UUID / GUID Generator
Generate cryptographically secure UUIDv4 (Random) and UUIDv7 (Time-Ordered RFC 9562) identifiers instantly. 100% client-side privacy with bulk batch export.
Generating...RFC 4122 & RFC 9562 Section 5.4: Cryptographic Randomness
UUID Version 4 relies entirely on pseudo-random numbers. Out of 128 total bits, 6 bits are fixed (4 bits for version 0100 at bits 48–51, and 2 bits for variant 10xx at bits 64–65).
This leaves exactly 122 bits of cryptographic entropy, providing 5.3 × 10³⁶ possible values.
Plain-Text Itemized Security Receipt
Cryptographic verification record for auditing & test receipts
Loading receipt...
Understanding UUIDs: RFC 9562 & RFC 4122 Standards
A Universally Unique Identifier (UUID), standardized by the Internet Engineering Task Force (IETF) and ISO/IEC 9834-8, is a 128-bit label used for unique information identification in software systems. In Microsoft ecosystems, it is commonly called a Globally Unique Identifier (GUID).
UUIDv4: Cryptographic Randomness
UUIDv4 allocates 122 bits to cryptographically secure pseudo-random numbers (CSPRNG). It is ideal for session tokens, password reset nonces, API keys, and identifiers that must not disclose creation timestamps or internal sequences.
Entropy: 122 bits random
UUIDv7: Time-Ordered Database Keys
Ratified in May 2024 under RFC 9562, UUIDv7 embeds a 48-bit millisecond Unix epoch timestamp into the most significant bits, followed by 74 bits of random entropy. Lexicographical sorting matches chronological order, maximizing database index performance.
Entropy: 74 bits random per ms
UUIDv4 vs UUIDv7: Key Architectural Differences
| Feature | UUIDv4 (Random) | UUIDv7 (Time-Ordered) |
|---|---|---|
| Standard RFC | RFC 4122 / RFC 9562 §5.4 | RFC 9562 §5.7 (New 2024 Standard) |
| Ordering & Sortability | Unordered / Random | Chronologically Sortable (Monotonic) |
| Clustered B-Tree Performance | Poor (High fragmentation & page splits) | Optimal (Append-mostly, compact storage) |
| Random Entropy | 122 bits | 74 bits per millisecond |
| Timestamp Leakage | None (100% opaque) | Reveals creation timestamp (ms accuracy) |
| Best Used For | Security tokens, API keys, nonces | Database primary keys, distributed events |
Frequently Asked Questions
Technically, they represent the same 128-bit identifier standard. UUID (Universally Unique Identifier) is defined by IETF RFC 4122 and RFC 9562 as well as ISO/IEC 9834-8. GUID (Globally Unique Identifier) is Microsoft's implementation terminology, typically presented in UPPERCASE and wrapped in curly braces like {XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX} in C# and the Windows Registry.
UUIDv4 values are completely random, causing extreme B-Tree index fragmentation, random page splits, and degraded I/O cache hit rates in databases like PostgreSQL, MySQL InnoDB, and SQLite. UUIDv7 embeds a 48-bit Unix millisecond timestamp at the front, creating natural chronological ordering while preserving 74 bits of random entropy for distributed uniqueness.
UUIDv4 provides 122 bits of cryptographic entropy (approximately 5.3 × 10³⁶ possible values). Under the generalized birthday problem, generating 1 billion (10⁹) UUIDv4 values has a collision probability of only 4.7 × 10⁻²⁰. Approximately 2.71 quintillion (2.71 × 10¹⁸) identifiers must be created before reaching a 50% probability of a single collision.
Yes. UUIDv7 conforms strictly to the standard 128-bit layout (8-4-4-4-12 hex representation) and uses variant bits 10xx (RFC variant 1), making it 100% compatible with existing UUID parsers, validators, and native database UUID column types.
Yes. The first 48 bits of a UUIDv7 encode milliseconds since the Unix epoch (1970-01-01T00:00:00Z). Anyone inspecting the identifier can decode its creation timestamp with millisecond precision. If generation time is confidential, use UUIDv4 instead.
All generation executes client-side using native Web Cryptography (crypto.getRandomValues) and memory-efficient TypedArrays. A batch of 1,000 UUIDs completes in under 25 milliseconds without UI thread blocking or network round-trips.
No. All UUIDs, timestamps, and seeds are generated 100% client-side in browser memory. Zero identifiers or telemetry are ever transmitted or saved on external servers.