umask Set default permissions for new files
Controls which permissions are taken away from new files and folders when they are created. The mask is a number: the permissions it contains are removed from the starting point. It is a shell built-in, so it affects only the current shell and the programs it starts.
Synopsis
umask [-S] [mask]
Common options
| Option or form | What it does |
|---|---|
-S | Show the current mask in symbolic form, as the permissions that are allowed (for example u=rwx,g=rx,o=rx) |
-p | Print the mask as a command you can reuse. Works in bash |
022 | The usual default. New files get 644 (rw-r--r--) and new folders get 755 (rwxr-xr-x) |
027 | Group can read, others get nothing. New files get 640 and new folders get 750 |
077 | Only the owner gets access. New files get 600 and new folders get 700 |
002 | Shared group work. New files get 664 and new folders get 775 |
Examples
umask
umask -S
(umask 077; touch private.txt; ls -l private.txt)
(umask 022; touch normal.txt; ls -l normal.txt)
(umask 077; mkdir secret; ls -ld secret)
echo 'umask 027' >> ~/.zshrc
Notes
- The mask removes permissions, it does not add them. New files start from 666 (no execute) and new folders from 777, then the mask is taken away. A file therefore never becomes executable from umask alone.
- A bare umask changes your current shell, and the change disappears when the shell ends. Wrapping it in parentheses, as in (umask 077; command), limits the change to that one line.
- To keep a mask, put the umask line in your shell startup file, such as ~/.zshrc or ~/.bashrc. Choose it before you create sensitive files, because changing it later does not alter files that already exist. Use chmod for those.
- On macOS the default mask is 022. Your own system may differ, so run umask to check.
See also
Last reviewed 2026-10-07.