chmod 700: private to the owner, the mode for ~/.ssh
Runs in your browser — nothing you paste leaves this page. How we prove that
chmod calculator playground
The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.
Results update as you type — press Enter to run now.
`chmod 700 file` sets `rwx------`: the owner can read, write and execute, and no other non-root account can do anything at all. It is the standard mode for `~/.ssh` and private script directories.
What chmod 700 means
In 700 the first digit is the owner, the second the group and the third everyone else: the owner gets read, write and execute, the group gets no access at all, and others get no access at all.
ls -l shows -rwx------. On a directory, the two zeros mean other users cannot list it or traverse it, which also hides every file inside, whatever those files' own modes say.
The ~/.ssh case
OpenSSH checks permissions before trusting your keys. With the server's default StrictModes yes, sshd refuses public-key login if your home directory, ~/.ssh or authorized_keys is writable by group or others. The conventional fix is chmod 700 ~/.ssh and chmod 600 ~/.ssh/authorized_keys ~/.ssh/id_*, leaving the .pub files at 644 if you like.
The same reasoning applies to ~/.gnupg, which GnuPG warns about when it is accessible to others, and to any directory holding credentials or tokens.
Other uses and limits
700 is right for a personal script that reads secrets, and for scratch or build directories a single service account owns. Root is not restricted by these bits: an administrator, or anything running as root, can still read the contents. File modes protect users from each other, not from the machine's owner.
Do not apply 700 recursively to files that are only data; they gain an execute bit they do not need. Give directories 700 and files 600 with a find -type d / find -type f split, or chmod -R u=rwX,go= dir.
Related values
700 is the most private directory mode in this set. 750 opens it to one group, read and traverse only, which is the usual next step when a service must read the contents. 755 opens it to every account. For the files inside, 600 is the matching private mode, and 640 the group-readable one. If you find a private directory at 777, treat its contents as exposed and rotate any secrets in it.
FAQ
Questions, answered.
Tap a question to expand the answer.
Why does SSH ignore my key after I copied ~/.ssh?
Copies often arrive with looser modes, and sshd with StrictModes refuses keys when ~/.ssh or authorized_keys is group- or world-writable. Set ~/.ssh to 700 and the files inside to 600, and check that your home directory is not group-writable either.
What is the difference between 700 and 600?
700 includes execute for the owner and 600 does not. Use 700 on directories, which need execute to be entered, and on scripts; use 600 on private files that are only read and written.
More free, private DevOps tools.
The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Utilities
Read more about this
- chown command in Linux: change file owner and group The chown command in Linux explained: user:group syntax, chown -R and symlinks, --reference, chgrp, chmod vs chown, and fixing Docker volume permission errors with numeric IDs.
- chmod command in Linux: syntax, examples and common mistakes The chmod command in Linux explained: octal and symbolic modes, chmod +x, chmod -R and its traps, setuid, setgid and sticky bits, umask, and how to fix Permission denied.
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.
Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.