UUID v4 Explained: Format, Randomness, and Collision Limits
See how browser-generated UUID v4 identifiers are formatted and why low collision probability is not guaranteed uniqueness or secrecy.
Published: September 22, 2026
Open UUID Generator
Quick answer
In short
- UUID v4: A 128-bit identifier with fixed version and variant bits and 122 random bits.generate UUIDs
- Limits: A random identifier can still collide and is not automatically a secret or access credential.
What a UUID v4 identifies
A UUID is a 128-bit (16-octet) identifier. Version 4 uses random or pseudorandom input, unlike versions based on time or names. It is commonly written as 32 lowercase hexadecimal digits in an 8-4-4-4-12 grouping. The hyphens are a readable representation, not extra random bits.
Version, variant, and random bits
The Calzivo UUID Generator requests 16 bytes from browser crypto.getRandomValues(). It sets the high nibble of byte 6 to 4 for version 4 and the two high bits of byte 8 to 10 for the RFC variant. The other 122 bits remain random. In the formatted string, the first digit of the third group is therefore 4, and the first digit of the fourth group is one of 8, 9, a, or b. For bit-layout illustration only, sixteen zero input bytes would format as 00000000-0000-4000-8000-000000000000; this fixed illustration is not a generated random value.
Collision probability is not a guarantee
With 122 random bits, independent well-generated UUID v4 values have a very large space and a low collision probability at ordinary scales. That is not a mathematical guarantee of uniqueness. Calzivo checks duplicates within one requested batch and fails the whole batch visibly if one occurs; it does not check other batches, databases, or other systems. Where uniqueness is essential, retain a database uniqueness constraint or equivalent check.
Browser generation and bulk output
Web Crypto provides cryptographically strong random values in the browser. Calzivo accepts a whole-number count from 1 through 100, generates in order, and shows the values in that order. Download is UTF-8 text/plain, with one UUID per line separated by LF and no trailing newline. A failed duplicate or unavailable random source is an error, not a partial success.
Identifiers are not automatically credentials
A UUID is designed for identification. Its random origin does not by itself make it a password, an encryption key, or a safe bearer token. Do not treat a visible or guessable-by-context identifier as proof of authorization. Use a purpose-designed authentication or token system where secrecy and access control matter.
Reference check
Sources and references
These references provide background context for the topic. They do not replace professional advice or official documents.
- RFC 9562: Universally Unique IDentifiers (UUIDs)
IETF / RFC Editor
- Crypto: getRandomValues() method
MDN Web Docs
UUID v4 fixes six format bits and leaves 122 random bits, making collisions unlikely but possible. Use uniqueness checks where necessary and never assume an identifier is a secret.
Use the tool instead
Use the matching calculator when you want to plug in your own numbers and get a result faster.
Open GeneratorRelated Tools
Related Guides
More guides coming soon!
