chmod 600: owner-only read and write for private keys and secrets
Runs in your browser — nothing you paste leaves this page. How we prove that
chmod calculator playground
The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.
Results update as you type — press Enter to run now.
`chmod 600 file` sets `rw-------`: the owner can read and write the file, and no other non-root account can open it. It is the mode for private keys, credentials and anything else that should stay with one user.
What chmod 600 means
In 600 the first digit is the owner, the second the group and the third everyone else: the owner gets read and write, the group gets no access at all, and others get no access at all.
ls -l shows -rw-------. There is no execute bit anywhere, so 600 is for data files; directories need 700, and private scripts too.
SSH keys and other files that require it
The OpenSSH client checks the mode of a private key and refuses to use one that group or others can read, printing "WARNING: UNPROTECTED PRIVATE KEY FILE!". chmod 600 ~/.ssh/id_ed25519 fixes it. On the server, authorized_keys is conventionally 600 too.
Other tools enforce the same rule: libpq ignores a ~/.pgpass that is group- or world-accessible, and many CLI credential files (~/.netrc, cloud provider credential files, .env) should be 600 even where nothing checks.
Pitfalls
Mode bits do not protect against root, backups or a copy to another machine: a key copied with scp or unpacked from an archive can arrive at 644, so recheck after moving it. Containers are a common case — a secret mounted into a container may need its owner set to the container's user, or the process cannot read a 600 file at all.
If a separate service account must read the file, 600 is too strict; use 640 with a shared group rather than widening it to 644.
Related values
600 is the tightest mode that still lets the owner edit. 640 relaxes it for one group, 644 for everyone. 400 (not covered here) removes the owner's write as well, which some tools such as cloud key downloads set by default, and which ssh also accepts. For directories holding these files, use 700: 600 on a directory would leave out the execute bit the owner needs to enter it.
FAQ
Questions, answered.
Tap a question to expand the answer.
Why does ssh say my private key permissions are too open?
The key file is readable by group or others, typically 644. ssh refuses such keys. Run chmod 600 on the key, and make sure you own the file.
Should .env files be 600?
Yes, if only the owner reads them. If a web server or app runs as a different account, make the file 640 and give it that account's group, so it is still not world-readable.
More free, private DevOps tools.
The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Utilities
Read more about this
- chown command in Linux: change file owner and group The chown command in Linux explained: user:group syntax, chown -R and symlinks, --reference, chgrp, chmod vs chown, and fixing Docker volume permission errors with numeric IDs.
- chmod command in Linux: syntax, examples and common mistakes The chmod command in Linux explained: octal and symbolic modes, chmod +x, chmod -R and its traps, setuid, setgid and sticky bits, umask, and how to fix Permission denied.
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.
Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.