Skip to main content
QUIETLYTIC
Developer

UUID Generator

Generate cryptographically random v4 UUIDs in bulk.

Local · nothing leaves this browser Ready
Esc Clear
Output

Press Generate, or paste a UUID to inspect it.

How it works

A version 4 UUID is 122 random bits and six reserved ones. The reserved six are the reason every value here has a 4 starting the third group and an 8, 9, a or b starting the fourth: four bits declare the version, two declare the variant, and neither was ever meant to be random.

The randomness source is the whole question

These come from crypto.getRandomValues, the browser's CSPRNG. A generator built on Math.random produces values that look identical and collide under load, because the underlying generator is seeded predictably and has nothing like 122 bits of state. With a real CSPRNG a collision needs something on the order of a billion values a second for decades — so in practice a repeat means a broken random source, not bad luck.

An old UUID may be carrying more than you think

Paste one into the inspector and it reports the version, the variant, and — for v1, v6 and v7 — the timestamp encoded inside it. A v1 records when it was created and, historically, the MAC address of the machine that created it. An identifier treated as opaque is not necessarily opaque.

Example

The nil UUID, all zeros, is a legal value meaning "no UUID" rather than a malformed one, and is reported as such. A v7 pasted into the inspector gives back its creation time to the millisecond, because that is literally the first 48 bits.

Frequently asked questions

Are these random enough to use as identifiers?

Yes. They come from crypto.getRandomValues, the browser CSPRNG, not Math.random. A v4 UUID carries 122 random bits, which is the same entropy budget a server-side generator works with — the source of randomness is what matters, not where the code runs.

Why does every UUID have a 4 in the same place?

Because it is a version 4. Six of the 128 bits are reserved: four declare the version, which is why the third group always starts with 4, and two declare the variant, which is why the fourth group always starts with 8, 9, a or b. Those bits are not random and were never meant to be.

Can a v4 UUID collide?

In principle. With 122 random bits you would need to generate on the order of a billion a second for decades before a collision became likely, so in practice a repeat means a broken random source rather than bad luck. That is the real reason the CSPRNG matters.

What does the inspector tell me about a UUID I already have?

Its version and variant, and — for v1, v6 and v7 — the timestamp embedded in it. That last one is worth knowing: a v1 UUID encodes when it was created and historically the MAC address of the machine that created it, so an identifier you treated as opaque may be carrying both.

Related tools

From the intelligence desk