Skip to the tool

UUID generator

Version 4 UUIDs, cryptographically random, one at a time or a thousand in a batch, formatted the way your system wants them.

Guide

How to use it

  1. Set how many (up to 1,000) and tap Generate.
  2. Format to taste: uppercase, hyphen-less, or braced {registry style} for Windows-flavoured systems.
  3. Tap any UUID to copy it alone, or Copy all for the batch, one per line, paste-ready for a seed script.

Examples

What is inside a v4 UUID

4 IN POSITION 13

Every v4 UUID has a 4 there, the version marker, and an 8, 9, a or b starting the next group (the variant). The other 122 bits are pure randomness.

1,000 AT ONCE

Bulk generation for seeding test data. Collision odds across your thousand: effectively zero, you would need 2.7 × 10¹⁸ UUIDs for a 50% chance of one duplicate.

AS A SECRET? NO

UUIDs are unguessable but often logged, cached and exposed in URLs, treat them as identifiers, not credentials. Secrets come from the password generator with expiry and storage discipline.

Method

How it works

Generation uses crypto.randomUUID(), the browser’s built-in, spec-compliant v4 generator seeded from OS entropy, the same quality as server-side generators. Formatting options re-dress the same 128 bits, hyphens and case carry no information.

Why v4 dominates: no coordination needed, any machine can mint identifiers with no registry and no collisions in practice. Time-ordered variants (v7) help database index locality, if you need those, your database or backend library is the right place to make them.

FAQ

Frequently asked questions

Are these truly unique?

Probabilistically, yes to an absurd degree: the space is 2¹²². Duplicate risk from proper generators is dwarfed by, say, cosmic-ray bit flips in your RAM.

UUID versions, which do I want?

v4 (random, this page) for general identifiers. v7 (time-ordered) for database keys at scale. v1 leaks MAC address and time, mostly avoided now. v5 is deterministic hashing of a name.

Uppercase or lowercase?

The spec outputs lowercase and treats comparison as case-insensitive. Microsoft ecosystems traditionally display uppercase in braces, hence the options.

Can I use these as database primary keys?

Yes, ubiquitously done. At serious write volume, v7’s time-ordering is kinder to B-tree indexes, for most applications v4 is fine.

Are they safe to expose in URLs?

As identifiers, yes, being unguessable beats sequential integers (no /user/42 enumeration). Just never let unguessability substitute for authorisation checks.

Is anything logged when I generate?

No, generation is local. Nobody else has ever seen these UUIDs, which is rather the point.

More tools

Related tools

GUID generatorThe Microsoft dialect, braces and all. Password generatorFor actual secrets. Random number generatorRandomness in decimal. Hash generatorDeterministic identifiers instead.
Skip to the tool

UUID generator

Version 4 UUIDs, cryptographically random, one at a time or a thousand in a batch, formatted the way your system wants them.

Version 4 UUIDs: 122 random bits from crypto.randomUUID, the collision odds are cosmic-ray territory. Tap any one to copy it.

Generated on your device. No server ever sees or logs them.

Guide

How to use it

  1. Set how many (up to 1,000) and tap Generate.
  2. Format to taste: uppercase, hyphen-less, or braced {registry style} for Windows-flavoured systems.
  3. Tap any UUID to copy it alone, or Copy all for the batch, one per line, paste-ready for a seed script.

Examples

What is inside a v4 UUID

4 IN POSITION 13

Every v4 UUID has a 4 there, the version marker, and an 8, 9, a or b starting the next group (the variant). The other 122 bits are pure randomness.

1,000 AT ONCE

Bulk generation for seeding test data. Collision odds across your thousand: effectively zero, you would need 2.7 × 10¹⁸ UUIDs for a 50% chance of one duplicate.

AS A SECRET? NO

UUIDs are unguessable but often logged, cached and exposed in URLs, treat them as identifiers, not credentials. Secrets come from the password generator with expiry and storage discipline.

Method

How it works

Generation uses crypto.randomUUID(), the browser’s built-in, spec-compliant v4 generator seeded from OS entropy, the same quality as server-side generators. Formatting options re-dress the same 128 bits, hyphens and case carry no information.

Why v4 dominates: no coordination needed, any machine can mint identifiers with no registry and no collisions in practice. Time-ordered variants (v7) help database index locality, if you need those, your database or backend library is the right place to make them.

FAQ

Frequently asked questions

Are these truly unique?

Probabilistically, yes to an absurd degree: the space is 2¹²². Duplicate risk from proper generators is dwarfed by, say, cosmic-ray bit flips in your RAM.

UUID versions, which do I want?

v4 (random, this page) for general identifiers. v7 (time-ordered) for database keys at scale. v1 leaks MAC address and time, mostly avoided now. v5 is deterministic hashing of a name.

Uppercase or lowercase?

The spec outputs lowercase and treats comparison as case-insensitive. Microsoft ecosystems traditionally display uppercase in braces, hence the options.

Can I use these as database primary keys?

Yes, ubiquitously done. At serious write volume, v7’s time-ordering is kinder to B-tree indexes, for most applications v4 is fine.

Are they safe to expose in URLs?

As identifiers, yes, being unguessable beats sequential integers (no /user/42 enumeration). Just never let unguessability substitute for authorisation checks.

Is anything logged when I generate?

No, generation is local. Nobody else has ever seen these UUIDs, which is rather the point.

More tools

Related tools