Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

Short ID Generator

Generate short URL-safe random IDs

Random string

Alphanumeric characters drawn from the crypto RNG, at the length you choose.

  • CGpCJIzqZ1RNhplue627r
  • trUa8mn0uot27HNO3tQWG
  • w9btKn45TtAaEfQPHjLja
  • 7Bm9BTukGqhWZUleOhdbB
  • FSFzGJmdmTPBg0TKF8JTv

Values come from crypto.getRandomValues, the browser's CSPRNG. They are generated locally and never sent anywhere — but a secret that has been displayed on screen is only as private as the screen.

Shorter Than a UUID, Same Idea

A UUID is 36 characters and looks like machinery. For anything a person sees — a share link, a document key, a public object reference — a shorter URL-safe identifier does the same job in a third of the space.

The trade is explicit: fewer characters means fewer bits means a higher collision probability at a given volume. That is a decision to make deliberately rather than by copying whatever the last project used.

Choosing a Length

Using a 64-character URL-safe alphabet (A–Z, a–z, 0–9, -, _), each character carries exactly 6 bits:

LengthBits1% collision chance at
848 bits~2.4 million IDs
1060 bits~152 million IDs
1272 bits~9.7 billion IDs
1696 bits~4 × 10¹³ IDs
21126 bitsBeyond any realistic volume
Twenty-one characters is the common default because it matches a UUID's entropy in 21 characters instead of 36.

Alphabet Choices Matter

  • URL-safe. Avoid characters that need percent-encoding, or the ID stops being short the
moment it hits a URL.
  • Case sensitivity. A case-sensitive ID halves in strength if anything in your stack
lower-cases it — some CDNs, some analytics tools, some email clients do.
  • Ambiguous characters. If a human will ever read one aloud or type it from a printed
page, excluding 0, O, I, l and 1 is worth the small entropy loss.

Do Not Truncate a Hash

A common shortcut is to hash something and take the first eight characters. That produces a deterministic ID — the same input always yields the same output — which leaks whether two records share an input and invites enumeration. If you want a random ID, generate random bytes.

Sequential Alternatives

Where ordering matters, ULID and UUIDv7 encode a timestamp in the high bits and keep randomness in the low bits. You get sortability and index locality at the cost of revealing roughly when the ID was created, which is sometimes fine and sometimes a leak.

Generated Locally

Bytes come from crypto.getRandomValues(), so the identifiers are unpredictable and never leave your browser.

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

How long should a short ID be?

Eight characters is fine for a few million records; twelve covers billions; twenty-one matches a UUID’s entropy. Pick from the volume you expect to reach, and remember that collision probability rises with the square of the count, not linearly.

Can I use a short ID in a URL?

Yes — that is the point. The alphabet is URL-safe, so no percent-encoding is needed and the identifier stays short in a link, a QR code or a printed reference.

Is a short ID secure enough to use as a secret link?

Only at sufficient length. Eight characters is 48 bits, which is guessable by a determined attacker enumerating in parallel. For an unlisted-URL capability use at least 16 characters, add rate limiting, and give the link an expiry.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need