email
alex.smith@example.com
alex+promo@example.comalex😺@example.comalex@exämple.com
We turn a database schema into production-realistic test data, then hide nasty edge cases inside it. Emojis, boundary integers, malformed strings. Your users are going to do it anyway, right?
Get started without an account or credit card. (See the FAQ for more details.)
$ mysqldump --no-data shop | curl -s -X POST \
"https://api.chaosdata.net/api/v1/quick-generate?rows=100&chaos=10&seed=42" \
-H "Accept: text/sql" --data-binary @-
-- ChaosData | seed=42 rows=100 chaos=10 anomalies=23
SET NAMES utf8mb4;
START TRANSACTION;
INSERT INTO `users` (`id`, `first_name`) VALUES
(1, 'Alex 🚀'),
(2, 'Jaymé́́́́́́'),
... 98 more rows
COMMIT;
Realistic values with a few nasty ones mixed in. Declared constraints
are always respected.
See every anomaly.
email
alex.smith@example.com
alex+promo@example.comalex😺@example.comalex@exämple.cominteger
42
2147483647-21474836480timestamp
2024-01-02 15:04:05
2038-01-19 03:14:071970-01-01 00:00:009999-12-31 23:59:59url
https://example.com/items/42
javascript:alert(1)https://user:pass@example.com/items/42https://münchen.de/items/42uuid
7f1c2f9e-3b6a-4c1d-9e2f-1a2b3c4d5e6f
{7f1c2f9e-3b6a-4c1d-9e2f-1a2b3c4d5e6f}7F1C2F9E-3B6A-4C1D-9E2F-1A2B3C4D5E6F7f1c2f9e3b6a4c1d9e2f1a2b3c4d5e6ftext
hello world
<script>alert("xss")</script>' OR '1'='1' --💥 hello worldCheck out the output below, then edit the schema or crank up the chaos!
Press “Generate data”.
Works with the databases you already use.
Don't use one of those? Suggest another one! features@chaosdata.net.
Use it without an account. Accounts and API keys are coming soon.
60 requests per minute per client address.
Up to 100 rows per table.
300 requests per minute, plus API keys and usage history, when accounts open.
No. Declared constraints are always respected: NOT NULL, UNIQUE, primary and
foreign keys, VARCHAR(n) lengths, UNSIGNED, enum membership and simple
CHECK ranges. Anomalies target the things your schema doesn't say: the assumptions
your code makes.
Yes. Output is ordered parent-first with valid foreign keys, wrapped in a transaction, and emitted in the syntax your database expects. If a generated row couldn't load, that's a bug.
Emoji and combining marks, bidi and zero-width characters, long-but-legal strings, boundary and negative numbers where nothing forbids them, extreme timestamps, malformed emails and dates, and XSS/SQL-injection payloads. The JSON response reports how many anomalies were injected.
Yes. The quick-generate endpoint is open with no account and no credit card, limited to 60 requests per minute per client address. Accounts are not open yet; when they launch they will raise that to 300 requests per minute and add API keys and usage history. Join the waitlist to hear when.
Pass a seed and you'll get the exact same bytes every time. The seed is echoed in the metadata
and in the SQL header.