Skip to content

ULID Generator

Generate one ULID or many at once: a 26-character, Crockford Base32 identifier that sorts lexicographically by creation time, encodes a real 48-bit millisecond timestamp, and fills the rest with cryptographically random bits from the Web Crypto API.

  • Sortable by creation time, like UUID v7
  • Crockford Base32 — no ambiguous I, L, O, U characters
  • Cryptographically random via Web Crypto
  • Bulk generation
  • Runs fully client-side

Generator

Generated locally with Web Crypto

Result

How to generate a ULID

  1. 01

    Choose how many

    Generate a single ULID or a batch for seeding test data.

  2. 02

    Generate

    Each ULID encodes the current millisecond timestamp plus 80 bits of cryptographic randomness.

  3. 03

    Copy the result

    Copy a single value or the whole list.

What a ULID actually is#

A ULID is 128 bits, the same size as a UUID, but encoded and structured differently. The first 48 bits are a millisecond-precision Unix timestamp; the remaining 80 bits are random. The whole thing is rendered as 26 characters of Crockford's Base32 — a modified alphabet that deliberately excludes the letters I, L, O and U, so a handwritten or read-aloud ULID cannot be confused between a 1, an I and an L, or a 0 and an O.

How this compares to UUID v7, this site's other time-sortable ID#

UUID v7 and ULID solve the identical problem — a randomly-distributed identifier that also sorts by creation time, avoiding the database index fragmentation that plain UUID v4 causes as a primary key — using nearly the same structure: both encode a 48-bit millisecond timestamp followed by random bits. The practical difference is encoding and ecosystem: UUID v7 is a hex-formatted, hyphenated string that fits the standard uuid type in most databases and matches an official IETF standard (RFC 9562); ULID is a Base32 string, one character shorter, avoids visually ambiguous characters, and predates the UUID v7 standard by several years as the original popularizer of this idea. Neither is more "correct" — the deciding factor is usually which one a project's existing tooling or database column type already expects.

Why the randomness matters here too#

Just as with this site's UUID and password generators, the 80 random bits come from crypto.getRandomValues, the browser's cryptographically secure random source — not Math.random, which has a predictable internal state. Two ULIDs generated in the same millisecond still differ with overwhelming probability, since 80 bits of true randomness is an enormous space to collide within.

Frequently asked questions

How is a ULID different from a UUID?

Same 128 bits of information, different encoding and structure. A ULID is 26 characters of Crockford Base32 that starts with a real timestamp and sorts by creation time. A standard UUID v4 is 36 hex characters with hyphens and no time ordering at all — UUID v7 adds time ordering similar to ULID but keeps the hex format.

Why does the alphabet exclude I, L, O and U?

To avoid characters that are easy to confuse when read aloud or handwritten — 1/I/L and 0/O look alike in many fonts. Crockford Base32 was designed specifically to sidestep that ambiguity.

Do ULIDs sort correctly as plain strings?

Yes — because the first 10 characters encode the timestamp in a fixed-width, most-significant-first format, sorting ULIDs as ordinary strings produces the same order as sorting by creation time.

Is the randomness cryptographically secure?

Yes — it uses the Web Crypto API's crypto.getRandomValues, the same cryptographically secure source this site's UUID and password generators use, not Math.random.

Are these generated on a server?

No. Every ULID is generated entirely in your browser — nothing is requested from or sent to a server.

Developers

UUID Generator

Generate cryptographically random UUID v4 or time-ordered UUID v7, in bulk.

Developers

Base64 Encoder & Decoder

Encode and decode Base64 with correct UTF-8 handling, including the URL-safe alphabet.

Developers

URL Encoder & Decoder

Percent-encode or decode a URL, a query parameter, or a form-urlencoded value — three different modes, not one.