Skip to content

chmod 750: owner full access, group read-only, others locked out

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 750 · rwxr-x--- · file
Output
Octal750
Symbolicrwxr-x---
ls -l-rwxr-x---
Commandchmod 750 file

`chmod 750 file` sets `rwxr-x---`: the owner has full control, members of the file's group can read and enter it, and every other account is shut out.

What chmod 750 means

In 750 the first digit is the owner, the second the group and the third everyone else: the owner gets read, write and execute, the group gets read and execute, and others get no access at all.

ls -l shows -rwxr-x---. The trailing 0 is what sets it apart from 755: the "everyone else" class has no bits, so an unrelated account cannot list the directory, cannot traverse into it, and cannot read a file by its full path even if that file's own mode is world-readable.

Typical uses

750 fits a directory owned by a deploy user and read by a service group. A common layout is chown -R deploy:www-data /srv/app with directories at 750 and files at 640, so the web server can read the code but not change it, and other local users see nothing.

Home directories on multi-user hosts are another case. Several distributions now create homes at 750 or 700 rather than the older 755, so one user cannot browse another's files by default.

Pitfalls

The group is the whole design, so check it. If the directory's group is the owner's personal group, 750 behaves like 700 for everyone else. Use ls -ld to confirm the group, and id <user> to confirm the service account is actually a member; group changes only apply to new login sessions or restarted services.

Because others lose traverse permission, a 750 directory hides everything beneath it, regardless of the children's modes. That is useful, but it also breaks things that expected to reach a path inside, such as a static file server running as a user outside the group.

Related values

750 is 755 with the world removed. Its file counterpart is 640, which keeps the same owner-group-nobody shape without execute. If the group does not need to see the contents either, step down to 700. If the files inside only need the owner, pair the 750 directory with 600 files. A group that also needs to create files wants 770, usually with the setgid bit so new entries keep the group.

FAQ

Questions, answered.

Tap a question to expand the answer.

Whenever accounts outside the owner and one group should not be able to read the contents. 755 lets every local user list and read; 750 limits that to the group. On a single-purpose server the difference is small, on a shared host it matters.

Usually 640: the owner reads and writes, the group reads, others get nothing. Use 750 on files only if group members need to execute them, such as scripts the service runs.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.