Utilities

UUID generator

Random v4 and time-ordered v7 UUIDs, up to 1,000 at once, and a decoder for any UUID. Made in your browser from its cryptographic random source.

Version
Format

1 to 1,000 at once.

Questions

Are the UUIDs made on a server?

No. They are generated in your browser with crypto.randomUUID and crypto.getRandomValues, the operating system’s cryptographic random source. Nothing is sent, nothing is put in the address bar, and the page keeps nothing after you leave.

v4 or v7: which should I use?

v4 is 122 random bits: use it when an ID must reveal nothing. v7 starts with a 48-bit Unix timestamp in milliseconds, so newer IDs sort after older ones. That keeps database indexes compact, because new rows land at the end of a B-tree, and RFC 9562 recommends v7 for database keys. The trade-off: anyone can read when a v7 UUID was made.

Can two UUIDs collide?

In practice, no. With 122 random bits you would need about 2.7 × 10^18 v4 UUIDs for a 50% chance of a single duplicate. A v7 UUID adds the millisecond to 73 bits of randomness, so a clash needs two UUIDs made in the same millisecond with the same random bits.

How do v7 UUIDs stay in order within one millisecond?

The 12 bits after the version digit are a counter (RFC 9562, section 6.2, method 1). In each new millisecond it starts at a random value below 2,048, and each further UUID in that millisecond adds one, so a batch of 1,000 stays in creation order. If it would pass 4,095, the timestamp moves on by a millisecond. The last 62 bits are random.

What does the decoder show?

The version and variant of any UUID; the creation time inside v1, v6 and v7 UUIDs, to 100 nanoseconds for v1 and v6; the clock sequence and node of v1 and v6; and whether it is the nil (all zeros) or max (all ones) UUID. Braces, urn:uuid: and missing hyphens are fine. A v4 has no time in it, and v3 and v5 are hashes of a name that can’t be read back.

Is a UUID the same as a GUID?

Yes. GUID is Microsoft’s name for the same 128-bit format. Windows tools often write GUIDs in upper case inside braces, such as {6F9619FF-8B86-D011-B42D-00C04FC964FF}, which the format options produce. Case doesn’t change the value, but RFC 9562 asks for lower case in output.

Can I use a UUID as a password or API key?

Better not. A v4 UUID is random, but UUIDs are made to be identifiers, so they get shown in URLs, emails and admin screens, and a v7 UUID is partly predictable because it holds a timestamp. For secrets, use a dedicated random value, such as a 32-character password from the password generator.

esc