chmod 640: owner writes, group reads, others see nothing
Runs in your browser — nothing you paste leaves this page. How we prove that
chmod calculator playground
The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.
Results update as you type — press Enter to run now.
`chmod 640 file` sets `rw-r-----`: the owner can edit the file, its group can read it, and other accounts cannot open it at all.
What chmod 640 means
In 640 the first digit is the owner, the second the group and the third everyone else: the owner gets read and write, the group gets read only, and others get no access at all.
ls -l shows -rw-r-----. Compared with 644 the final digit drops to 0, so the file stops being world-readable while the group keeps read access.
Where 640 is used
On Debian and Ubuntu, /etc/shadow is 640 owned by root:shadow: only root can change the password hashes, and only programs in the shadow group can read them. Many log files under /var/log follow the same pattern with the adm group, so administrators can read logs without root.
For applications, 640 is the standard way to give a service a secret without making it world-readable: the deploy user owns the file, the service's group reads it, for example chown deploy:www-data .env && chmod 640 .env.
Pitfalls
The group must be specific. A file at 640 in a broad group like users is readable by most of the machine. Also remember that the directory path must be traversable by the group — a 640 file inside a 700 directory is unreachable for the service no matter what its own mode says. 750 is the usual parent.
Some programs check modes themselves and reject group-readable secrets; SSH private keys and PostgreSQL's ~/.pgpass both want 600. Use 640 only where the consuming program accepts it.
Related values
640 is the middle of a three-step ladder for secrets: 644 is readable by every account, 640 by the owner and one group, 600 by the owner alone. Pick the narrowest the consuming program accepts. The directory mode that pairs with 640 files is 750; 700 would block the group, 755 would let others list file names even though they cannot read the files themselves.
FAQ
Questions, answered.
Tap a question to expand the answer.
What is the difference between 640 and 600?
600 lets only the owner read; 640 also lets the file's group read. Use 640 when a service running in a different account needs read access through a shared group.
Why can my service still not read a 640 file?
Check three things: the file's group matches a group the service account belongs to, the service was restarted after the group change, and every parent directory grants that group execute.
More free, private DevOps tools.
The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Utilities
Read more about this
- chown command in Linux: change file owner and group The chown command in Linux explained: user:group syntax, chown -R and symlinks, --reference, chgrp, chmod vs chown, and fixing Docker volume permission errors with numeric IDs.
- chmod command in Linux: syntax, examples and common mistakes The chmod command in Linux explained: octal and symbolic modes, chmod +x, chmod -R and its traps, setuid, setgid and sticky bits, umask, and how to fix Permission denied.
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.
Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.