Developer utilities
chmod calculator.
Tick the permission boxes, type an octal mode like 755, or paste a string like rwxr-xr-x. All three stay in sync, with the matching chmod command and a plain warning when a mode is risky.
Set permissions
| Who | Read (4) | Write (2) | Execute (1) |
|---|---|---|---|
| Owner (u) | |||
| Group (g) | |||
| Other (o) |
| Special bit | Set |
|---|---|
| Setuid (4000) | |
| Setgid (2000) | |
| Sticky (1000) |
Result
chmod 644 file
-rw-r--r--
Try a symbolic change
Worked example: chmod 754
7 = 4+2+1 gives the owner read, write and execute (rwx). 5 = 4+1 gives the group read and execute (r-x). 4 gives other read only (r--). The string is rwxr-xr--. Add the setuid bit by prefixing a fourth digit: 4754 shows as rwsr-xr--, because the owner execute position becomes s. If the execute bit under a special bit is off, the letter is uppercase (S or T), meaning the special bit is set but execute is not.
Symbolic operations
A symbolic mode is who (u owner, g group, o other, a all), an operator and permissions. + adds, - removes, = sets exactly. So u+x adds execute for the owner, a-w removes write for everyone, and go=rX gives group and other exactly read, plus execute only for directories or files that already have an execute bit. Clauses join with commas: u=rwx,go=rx is 755. = with a who letter clears that who’s rwx bits first; = with no who clears every mode bit, including the special ones. A permission letter u, g or o copies that class’s current bits, so g=u makes group match owner.
Questions
What does chmod 755 mean?
Owner read, write and execute; group and other read and execute (rwxr-xr-x). It is the usual mode for programs and directories.
What is the difference between 644 and 600?
644 (rw-r--r--) lets everyone read the file. 600 (rw-------) keeps it to the owner, which SSH requires for private keys.
Why avoid 777?
It lets every local user and process rewrite or replace the file. Use the narrowest mode that works, and fix ownership with chown or group membership rather than opening a file to everyone.
What do 4000, 2000 and 1000 do?
Setuid (4000) and setgid (2000) run a program with its owner’s or group’s identity. Sticky (1000) on a directory limits deletion and renaming to the entry’s owner, as on /tmp.
Sources and limitations
Bit values (4000 S_ISUID, 2000 S_ISGID, 1000 S_ISVTX, and 0400 to 0001 for owner, group and other) and the symbolic grammar come from the POSIX chmod utility page, checked 2026-10-01. Details this tool cannot know: with no who letter, real chmod subtracts your shell’s umask, whereas this calculator assumes umask 000; whether setuid or setgid are honoured on non-executable files, directories or certain filesystems is implementation-defined; and the sticky bit on non-directories is unspecified by POSIX. Linux, macOS and BSD also support extras such as ACLs and file flags that chmod modes do not show. Nothing leaves your browser.