Apia saysThe Web Crypto API provides secure randomness and hashing — randomUUID and subtle.digest.
crypto.randomUUID() generates a v4 UUID; crypto.getRandomValues(arr) fills a typed array with cryptographically secure randomness (never use Math.random for security). crypto.subtle handles hashing (digest), signing, and encryption — all async and HTTPS-only. Don't roll your own crypto; use these primitives.
Power-ups you unlock
crypto.randomUUID() → secure v4 UUID
getRandomValues for secure randomness
crypto.subtle.digest/sign/encrypt (async)
HTTPS-only; never use Math.random for security
Legacy Larry attacks — common mistakes
Using Math.random for tokens/IDs
Rolling your own hashing/encryption
Forgetting subtle.* is async and secure-context only
Boss battleGenerate a secure UUID and hash a string with subtle.digest (SHA-256).