UUID generator — version 4, from your browser’s cryptographic random source
Generate one identifier or a few hundred at once, in uppercase, wrapped in braces, or with the hyphens stripped for a database column. Every value comes from crypto.randomUUID, which draws on the same random source as the rest of the browser’s cryptography, and it is generated on your machine — nothing is uploaded or saved.
- Nothing is uploaded or saved
- Works offline
Generated in this page, on your machine, when you pressed the button. The third group always starts with 4 (the version) and the fourth with 8, 9, a or b (the RFC 4122 variant) — that is how you can tell these really are v4. This page cannot produce v1 or v7; see the FAQ below.
How it works
- 1
Say how many you need
One for a config file, a few hundred to seed a table. The list regenerates when you press Generate, never while you are only changing how it looks.
- 2
Choose the shape
Uppercase, braces, and hyphens are three independent toggles applied to the identifiers you already have. Braces are what .NET and the Windows registry print; hyphens stripped is what a CHAR(32) column wants. The underlying value is the same in every form.
- 3
Copy all or download
Copy puts every identifier on the clipboard, one per line, in the format currently shown. Download writes the same list to a .txt file. Neither step involves a server.
- 4
Check it really is a v4
The first character of the third group is always 4 — that is the version field — and the first character of the fourth group is always 8, 9, a or b, which is the RFC 4122 variant. Any generator whose output does not follow that pattern is not producing what it claims.
Frequently asked questions
Which UUID version does this generate?
Version 4, random, and only version 4. crypto.randomUUID — the browser function this page uses — is specified to produce v4 and nothing else, so this page cannot generate v1 or v7 and does not pretend to. If you need one of those, it has to come from a library or from your database.
What are v1 and v7, and would I want them instead?
Version 1 packs a timestamp and a value derived from the machine’s network address into the identifier, which leaks when and roughly where it was made — that is why it fell out of favour. Version 7 keeps the useful half: a Unix millisecond timestamp in the leading bits, with the rest random, so ids sort in creation order. That ordering is worth a lot as a database primary key, because random v4 values scatter inserts across a B-tree index instead of appending to the end of it.
How random is “random” here?
crypto.randomUUID and crypto.getRandomValues draw from the platform’s cryptographically strong random source — the same one that backs key generation in the browser. That is a different thing from Math.random(), which is fast, seeded, and predictable from its own earlier output. This page deliberately has no Math.random() fallback: on a browser without a strong source it says so rather than handing you values that look identical and are not.
Can two UUIDs ever be the same?
In theory, yes; in practice you will not see it. A v4 UUID carries 122 random bits — six of the 128 are fixed by the version and variant fields — so there are 2^122, about 5.3 × 10^36, possible values. By the birthday bound you would have to generate on the order of 10^18 of them before a repeat became likely. Uniqueness is a probability argument, not a guarantee, which is why a database that truly cannot tolerate a duplicate still puts a unique constraint on the column.
Should I store them with the hyphens or without?
Whichever your column expects, but consistently. The hyphens carry no information — they mark the fields of a layout that only versions 1 and 2 actually use — so a CHAR(32) column without them saves four bytes a row and compares faster. Postgres has a native uuid type that stores 16 bytes regardless of how you type it, and that is better than either. The real failure is a table holding both forms, where a lookup for one shape silently misses the other.
Are these the same UUIDs someone else is getting?
No. They are generated in your browser, on your machine, at the moment you press the button, and no part of this page sends them anywhere or writes them down. Reload the page and you get a different set; nobody, including this site, has a record of the previous one.
Are UUIDs safe to use as a secret?
A v4 UUID has 122 bits of entropy from a strong source, so guessing one is not feasible — but it is designed to be an identifier and it usually behaves like one: it ends up in URLs, logs, referrer headers and support tickets. If a value has to stay secret, generate a token meant to be secret and treat it accordingly, rather than relying on an id nobody was ever careful with.