UUID Generator

Generate cryptographically secure UUID v4 identifiers in your browser. Batch up to 100 with uppercase, hyphen, and braces options.

Format:5 UUIDs generated this session

UUIDs (5)

  • 7cf9c0c3-a9a5-448a-85c5-cfae83cc907a
  • 2531f441-0903-4629-9e91-5703a5fe04cb
  • 32b6731e-46de-4adb-870b-de5f955af2a2
  • ed602de9-fadc-4000-874d-aec79d9a3b0a
  • 99b623f5-bf8b-4696-83d3-801acbca4087

Frequently Asked Questions

A UUID (Universally Unique Identifier) is a 128-bit label, usually written as 36 characters in the pattern 8-4-4-4-12 hexadecimal digits, like 3f8a2c1e-9b4d-4e7a-8c2f-1d6b0a9e5c43. UUIDs are designed to be unique across systems without a central authority coordinating them, which makes them the standard choice for database keys, request IDs, file names, and distributed-system identifiers. The variant and version nibbles embedded in the string tell you which generation scheme produced it.

Version 4 UUIDs contain 122 random bits (128 bits minus 6 fixed version/variant bits), giving 2^122 ≈ 5.3 × 10^36 possible values. The birthday bound makes collisions practical to reason about: after generating n UUIDs, the chance any two match is roughly n² / 2^123. To reach a 50% chance of even one collision you would need to generate about 2.6 × 10^18 (2.6 quintillion) UUIDs — and generating a billion UUIDs per second for 85 years only approaches that. For comparison, at one trillion UUIDs (10^12) the collision probability is still about 4 × 10^-13.

They are when generated from a cryptographic random source. This tool uses crypto.randomUUID(), which the spec requires to come from a cryptographically secure random number generator, and falls back to crypto.getRandomValues() — the same CSPRNG — with the version and variant bits set per RFC 9562. Neither generator is predictable from earlier outputs, so v4 UUIDs are safe to use as unguessable tokens, session IDs, or secret-capable identifiers. They are not, however, a substitute for dedicated secrets of 128+ bits of entropy — they are exactly 122.

Version 1 derives uniqueness from a timestamp plus the device MAC address — unique but predictable, and it leaks where and when it was made. Version 5 derives the UUID deterministically by hashing a name with SHA-1 under a namespace: same input, same UUID, useful for stable IDs derived from URLs or domain names. Version 4 is pure random: no clock, no hardware identity, no structure to leak, and no coordination needed. That independence is why v4 is the default choice for keys, tokens, and anything exposed to the outside world. (A newer v7 uses timestamped ordering for database index friendliness, with random entropy.)

Functionally yes. GUID (Globally Unique Identifier) is Microsoft’s name for the same 128-bit identifier used across Windows, COM, and SQL Server, and the terms are used interchangeably. Historically some Microsoft generators produced variant-2 GUIDs, but modern GUID generators produce standard RFC-compatible v4 values, so a GUID from this tool is a UUID in every practical sense.

Quick Answer

Click Generate to create UUID v4 identifiers — each is 122 random bits from your browser’s cryptographic random number generator, formatted as the canonical 8-4-4-4-12 hex string (example: 3f8a2c1e-9b4d-4e7a-8c2f-1d6b0a9e5c43). Generate up to 100 at a time, then toggle uppercase, hyphens, or braces to match whatever format your code or config expects. Copy individual values or all of them at once. Generation happens entirely on your device with crypto.randomUUID() and never leaves your browser.

Key Facts

  • UUID v4: 122 cryptographically random bits per identifier via the Web Crypto API
  • crypto.randomUUID() with a spec-compliant crypto.getRandomValues() fallback
  • Batch-generate 1–100 UUIDs per click
  • Formatting toggles: uppercase, remove hyphens, wrap in braces
  • Copy individual UUIDs or all of them with one click
  • Runs 100% in your browser — nothing is sent to a server or stored

Frequently Asked Questions

What is a UUID?

A UUID (Universally Unique Identifier) is a 128-bit label, usually written as 36 characters in the pattern 8-4-4-4-12 hexadecimal digits, like 3f8a2c1e-9b4d-4e7a-8c2f-1d6b0a9e5c43. UUIDs are designed to be unique across systems without a central authority coordinating them, which makes them the standard choice for database keys, request IDs, file names, and distributed-system identifiers. The variant and version nibbles embedded in the string tell you which generation scheme produced it.

What are the odds of a v4 UUID collision?

Version 4 UUIDs contain 122 random bits (128 bits minus 6 fixed version/variant bits), giving 2^122 ≈ 5.3 × 10^36 possible values. The birthday bound makes collisions practical to reason about: after generating n UUIDs, the chance any two match is roughly n² / 2^123. To reach a 50% chance of even one collision you would need to generate about 2.6 × 10^18 (2.6 quintillion) UUIDs — and generating a billion UUIDs per second for 85 years only approaches that. For comparison, at one trillion UUIDs (10^12) the collision probability is still about 4 × 10^-13.

Are v4 UUIDs cryptographically secure?

They are when generated from a cryptographic random source. This tool uses crypto.randomUUID(), which the spec requires to come from a cryptographically secure random number generator, and falls back to crypto.getRandomValues() — the same CSPRNG — with the version and variant bits set per RFC 9562. Neither generator is predictable from earlier outputs, so v4 UUIDs are safe to use as unguessable tokens, session IDs, or secret-capable identifiers. They are not, however, a substitute for dedicated secrets of 128+ bits of entropy — they are exactly 122.

What is the difference between v4, v1, and v5 UUIDs?

Version 1 derives uniqueness from a timestamp plus the device MAC address — unique but predictable, and it leaks where and when it was made. Version 5 derives the UUID deterministically by hashing a name with SHA-1 under a namespace: same input, same UUID, useful for stable IDs derived from URLs or domain names. Version 4 is pure random: no clock, no hardware identity, no structure to leak, and no coordination needed. That independence is why v4 is the default choice for keys, tokens, and anything exposed to the outside world. (A newer v7 uses timestamped ordering for database index friendliness, with random entropy.)

Is a UUID the same as a GUID?

Functionally yes. GUID (Globally Unique Identifier) is Microsoft’s name for the same 128-bit identifier used across Windows, COM, and SQL Server, and the terms are used interchangeably. Historically some Microsoft generators produced variant-2 GUIDs, but modern GUID generators produce standard RFC-compatible v4 values, so a GUID from this tool is a UUID in every practical sense.