How to generate a UUID in JavaScript & Node.js
In 2026 you rarely need an npm package for this: crypto.randomUUID() is built into every modern browser, Node.js, Deno, and Bun, and returns a random UUID v4 in one call. All snippets below were run on Node.js 23.
By the Withuse team · Updated
The zero-dependency answer
// Browser, Node.js 14.17+, Deno, Bun — no import needed const id = crypto.randomUUID(); // "8f76cd82-a66e-41b9-b47b-9b2e55f1bb24"
That's it. It is cryptographically secure, always lowercase, and always version 4. Before reaching for npm install uuid, check the support table:
Where crypto.randomUUID() works
| Runtime | Supported since | Note |
|---|---|---|
| Chrome / Edge | 92 (2021) | HTTPS or localhost only (secure context) |
| Firefox | 95 (2021) | Secure context only |
| Safari | 15.4 (2022) | Secure context only |
| Node.js | 14.17 / global since 19 | Older Node: require("crypto").randomUUID() |
| Deno / Bun | From 1.x | Global |
The classic gotcha: on a plain http:// page (not localhost), crypto.randomUUID is undefined — the spec restricts it to secure contexts.
When you still need the uuid package
Three cases justify npm install uuid:
import { v7 as uuidv7, v5 as uuidv5, validate, version } from "uuid";
// 1. UUID v7 — time-ordered, ideal for database keys
uuidv7(); // "01a0176b-aac4-70a3-9b9b-89e561ddee46" (sortable)
// 2. UUID v5 — deterministic, same input → same UUID
uuidv5("example.com", "6ba7b810-9dad-11d1-80b4-00c04fd430c8");
// always "cfbff0d1-9375-5685-968c-48ce8b15ae17"
// 3. Validation helpers
validate("550e8400-e29b-41d4-a716-446655440000"); // true
validate("not-a-uuid"); // false
version("550e8400-e29b-41d4-a716-446655440000"); // 4If your UUIDs become database primary keys, prefer v7 over v4 — see UUID v4 vs v7 for why time-ordered keys keep indexes fast.
Validating without a dependency
const UUID_RE =
/^[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;
UUID_RE.test("550e8400-e29b-41d4-a716-446655440000"); // trueTypeScript tip: a branded UUID type
type UUID = string & { readonly __brand: "UUID" };
function newId(): UUID {
return crypto.randomUUID() as UUID;
}
// Now a plain string can't be passed where a UUID is expected.TypeScript 5+ also types crypto.randomUUID() as `${string}-${string}-${string}-${string}-${string}`, which catches some obvious mistakes at compile time.
Frequently asked questions
Do I need the npm uuid package to generate a UUID?
Usually not. crypto.randomUUID() is built into every current browser, Node.js 14.17 and later, Deno and Bun, and it returns a cryptographically secure UUID v4 with no install and no bundle cost. Three situations still justify the package. You need UUID v7, whose time-ordered layout keeps database indexes efficient and which no runtime exposes natively yet. You need the deterministic name-based versions v5 or v3, where the same namespace and name must always produce the same identifier. Or you want the validate() and version() helpers rather than maintaining your own regular expression. If none of those apply, dropping the dependency removes roughly 10 kB from your bundle and one more package from your supply chain, which is worth doing on a front end.
Why is crypto.randomUUID undefined in my browser?
Because the page is not in a secure context. The Web Crypto specification only exposes randomUUID() on pages served over HTTPS or from localhost, so on a plain http:// page — a staging server accessed by IP address, for example — the function genuinely does not exist and calling it throws a TypeError. The fix is to serve over HTTPS, or to test through localhost rather than a LAN address. Two other causes look identical but are not: a Node.js version below 14.17, where the function was not yet available, and Node 14 to 18 where it lives on the crypto module and must be imported with require('crypto').randomUUID() instead of being a global. From Node 19 onward the global is present.
Is crypto.randomUUID() cryptographically secure?
Yes. The Web Crypto specification requires it to draw from a cryptographically secure pseudo-random number generator, the same source that backs crypto.getRandomValues(), so the 122 random bits are unpredictable even to an attacker who has collected many earlier values. That makes it appropriate for identifiers that must not be guessable. What it does not do is make a UUID a credential: anyone who obtains the value can use it, so a UUID is an identifier, not an authorisation. Also avoid the common shortcut of building a UUID from Math.random() — that generator is explicitly not cryptographically secure, its output can be predicted from previous values, and several widely copied snippets on the web still use it.
How do I validate a UUID string in JavaScript?
With the uuid package, validate('550e8400-e29b-41d4-a716-446655440000') returns a boolean and version() returns the numeric version, which lets you enforce a specific one. Without a dependency, a strict regular expression covering the version and variant digits does the job: the shape check alone is not enough, because it would accept values whose version nibble is not a real UUID version. Whichever you choose, anchor the pattern with ^ and $ or use fullmatch semantics, otherwise a UUID embedded in a longer string passes. Add the case-insensitive flag as well, since Microsoft tooling and several databases emit uppercase. Our UUID regex page lists four ready-made patterns and a live tester if you want to check one against real input.
Need a batch of UUIDs without writing code? Our free UUID generator creates up to 1,000 at once — v1/v3/v4/v5/v7, entirely in your browser. Also in this series: UUID in Python.