A UUID looks like random noise — 3f2504e0-4f89-41d3-9a0c-0305e82c3301 — but that structure is deliberate. It's a 128-bit identifier designed to be generated independently, on any machine, with no central authority handing out numbers, while still being safe to treat as globally unique.
What a UUID Is
UUID stands for Universally Unique Identifier. It's a 128-bit value, conventionally written as 32 hexadecimal digits split into five groups by hyphens (8-4-4-4-12). The "universally" part is the key idea — unlike a database auto-increment ID, which only guarantees uniqueness within one table, a UUID is designed so that two different systems, generating IDs completely independently with no communication between them, can both trust their IDs won't collide.
UUID vs. GUID
These terms are used almost interchangeably, and for good reason: a GUID (Globally Unique Identifier) is Microsoft's name for the exact same 128-bit concept, used across Windows and the .NET ecosystem. UUID is the vendor-neutral standard name defined by the IETF (RFC 4122) and used everywhere else — Linux, web standards, most programming languages. In practice, if you see "GUID" in documentation, you can treat it as referring to the same thing described here as a UUID; the underlying format and guarantees are identical.
Why Version 4 Is the Default
UUIDs come in several defined "versions" that determine how the bits are generated. Version 1 derives from a timestamp plus the generating machine's network (MAC) address — which technically leaks machine identity and creation time, a real privacy consideration. Version 4, by far the most common today, is instead built almost entirely from random bits (122 of the 128 bits are random; the other 6 are fixed to identify the UUID as version 4). This makes it simple to generate anywhere with no machine-specific input required, and it's the version generated by this site's own UUID tool and by the crypto.randomUUID() function built into modern browsers.
How to Generate One
- Open the UUID Generator.
- Choose how many UUIDs you need at once.
- Copy the generated value(s) — each one is produced using the browser's cryptographically secure random number generator, not a weaker pseudo-random function.
FAQ
Can two randomly generated UUIDs ever collide? In theory yes, in practice effectively no. A version 4 UUID has 122 random bits, giving about 5.3 x 10^36 possible values. Even generating a billion UUIDs per second, you'd need roughly 100 trillion years of continuous generation before the probability of any single collision reached 50% — far beyond any realistic system's lifetime.
Which UUID version should I use? Version 4 (fully random) is the standard default for almost every use case today — it requires no coordination, no machine identifiers, and no timestamp, and modern browsers and languages generate it natively via cryptographically secure randomness. Older versions like v1 (timestamp + MAC address) are mostly used in legacy systems that specifically need chronological ordering baked into the ID.
Are UUIDs safe to use as database primary keys? Yes, and they're a common choice specifically because they can be generated on the client or in application code before a row is ever inserted, with no risk of collision even across multiple database servers. The trade-off is that UUIDs take more storage space than auto-incrementing integers (16 bytes vs. typically 4-8) and their randomness can fragment certain database index structures — a known, well-documented trade-off rather than a flaw.
Is a UUID the same as a session token or API key? No, even though a UUID and a typical token can look similar as random-looking strings. A UUID's job is only to be unique, with no guarantee about how unpredictable or secret it is depending on generation method. A proper session token or API key is specifically designed and managed as a secret credential, generated and stored with security in mind — a raw UUID shouldn't be assumed to carry that same guarantee unless it was specifically generated by a cryptographically secure source, like this tool's crypto.getRandomValues()-based generator.