Is anything sent to a server?
No. The calculation runs in your browser; the modes you enter are not sent to a server.
Convert Unix permissions between checkboxes, octal (755) and symbolic (rwxr-xr-x), including setuid, setgid and sticky bits; parse ls -l output; get the chmod command.
Loading Chmod Calculator…
Loading Chmod Calculator…
Unix permissions are twelve bits that most people read as three digits. This calculator converts between the three ways you meet them: a checkbox matrix of read, write and execute for owner, group and others; octal numbers like 644, 0755 or 4755; and symbolic strings like rwxr-xr-x — including whole ls -l output such as drwxrwxrwt or -rwsr-xr-x. The special bits are supported both ways: setuid, setgid and sticky, with the uppercase S and T forms that appear when the execute bit underneath is off. For any mode it shows the chmod command in numeric and symbolic form, explains in plain words what the owner, group and everyone else can do — which differs between files and directories — and warns about world-writable modes, setuid binaries and combinations that have no effect. A list of common modes (600 for SSH keys, 700 for ~/.ssh, 1777 for /tmp, 2775 for team directories) explains when each is right.
Each octal digit packs three bits: read 4, write 2, execute 1. A three-digit mode is owner-group-others; a fourth leading digit carries setuid (4), setgid (2) and sticky (1). Digits 8 and 9 don't exist in octal and are rejected.
The nine-character form lists r, w and x for owner, group and others. ls -l prefixes a file type (- file, d directory, l symlink) and may append . or + for SELinux contexts and ACLs; the calculator strips those. Special bits replace the relevant x with s or t (lowercase when x is also set).
chmod accepts either the octal number or a symbolic assignment like u=rwx,g=rx,o=rx. The recursive form (-R) applies one mode to everything below a directory, which is usually wrong for mixed trees — use find with -type d and -type f to set directories and files separately.
World-writable files and directories without the sticky bit, setuid on executables, setuid without execute, and a sticky bit on a regular file are flagged, since each is either dangerous or has no effect.
Short answers for the things developers usually ask before trusting a tool.
No. The calculation runs in your browser; the modes you enter are not sent to a server.
Each digit is one class of user: owner, group, others. Each digit is the sum of read (4), write (2) and execute (1). 7 = 4+2+1 = rwx, 5 = 4+1 = r-x. So 755 is rwxr-xr-x: the owner can do everything; everyone else can read and execute. It's the usual mode for directories and scripts.
644 (rw-r--r--) has no execute bit, so it's for regular files: the owner edits, everyone reads. 755 adds execute, which programs and scripts need to run and directories need to be entered. A directory with 644 can't be opened even by its owner.
s in the owner or group execute position means setuid or setgid is set along with execute; S means it's set without execute (usually a mistake). t in the others position is the sticky bit with execute (as on /tmp, drwxrwxrwt); T is sticky without execute. They correspond to a fourth leading octal digit: 4 setuid, 2 setgid, 1 sticky — so 4755 is rwsr-xr-x.
777 lets every user on the system — including a compromised web server process — change or replace the file. It often "fixes" a permission error by hiding the real problem: the wrong owner or group. Use chown to give the right user ownership, and 755/644 (or 750/640 for group-only access).
For a directory, read lets you list the names inside, write lets you create, rename and delete entries (only together with execute), and execute lets you enter it and access files by name. That's why directories almost always have x wherever they have r.
Useful follow-ups when one conversion usually turns into three more.
Network, broadcast, host range and counts for any CIDR block, AWS/Azure/GCP reserved addresses, subnet splitting, range-to-CIDR and overlap checks. IPv4 and IPv6.
Convert one or more docker run commands into a Compose file (compose.yaml, no obsolete version key): ports, volumes, env, networks, healthchecks, GPUs and more.
Parse any cron expression into plain English and see the next 12 scheduled run times.