Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

UUID Generator

UUID Generator

UUID v4

128-bit random identifier, RFC 9562 version 4, lowercase and hyphenated.

  • cf8fcce1-bf4e-4f40-b467-5d1c279736a6
  • c672b084-7358-404c-9233-ca25e2248b6e
  • 7114e063-c436-4bfa-86f8-0410e1165a4a
  • a2cc4072-e30c-4077-be75-db3f7a6fe2c8
  • 316376ab-4347-4c89-984b-b233e0a950e1
  • 961ad288-3742-42bf-a05c-dd9775ea3b4a
  • 3e6a930c-be4e-4aa2-a962-192e751619e5
  • f66797ad-8d7e-4667-85c9-5e59605e01a8
  • 6cc94987-64a0-4d55-891d-36bed43ee0d1
  • 3734facb-e1c0-4ae1-a977-c7479562b38f

Values come from crypto.getRandomValues, the browser's CSPRNG. They are generated locally and never sent anywhere — but a secret that has been displayed on screen is only as private as the screen.

UUID Generator

A UUID is a 128-bit identifier that can be generated independently on any machine without coordination, and still be unique. That property — no central authority, no round trip — is why they underpin distributed systems.

The Versions Are Not Interchangeable

VersionBuilt fromSortableUse it for
v1Timestamp + MAC addressRoughlyLegacy; leaks the host
v3MD5 of a namespace + nameNoDeterministic IDs from a known name
v4122 random bitsNoThe general default
v5SHA-1 of a namespace + nameNoDeterministic, preferred over v3
v7Unix timestamp + randomnessYesNew database keys
v4 is what most people mean by "a UUID". v7 is the one to reach for when the identifier will become a primary key, because it sorts by creation time.

Deterministic UUIDs Are Underused

v5 hashes a namespace and a name, so the same inputs always produce the same UUID on any machine, forever. That makes it ideal for deriving a stable ID from something you already have — a URL, a file path, an external system's key — without storing a mapping table.

`` uuid5(NAMESPACE_URL, "https://example.com/a") -> always the same UUID `

Generating in Bulk

Seeding a test database, building a fixture set or pre-allocating keys all want a column of identifiers rather than one. Generating them client-side costs nothing and needs no round trip — unlike database-generated keys, which force an insert before you know the ID.

Storage: Do Not Use a 36-Character String

A UUID is 16 bytes. Stored as text it is 36 characters, and indexed as text it compares character by character.

StorageSizeNotes
uuid (PostgreSQL)16 bytesNative, correct
BINARY(16) (MySQL)16 bytesWith UUID_TO_BIN()
CHAR(36)36 bytes2.25× larger, slower to compare
On a large table with several UUID foreign keys, that difference is measured in gigabytes.

Randomness Source

These are generated with crypto.getRandomValues(), the browser's CSPRNG. A generator built on Math.random() produces values that look identical and are predictable — which matters the moment anyone treats an ID as unguessable.

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

Is this UUID truly random?

Yes, generation uses cryptographically secure random number generation (CSPRNG) suitable for security-sensitive applications.

Can two generated values ever be the same?

While theoretically possible, the probability is astronomically low. For UUIDs, there are 2^122 possible values—collision is practically impossible.

Are generated values stored anywhere?

No, all generation happens locally in your browser. Nothing is sent to any server, ensuring complete privacy.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need