Chmod Calculator
Calculate Linux file permissions with an interactive chmod calculator. Convert between numeric (755) and symbolic (rwxr-xr-x) notation. Free online tool.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Common Permissions
| Numeric | Symbolic | Use Case |
|---|---|---|
755 | rwxr-xr-x | Directories, executable scripts, web server root |
644 | rw-r—r— | Regular files, HTML/CSS, config files |
600 | rw------- | Private files (SSH keys, .env) |
700 | rwx------ | Private directories, ~/.ssh |
777 | rwxrwxrwx | World-writable (avoid in production) |
444 | r—r—r— | Read-only for everyone |
750 | rwxr-x--- | Owner full, group read/execute, others none |
664 | rw-rw-r— | Shared files where group members can edit |
Worked Examples
Setting up a web server file
Your web server serves static HTML. The web server process (running as www-data) only needs to read the files, while you as the owner need to edit them:
chmod 644 index.html # Owner: read+write, Group/Others: read
This gives you rw-r—r— — you can edit, the server can read, and no one can execute the file.
Making a script executable
You’ve written a deployment script and need to run it. Others on the team should be able to run it too but not modify it:
chmod 755 deploy.sh # Owner: full, Group/Others: read+execute
This gives you rwxr-xr-x. Now you can run ./deploy.sh directly.
Protecting SSH keys
SSH refuses to use a private key if its permissions are too open. Lock it down to owner-only:
chmod 600 ~/.ssh/id_rsa # Owner: read+write, no one else
Result: rw-------. OpenSSH refuses a private key that group or others have any access to; 600, 400 and 700 all pass.
Special Bits: Setuid, Setgid and Sticky
The optional first digit adds 4 for setuid, 2 for setgid and 1 for the sticky bit. In the mode string they replace the
execute position: s when execute is also set, S when it is not (for others, t and
T). These are real values from a Debian system with GNU coreutils 9.1, and the tool gives the same strings:
| Path | ls -l | Numeric | Symbolic cmd from the tool |
|---|---|---|---|
/tmp | drwxrwxrwt | 1777 | chmod u=rwx,g=rwx,o=rwx,+t |
/usr/bin/passwd | -rwsr-xr-x | 4755 | chmod u=rwxs,g=rx,o=rx |
| a team directory | drwxrwsr-x | 2775 | chmod u=rwx,g=rwxs,o=rx |
The sticky bit on /tmp lets everyone create files but only the owner delete them. Setuid on passwd
makes it run as its owner (root) so users can change their own password. Setgid on a directory makes new files take the
directory’s group; on Linux a new subdirectory inherits the setgid bit too, so a shared project folder stays shared.
The sticky bit is written as a separate +t because BSD and macOS chmod ignore o+t;
+t works on both. The symbolic commands for all eight combinations of special bits were run through GNU and macOS chmod to confirm the resulting mode.
Limits and Gotchas
- Absolute modes only. The tool outputs the full mode (
u=…,g=…,o=…). It does not build relative changes such aschmod g+wora-x, and it does not showX(execute only for directories). chmod 755does not clear setgid on a directory with GNU chmod. The coreutils manual says the setuid and setgid bits of a directory are kept unless you clear them explicitly. On GNU coreutils 9.1, a2755directory stays2755afterchmod 755;chmod 00755orchmod g-sclears it. The same applies to theu=…,g=…command.- Numeric input needs 3 or 4 digits from 0 to 7. Spaces at the ends and a
0oprefix, as in Python’s0o644, are ignored. Any other character, such as the 8 in7558, fewer than 3 digits or more than 4 shows “Invalid octal” and keeps the last valid result. - The find command matches exactly.
find . -type f -perm 0644lists files whose mode is exactly 644. To find files that have at least those bits, use-perm -644; to find files with any of them,-perm /644(GNU find). - Permissions are only part of access. ACLs (the
+after the mode inls -l), SELinux, mount options such asnoexec, and the permissions of every parent directory can still deny access.
Why New Files Get 644 and 755
Programs usually create files with mode 666 and directories with 777, and the kernel removes the bits set in the
umask. With the common umask 022, a new file becomes 644 and a new directory
755; with 077, a file becomes 600. If files keep coming out with the wrong mode, check
umask before running chmod on them one by one. For private keys, OpenSSH refuses a key that group or
others have any access to (“Permissions 0644 … are too open”), so use 600 or 400.
FAQ
What is chmod?
chmod (change mode) is a Unix/Linux command that sets file and directory permissions. It controls who can read, write, or execute a file. Permissions are assigned to three classes: the file owner, the group, and all other users.
What do the chmod numbers mean?
Each digit represents a permission class (owner, group, others). The digit is the sum of: 4 (read), 2 (write), and 1 (execute). For example, 7 = 4+2+1 (read+write+execute), 5 = 4+1 (read+execute), 0 = no permissions.
What are common chmod values like 755 and 644?
755 (rwxr-xr-x) is standard for directories and executable scripts — owner has full access, others can read and execute. 644 (rw-r--r--) is standard for regular files — owner can read/write, others can only read. 600 (rw-------) is used for private files like SSH keys.
What does a fourth digit such as 4755 or 1777 mean?
The leading digit adds the special bits: 4 for setuid, 2 for setgid and 1 for the sticky bit, so 4755 is 755 plus setuid and 1777 is 777 plus the sticky bit. In the mode string they replace the execute letter: s or t when execute is also set, S or T when it is not (4755 is rwsr-xr-x). Open Special Bits to set them, or type the four digits. On a directory, GNU chmod 755 keeps an existing setgid bit; use 00755 or g-s to clear it.
What permissions does WordPress recommend on shared hosting?
WordPress's Changing File Permissions page says that on shared hosting with suexec, where PHP runs as the file owner, all directories should be 755 or 750, all files 644 or 640, and wp-config.php 440 or 400 so that other users on the server cannot read it. It also says no directory should ever be 777, upload directories included. Type each number into Numeric to see the mode string and the commands.
Is the mode I enter sent or saved anywhere?
No. The calculation runs in your browser tab; the permissions, numbers and mode strings you enter are not sent to a server and are not saved in browser storage. The page's analytics records a usage event with the tool name and the action (a checkbox, a special bit, or a committed numeric or symbolic entry), not the mode itself.