UUID Generator
Generate random UUID v4 identifiers in bulk with one click. No server needed.
What this generator produces
Version 4 UUIDs: 128-bit identifiers in the familiar
xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx form, for example
f47ac10b-58cc-4372-a567-0e02b2c3d479. Generate one or a hundred at a time and copy
them as a list.
They are produced with your browser's cryptographic random number generator, not with a predictable sequence, so the values are suitable for identifiers that must not be guessable.
How to use it
- Set how many UUIDs you need.
- Click Generate.
- Click Copy to put the whole list on your clipboard, one identifier per line.
The anatomy of a UUID
All 32 hexadecimal digits are not random. A few of them are structural, and knowing
which is which explains why every v4 identifier you will ever see has a 4 in the
same place:
| Position | What it holds | Value in v4 |
|---|---|---|
| Digits 1-8 | Random | any hex |
| Digits 9-12 | Random | any hex |
| Digit 13 | Version | always 4 |
| Digits 14-16 | Random | any hex |
| Digit 17 | Variant | 8, 9, a or b |
| Digits 18-32 | Random | any hex |
That leaves 122 random bits - about 5.3 × 1036 possible values. At that size, generating a billion UUIDs a second for a century still gives a collision probability far below one in a trillion, so in practice you never need to check for duplicates. The theoretical limit is why identifiers in distributed systems are usually UUIDs: two machines that never talk to each other can mint identifiers independently without coordinating.
Why not just use your database counter
| Property | Auto-increment integer | UUID v4 |
|---|---|---|
| Size | 4 or 8 bytes | 16 bytes (36 as text) |
| Guessable? | Yes, trivially | No |
| Safe to expose in a URL? | Leaks your volume and invites enumeration | Yes |
| Generated without a central authority? | No | Yes, on any machine |
| Index locality | Excellent, sequential | Poor, random inserts |
The last row is the real cost. Random keys scatter writes across a B-tree index, which costs space and page splits at scale; sequential identifiers append neatly at the end. That is the whole reason time-ordered identifiers such as UUID v7 and ULID exist: random enough not to be guessable, ordered enough to index well. For small applications v4 is perfectly fine; for a high-write table, the ordering matters more than the format.
Seven versions, one shape
The UUID format has accumulated versions over thirty years, and they are not interchangeable:
| Version | Built from | Typical use |
|---|---|---|
| v1 | Timestamp and MAC address | Legacy systems; leaks host identity |
| v3 | MD5 hash of a name | Deterministic IDs; MD5 is obsolete |
| v4 | 122 random bits | The default for most applications |
| v5 | SHA-1 hash of a name | Deterministic IDs; the safer v3 |
| v6, v7 | Timestamp plus randomness | Sortable keys in modern databases |
| v8 | Application-defined | Custom schemes inside the standard format |
v3 and v5 are the interesting exceptions: given the same name and namespace they always produce the same identifier, which is how you get a stable ID for something like a URL without storing a mapping. That determinism is the point - and also the reason they must not be used for anything that has to be unguessable.
UUID or GUID?
They are the same thing. GUID (globally unique identifier) is the name
Microsoft and much of the Windows ecosystem uses for the identifier that the standard calls a
UUID. Same 128 bits, same hyphenated hex layout, same version and variant fields. The first
digit being 4 in a modern identifier is how you know it is a v4 UUID regardless of
which word the tool uses.
When a UUID is the wrong tool
- As a password, token or API key. 122 bits of randomness is a lot, but a UUID is designed to be stored and printed by many systems, and once it is in a log, a screenshot or an index it is as public as anything else. Use a purpose-built secret with enough entropy and rotate it - the password generator is the tool for that job, not this one.
- As a sequential key you need to sort. Use v7 or ULID, or an integer.
- When you need it to be short. 36 characters of text is a lot of URL, a lot of QR code and a lot of log line. Base64url of 16 random bytes carries the same entropy in 22 characters - our Base64 tool shows the trade-off.
- When the ID must be meaningful. A UUID says nothing about what it names. If you need to look at an identifier and know what it points to, a UUID is the wrong shape.
FAQ
Are the UUIDs unique?
Effectively yes. A version 4 UUID carries 122 random bits, so the chance of a collision is negligible: you would need to generate enormous numbers of them for it to become a realistic concern.
Does the generator send my data anywhere?
No. The identifiers are produced in your browser with its cryptographic random number generator, and nothing is transmitted or stored.
What is the difference between a UUID and a GUID?
Nothing structural. GUID is Microsoft terminology for the same 128-bit identifier defined by the UUID standard: same layout, same version and variant fields.
Why does every UUID have a 4 in it?
The 13th hexadecimal digit encodes the version, and 4 means version 4, the random variant. The 17th digit encodes the variant and is always 8, 9, a or b. The remaining 122 bits are random.
Should I use a UUID as an API key or session token?
No. A UUID is designed to be stored, logged and displayed by many systems, so it leaks easily. Use a purpose-built secret with enough entropy, stored hashed, and rotate it.