UUID v4 and what makes it safe
A version 4 UUID is 122 bits of randomness formatted as 36 characters. Its value is that two systems which have never communicated can each mint identifiers without coordinating, and the chance of a collision stays negligible - you would need to generate billions of them before it became worth thinking about.
That property depends entirely on the randomness being real. UUIDs generated from a weak random source become guessable, which turns any identifier used in a URL into an enumeration vulnerability. These are generated with the browser cryptographic random source, not Math.random.
When a ULID is the better choice
Random UUIDs have one practical drawback: they sort meaninglessly. Used as a primary key in a B-tree index, each insert lands in a random position, which fragments the index and slows writes as the table grows.
A ULID solves this by putting a millisecond timestamp in the leading bits and randomness in the rest. The result is still globally unique and still safe to expose, but it sorts chronologically - so inserts append rather than scatter, and sorting by ID sorts by creation time for free. It is also shorter and case-insensitive, encoded in Crockford Base32.
The trade-off is that a ULID reveals roughly when it was created. That is usually harmless and occasionally not.
Generating in bulk
Bulk generation is for seeding test data, backfilling a column, or preparing a batch of fixture records. Generate the count you need and copy the whole list in one action rather than clicking through one at a time.
Frequently asked questions
- Are these UUIDs cryptographically random?
- Yes. They use the browser Web Crypto random source rather than Math.random, so they are unpredictable and safe to use as identifiers exposed in URLs.
- What is the difference between a UUID and a ULID?
- Both are globally unique. A v4 UUID is entirely random and sorts meaninglessly. A ULID is timestamp-prefixed, so it sorts by creation time and behaves better as a database key - at the cost of revealing roughly when it was made.
- Can two UUIDs ever collide?
- In theory yes, in practice no. With 122 random bits you would need to generate billions before a collision became a realistic concern.
- Are the generated values sent anywhere?
- No. Generation happens entirely in your browser and nothing is transmitted or logged.