UUID Generator
Generate UUIDs — random v4 or time-ordered v7 — one at a time or in bulk, in whichever format your system expects, and paste any UUID back in to read its version and creation time.
Anatomy of a v4 UUID
Take f47ac10b-58cc-4372-a567-0e02b2c3d479. The
4 starting the third group is the version marker, and the
a starting the fourth group encodes the variant — its top
bits are always 10, so that character is only ever 8, 9, a
or b. Every other hex digit is random.
That leaves 122 random bits out of 128. The hyphens carry no information; they exist purely to make the value readable, which is why the no-hyphen format is just as valid and stores in 16 bytes either way.
How unlikely a collision really is
122 random bits give 5.3 × 10³⁶ possible values. The birthday bound says the count at which a collision becomes likely is roughly the square root of that, not the number itself:
| UUIDs generated | Chance of one collision | At a billion per second |
|---|---|---|
| 103 trillion | 1 in a billion | 29 hours |
| 103 quadrillion | 1 in a thousand | 3.3 years |
| 2.7 quintillion | Even odds | 86 years |
Which is why a duplicate in production is a bug report about the random source, not a statistical curiosity.
Which version to use
| Version | Based on | Use when |
|---|---|---|
| v1 | Timestamp + MAC address | Legacy — leaks hardware identity |
| v4 | Random | Default for public identifiers |
| v5 | Namespace + name (SHA-1) | Same input must give the same ID |
| v7 | Timestamp + random | Database keys needing sortable inserts |
Frequently asked questions
When should I choose version 7 over version 4?
Whenever the identifier becomes a database key. A v4 is sixteen random bytes, so consecutive inserts land all over a B-tree and every one dirties a different page; a v7 carries a millisecond timestamp in its leading bits, so identifiers made in order sort in order and inserts stay at the end of the index. Choose v4 when the identifier is public and should reveal nothing — a v7 tells anyone holding it roughly when the record was created.
Do the v7 UUIDs generated together actually sort?
Yes. Everything in one batch shares a millisecond, so the timestamp alone cannot order them — the remaining bits would be random and the set would look sortable without being so. This generator keeps a counter in the twelve bits RFC 9562 reserves for exactly that, and steps into the next millisecond when the counter fills, so a run of a thousand comes out in the order it was made.
What is a version 4 UUID?
A 128-bit identifier where 122 bits are random and 6 are fixed markers identifying the version and variant. Because it carries no timestamp, MAC address or counter, it reveals nothing about when or where it was created — which is exactly why it is the default choice for public-facing identifiers.
Can two UUIDs collide?
In theory yes, in practice no. With 122 random bits there are 5.3 × 10³⁶ possible values, and you would need to generate roughly 2.7 quintillion of them to reach even odds of a single collision. At a billion per second that is 86 years of continuous generation. Every real-world duplicate traces back to a broken random source, not to bad luck.
Should I use a UUID as a database primary key?
It depends on the index. Random UUIDs scatter writes across a B-tree, which fragments the index and hurts insert performance at scale — a real cost in MySQL and SQL Server with clustered indexes. UUIDv7, which puts a timestamp in the high bits, keeps inserts sequential and is the better choice for new schemas that want both properties.
Are these generated securely?
Yes. They come from crypto.randomUUID() where available, falling back to crypto.getRandomValues() with the version and variant bits set correctly. Both draw from the operating system's cryptographic entropy pool, so the output is suitable for identifiers that must be unguessable, such as invite tokens.
Related tools
- Diagram & Flowchart MakerDraw flowcharts and diagrams, connect the boxes with arrows that route themselves, and let it arrange the whole thing. Exports SVG. Nothing is uploaded.
- Password GeneratorGenerate strong random passwords using your browser's cryptographic RNG, with a live strength estimate.
- HTML Entity EncoderEncode text for HTML or decode entities back — the five markup breakers, named Latin-1 and symbol sets, numeric references up to emoji. Decodes exactly once.