chmod 644: the default mode for regular files
Runs in your browser — nothing you paste leaves this page. How we prove that
chmod calculator playground
The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.
Results update as you type — press Enter to run now.
`chmod 644 file` sets `rw-r--r--`: the owner can edit the file and everyone else can read it, with no execute bit for anyone. It is what most ordinary files are.
What chmod 644 means
In 644 the first digit is the owner, the second the group and the third everyone else: the owner gets read and write, the group gets read only, and others get read only.
ls -l shows -rw-r--r--. The 6 is read plus write and each 4 is read alone. New files come out as 644 under the common 022 umask, so it is the mode you will see on most documents, source files, images and configuration.
Typical 644 files
/etc/passwd, /etc/hosts and most of /etc are 644, owned by root: every program can read them, only root can change them. Static web content — HTML, CSS, JavaScript, images, and PHP source — is conventionally 644, paired with 755 directories, so the server can read but not rewrite the site.
Public SSH keys (id_ed25519.pub) can be 644; only the private half needs to be locked down.
Pitfalls
644 is world-readable. An .env file, a database password in config.php, or a private key at 644 can be read by every account on the host, and ssh refuses a private key with this mode outright. Use 600 for those, or 640 if a service group must read them.
A script at 644 cannot be run as ./script; add execute with chmod +x or set 755. And never use chmod -R 644 on a directory tree: directories lose execute and nobody, including the owner, can enter them. Use find dir -type f -exec chmod 644 {} + instead.
Related values
644 has close relatives for each audience. 640 hides the file from everyone outside the group, 600 from everyone but the owner. 664 lets the group edit as well as read. 444 removes the owner's write and makes the file read-only for all. For directories and executables the parallel mode is 755: the same shape, with execute added so the directory can be entered or the program run.
FAQ
Questions, answered.
Tap a question to expand the answer.
Should a config file be 644 or 600?
It depends on what is in it. A config with no secrets can be 644 so tools and other users can read it. One holding passwords, API keys or tokens should be 600, or 640 with a group the service runs in.
Why can I not cd into a directory after chmod -R 644?
Directories need the execute bit to be traversed, and 644 has none. Restore it with find dir -type d -exec chmod 755 {} + and keep 644 for files only.
More free, private DevOps tools.
The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Utilities
Read more about this
- chown command in Linux: change file owner and group The chown command in Linux explained: user:group syntax, chown -R and symlinks, --reference, chgrp, chmod vs chown, and fixing Docker volume permission errors with numeric IDs.
- chmod command in Linux: syntax, examples and common mistakes The chmod command in Linux explained: octal and symbolic modes, chmod +x, chmod -R and its traps, setuid, setgid and sticky bits, umask, and how to fix Permission denied.
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.
Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.