Skip to content

chmod 400: read-only for the owner, nothing for anyone else

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 400 · r-------- · file
Output
Octal400
Symbolicr--------
ls -l-r--------
Commandchmod 400 file

`chmod 400 file` sets `r--------`: the owner can read the file and no other non-root account can do anything with it. Not even the owner can write to it without changing the mode first, which is what makes it the classic mode for downloaded private keys.

What chmod 400 means

In 400 the first digit is the owner, the second the group and the third everyone else: the owner gets read only, the group gets no access at all, and others get no access at all.

ls -l shows -r--------. The 4 is read alone and the two zeros remove every bit from the group and others. Compared with 600, the only change is that the owner loses write, so an accidental redirect or an editor save fails instead of silently replacing the contents.

SSH keys and AWS .pem files

The OpenSSH client refuses a private key you own if group or others have any permission bit on it, and prints "UNPROTECTED PRIVATE KEY FILE". Both 400 and 600 satisfy that check, because the rule is about the group and other digits, not the owner's write bit. AWS's EC2 instructions use chmod 400 key.pem for the key pair you download, which is why so many guides repeat that number.

Choose 400 for a key that should never change once written, and 600 when a tool needs to rewrite the file in place, for example a credentials file a CLI refreshes. Either is a correct answer for an SSH key.

Other secrets that suit 400

TLS private keys, API tokens written once by a provisioning script, and recovery codes are all good candidates. Configuration-management tools often deploy them at 400 owned by the service account, so the service can read the secret but a bug in it cannot overwrite it.

Limits and pitfalls

400 is not a lock. The owner can run chmod u+w at any time, root ignores the bits, and rm only needs write on the directory, so the file can still be deleted. A key copied with scp or extracted from an archive may arrive at 644, so check the mode after moving it. If a service in another account must read the secret, 400 is too strict; use 440 or 640 with a shared group rather than making it world-readable.

FAQ

Questions, answered.

Tap a question to expand the answer.

Both work: ssh only rejects keys that group or others can access. 400 adds protection against accidental overwrites; 600 is more convenient if you ever need to edit or replace the file in place.

There is no write bit, even for the owner. Run chmod u+w on it, make the change, then chmod 400 again, or edit it as a 600 file if it changes often.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.