode is exactly 644. To find files that have at least those bits, use -perm -644; to find files with any of them, -perm /644 (GNU find).
  • Permissions are only part of access. ACLs (the + after the mode in ls -l), SELinux, mount options such as noexec, and the permissions of every parent directory can still deny access.

Why New Files Get 644 and 755

Programs usually create files with mode 666 and directories with 777, and the kernel removes the bits set in the umask. With the common umask 022, a new file becomes 644 and a new directory 755; with 077, a file becomes 600. If files keep coming out with the wrong mode, check umask before running chmod on them one by one. For private keys, OpenSSH refuses a key that group or others have any access to (“Permissions 0644 … are too open”), so use 600 or 400.

FAQ

What is chmod?

chmod (change mode) is a Unix/Linux command that sets file and directory permissions. It controls who can read, write, or execute a file. Permissions are assigned to three classes: the file owner, the group, and all other users.

What do the chmod numbers mean?

Each digit represents a permission class (owner, group, others). The digit is the sum of: 4 (read), 2 (write), and 1 (execute). For example, 7 = 4+2+1 (read+write+execute), 5 = 4+1 (read+execute), 0 = no permissions.

What are common chmod values like 755 and 644?

755 (rwxr-xr-x) is standard for directories and executable scripts — owner has full access, others can read and execute. 644 (rw-r--r--) is standard for regular files — owner can read/write, others can only read. 600 (rw-------) is used for private files like SSH keys.

What does a fourth digit such as 4755 or 1777 mean?

The leading digit adds the special bits: 4 for setuid, 2 for setgid and 1 for the sticky bit, so 4755 is 755 plus setuid and 1777 is 777 plus the sticky bit. In the mode string they replace the execute letter: s or t when execute is also set, S or T when it is not (4755 is rwsr-xr-x). Open Special Bits to set them, or type the four digits. On a directory, GNU chmod 755 keeps an existing setgid bit; use 00755 or g-s to clear it.

What permissions does WordPress recommend on shared hosting?

WordPress's Changing File Permissions page says that on shared hosting with suexec, where PHP runs as the file owner, all directories should be 755 or 750, all files 644 or 640, and wp-config.php 440 or 400 so that other users on the server cannot read it. It also says no directory should ever be 777, upload directories included. Type each number into Numeric to see the mode string and the commands.

Is the mode I enter sent or saved anywhere?

No. The calculation runs in your browser tab; the permissions, numbers and mode strings you enter are not sent to a server and are not saved in browser storage. The page's analytics records a usage event with the tool name and the action (a checkbox, a special bit, or a committed numeric or symbolic entry), not the mode itself.