UUID Generator (v4 and v7)

Generate UUIDs several at a time. v4 is fully random, so nothing about creation order survives in it; v7 puts a timestamp in the leading bits, so values sort in the order they were made. If these are going to be database primary keys, v7 is the one that behaves for your index.

sorts by creation time

How many

    Generated in your browser. Nothing goes through a server, so there is no chance the same value was handed to someone else. Randomness comes from crypto.getRandomValues.

    How to read a v7

    The first twelve hex digits are the Unix time in milliseconds. The 7 after them is the version, and a seventeenth character of 8 to b marks the standard variant. The three digits after the 7 are the sequence within the same millisecond — it restarts from a random value when the clock ticks and increments by one within the tick. That is why a batch shares nearly the same first sixteen characters and differs only after that. The time comes from this device's clock, so values mixed with ones from a machine whose clock is off will sort accordingly.

    What the short ID really is

    Twenty-one characters drawn from sixty-four: A–Z, a–z, 0–9, _ and -. Six bits per character makes 126 bits — more than the 122 random bits in a v4. It is not weaker for being short; the notation is denser. There are no hyphens, and nothing needs encoding in a URL. The length cannot be changed.

    Where the randomness comes from

    All three use the browser's crypto. Math.random is predictable and unsuitable for identifiers; it is not used here. Values are generated when the page opens and whenever the kind or count changes, and are stored nowhere — copy what you need. Generating again discards the previous batch.

    Frequently asked questions

    Should I use v4 or v7?

    v7 for primary keys. Because v4 is fully random, each new value lands somewhere arbitrary in the index and write performance suffers. In v7 the leading 48 bits are a millisecond timestamp, so values append in order. The trade-off is that the creation time is visible in the value, so use v4 where that matters.

    If I generate a batch at once, do they stay in order?

    They do. A 12-bit counter keeps ordering within the same millisecond. Generating from the clock alone would put an entire batch in one millisecond and let the trailing random bits shuffle them, which removes the reason to use v7 in the first place.

    Can v4 collide?

    Not in practice. With 122 random bits, generating a billion a second for a century leaves a negligible chance of collision — provided the randomness is sound, which is why the browser's cryptographic generator is used here.

    Are short IDs safe?

    The short ID here is 21 characters carrying 126 bits of randomness — more than a v4 UUID's 122. Short is about length, not safety. It only becomes risky if someone truncates it further. It is fine for values shown in a URL, and this length is enough even for values nobody else should be able to guess.

    Are they uppercase?

    Lowercase. RFC 9562 says to emit lowercase and accept either when reading. Most consumers do not care, but if any code compares them as strings, settle on one case.

    Is there no v1 or v5?

    No. v1 embeds a MAC address, which reveals the machine it was made on, and v5 hashes a name — it is not a random generator. v7 when you need ordering, v4 otherwise.

    Does anything I paste get sent to a server?

    No. Everything runs inside your browser and nothing is uploaded or stored. That is why you can use it on things you would not normally paste into a web page, like an internal config file or a production query. It also works with your network disconnected.