Controlling Deno File System Access with Permission Flags
Learn how to grant Deno scripts precise file‑system access with --allow-read and --allow-write flags, see a concrete example, and understand the limits and common mistakes.
24 Dec 2025, 21:56 UTC

Granting Deno File System Access
Deno runs every script in a secure sandbox. By default the script cannot read, write, or execute anything outside of its own memory. To let a Deno program touch the file system you must explicitly grant permission with command‑line flags. The flags are evaluated once when the process starts; there is no API to add or remove permissions while the script is running.
Worked Example
Suppose you have a simple script script.ts that reads a file, modifies its content, and writes the result to another file:
// script.ts
import { readTextFile, writeTextFile } from "https://deno.land/std@0.224.0/fs/mod.ts";
async function main() {
const input = await readTextFile("/tmp/hello.txt");
const output = input.toUpperCase();
await writeTextFile("/tmp/out.txt", output);
console.log("Done");
}
main();
To allow this script to read from /tmp and write to the same directory, run Deno with the following flags:
# Run from a terminal where you have execute permission on the deno binary
denorun --allow-read=/tmp --allow-write=/tmp script.ts
If the files /tmp/hello.txt exists and contains hello, the script will create /tmp/out.txt containing HELLO and print "Done". No further configuration is needed.
Limits and Common Pitfalls
- Path‑specific grants –
--allow-read=/tmponly permits access to paths that start with/tmp. A relative path like../etc/passwdthat resolves outside the allowed directory will still be denied. - Blank flags give full access – Omitting the path, e.g.
--allow-read, grants read access to the entire filesystem. This is rarely what you want in production. - No runtime changes – Once the process starts, you cannot add or remove permissions via environment variables,
Deno.permissionsAPI, or by editing the flag string. You must restart the script with a new set of flags. - Mixing flags can widen scope unintentionally – Using
--allow-alltogether with specific flags does not narrow the permission set; the all‑access flag overrides the specifics. - Forgotten flags lead to
PermissionDenied– Running the script without the appropriate flag throws an error like:
error: Uncaught PermissionDenied: read access to "/tmp/hello.txt", run again with the --allow-read flag
To avoid this, always verify that the flag matches the exact directory tree you intend to expose.
Verifying the Setup
- Create a test file:
echo 'hello' > /tmp/hello.txt - Run the script with the flags as shown above.
- Check the output:
cat /tmp/out.txtshould displayHELLO. - Run the same command without
--allow-reador--allow-writeand observe thePermissionDeniederror.
If the script succeeds only when the flags are present, you have confirmed that Deno’s permission system is working as expected.
When to Use This Approach
Use explicit --allow-read and --allow-write flags in CI pipelines, local development, or any scenario where you want to limit a Deno program to a known subset of the filesystem. Avoid --allow-all in production unless you intentionally need full access and have other safeguards in place.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.