Skip to content

chmod 640: owner writes, group reads, others see nothing

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 640 · rw-r----- · file
Output
Octal640
Symbolicrw-r-----
ls -l-rw-r-----
Commandchmod 640 file

`chmod 640 file` sets `rw-r-----`: the owner can edit the file, its group can read it, and other accounts cannot open it at all.

What chmod 640 means

In 640 the first digit is the owner, the second the group and the third everyone else: the owner gets read and write, the group gets read only, and others get no access at all.

ls -l shows -rw-r-----. Compared with 644 the final digit drops to 0, so the file stops being world-readable while the group keeps read access.

Where 640 is used

On Debian and Ubuntu, /etc/shadow is 640 owned by root:shadow: only root can change the password hashes, and only programs in the shadow group can read them. Many log files under /var/log follow the same pattern with the adm group, so administrators can read logs without root.

For applications, 640 is the standard way to give a service a secret without making it world-readable: the deploy user owns the file, the service's group reads it, for example chown deploy:www-data .env && chmod 640 .env.

Pitfalls

The group must be specific. A file at 640 in a broad group like users is readable by most of the machine. Also remember that the directory path must be traversable by the group — a 640 file inside a 700 directory is unreachable for the service no matter what its own mode says. 750 is the usual parent.

Some programs check modes themselves and reject group-readable secrets; SSH private keys and PostgreSQL's ~/.pgpass both want 600. Use 640 only where the consuming program accepts it.

Related values

640 is the middle of a three-step ladder for secrets: 644 is readable by every account, 640 by the owner and one group, 600 by the owner alone. Pick the narrowest the consuming program accepts. The directory mode that pairs with 640 files is 750; 700 would block the group, 755 would let others list file names even though they cannot read the files themselves.

FAQ

Questions, answered.

Tap a question to expand the answer.

600 lets only the owner read; 640 also lets the file's group read. Use 640 when a service running in a different account needs read access through a shared group.

Check three things: the file's group matches a group the service account belongs to, the service was restarted after the group change, and every parent directory grants that group execute.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.