Generators tool

UUID Generator: Random v4 and Time-Sorted v7 UUIDs

Generate random v4 or time-sorted v7 UUIDs (GUIDs), one or up to 1,000 at once, and copy or download them. Paste a UUID to check it and see its version.

Last updated

A UUID generator makes 128-bit IDs that are unique without asking a database for the next number. Pick v4 for a random UUID or v7 for one that sorts by time, choose how many, and copy or download them. Paste any UUID into the checker underneath to see if it is valid and which version it is.

Version

Format

Your UUIDs
Generating…

Made in your browser with crypto.getRandomValues, the same secure generator password managers use. Nothing is uploaded or stored.

Any version, with or without hyphens, braces or a urn:uuid: prefix.

A new list is made whenever you change the version or the count, and Generate makes a fresh one with the same settings. Changing the format rewrites the same UUIDs rather than making new ones.

UUID v4 vs UUID v7

Both are 128 bits in the same 8-4-4-4-12 layout, and both work anywhere a UUID is accepted. They differ in what fills the bits.

UUID v4UUID v7
Made from122 random bits48-bit Unix time in ms, then random bits
Sorts by creation timeNoYes
Reveals when it was madeNoYes, to the millisecond
Good database primary keyWorks, but scatters inserts across the indexYes, new rows land at the end of the index
StandardRFC 4122 (2005), now RFC 9562RFC 9562 (2024)
Example3f2b8c1e-9a4d-4e7b-8c2f-5d6a7b8c9d0e01926d6e-3b1a-7c42-9e5f-2a8b4c6d8e0f

Look at the first digit of the third group: that is the version, 4 or 7. The first digit of the fourth group is the variant, and for every UUID made today it is 8, 9, a or b.

The v7 UUIDs on this page stay in order even when a thousand are made in the same millisecond: the 12 bits after the version digit are a counter that goes up by one for each UUID within a millisecond, as RFC 9562 suggests.

How to use it

  1. Pick v4 random or v7 time-sorted.
  2. Set How many: tap 1, 10, 100 or 1,000, or type any number up to 1,000.
  3. Pick a Format. Upper case, No hyphens and Braces can be combined, so {3F2B8C1E9A4D4E7B8C2F5D6A7B8C9D0E} is one option.
  4. Tap Copy to copy them all, one per line, or .txt to save them as a file.
  5. To check a UUID you already have, paste it into Check a UUID.

Generating a UUID in code

Most languages can make a v4 UUID in one line, and newer versions make v7 directly.

LanguageUUID v4UUID v7
JavaScriptcrypto.randomUUID()v7() from the uuid package
Pythonuuid.uuid4()uuid.uuid7() (Python 3.14+)
SQL, PostgreSQLgen_random_uuid()uuidv7() (PostgreSQL 18+)
C#Guid.NewGuid()Guid.CreateVersion7() (.NET 9+)
JavaUUID.randomUUID()a library such as uuid-creator
Gouuid.New() from github.com/google/uuiduuid.NewV7() from the same package

crypto.randomUUID() only exists on pages served over HTTPS or from localhost, so it is undefined on a plain http:// test server.

UUID gotchas

  • Store them as 16 bytes, not 36 characters. PostgreSQL has a uuid type; in MySQL use BINARY(16). A CHAR(36) column is more than twice the size and slower to compare.
  • Random v4 keys fragment indexes. Each insert lands at a random spot in a B-tree index, so a busy table spends time splitting pages. That is the main reason v7 exists.
  • v7 leaks the time. Anyone who sees a v7 ID can read when the row was made. Use v4 for IDs in public URLs if that matters.
  • Compare them case-insensitively. 3F2B… and 3f2b… are the same UUID. The standard says to write them in lower case and to accept either.
  • .NET byte order. Guid.ToByteArray() writes the first three groups little-endian, so the bytes differ from the text order other languages use. Converting through the string form avoids surprises.
  • Not a secret. A UUID is an identifier. For API keys, session tokens and password reset links, use a token made for the job.

Special UUIDs

Two values are reserved and are not made by any version:

  • Nil UUID, 00000000-0000-0000-0000-000000000000, often used to mean "no ID yet".
  • Max UUID, ffffffff-ffff-ffff-ffff-ffffffffffff, added in RFC 9562 as a sentinel for "after everything".

The checker recognises both.

  • Base64 Encoder and Decoder. Base64 is how some systems shorten a UUID: its 16 bytes become 22 characters of base64url.
  • JSON Formatter and Validator for checking the JSON your generated IDs end up in.
  • Radix sort sorts fixed-length keys such as UUIDs one digit at a time. For v7, the leading time digits decide almost all of the order.
  • The SQL cheat sheet for the primary keys and indexes these IDs go into.

Common questions

What is a UUID generator?

A UUID generator makes universally unique identifiers: 128-bit values written as 32 hex digits in the pattern 8-4-4-4-12, such as 3f2b8c1e-9a4d-4e7b-8c2f-5d6a7b8c9d0e. They are unique without a central counter, so any computer can make one and trust it will not clash with an ID made anywhere else. This one makes version 4 and version 7 UUIDs in your browser, one at a time or up to 1,000 at once.

What is the difference between a UUID and a GUID?

Nothing that matters. GUID, globally unique identifier, is Microsoft's name for the same 128-bit format, and a GUID generator and a UUID generator make the same thing. Windows and .NET often show GUIDs in upper case inside braces, like {3F2B8C1E-9A4D-4E7B-8C2F-5D6A7B8C9D0E}; tick Upper case and Braces to get that format here.

Should I use UUID v4 or UUID v7?

Use v7 for database primary keys and anything you will sort or index, because v7 UUIDs start with the time they were made and so arrive in order. Use v4 when the ID should reveal nothing, since a v7 UUID shows to the millisecond when it was created. Both are unique enough for any real system.

Can two random UUIDs ever be the same?

In theory yes, in practice no. A version 4 UUID has 122 random bits, so you would need to generate about 2.7 quintillion of them before the chance of a single repeat reached one half. The real risk is a broken random number generator, which is why this generator only uses crypto.getRandomValues, the browser's secure source, and never Math.random.

How do I check if a string is a valid UUID?

Paste it into Check a UUID below the generator. It accepts upper or lower case, with or without hyphens, in braces or with a urn:uuid: prefix, and tells you whether it is valid, which version it is and, for version 7, the date and time it was made. It also says what is wrong with an invalid one, such as the wrong number of digits or a letter past f.

Is a UUID safe to use as a secret or a password reset token?

Not on its own terms. The UUID standard warns against assuming UUIDs are hard to guess, and a v7 UUID is partly a timestamp. A v4 UUID from a secure generator is hard to guess in practice, but for session tokens, API keys and reset links use a token made for the job, with its own length and expiry rules.

Are the UUIDs I generate here sent anywhere?

No. They are made in your browser and never leave it, and a UUID you paste into the checker is never sent anywhere either. The site records that the tool was used, the version, how many were made and the format picked, so we know which tools are worth building next. The UUIDs themselves are never part of that.

See all tools

Want this explained by a cat?

The videos cover the same ground in sixty seconds. If there is a tool you want built next, ask.