Break your app before your users do.

We turn a database schema into production-realistic test data, then hide nasty edge cases inside it. Emojis, boundary integers, malformed strings. Your users are going to do it anyway, right?

Get started without an account or credit card. (See the FAQ for more details.)

What does chaotic data look like?

Realistic values with a few nasty ones mixed in. Declared constraints are always respected.
See every anomaly.

email

alex.smith@example.com

  • alex+promo@example.com
  • alex😺@example.com
  • alex@exämple.com

integer

42

  • 2147483647
  • -2147483648
  • 0

timestamp

2024-01-02 15:04:05

  • 2038-01-19 03:14:07
  • 1970-01-01 00:00:00
  • 9999-12-31 23:59:59

url

https://example.com/items/42

  • javascript:alert(1)
  • https://user:pass@example.com/items/42
  • https://münchen.de/items/42

uuid

7f1c2f9e-3b6a-4c1d-9e2f-1a2b3c4d5e6f

  • {7f1c2f9e-3b6a-4c1d-9e2f-1a2b3c4d5e6f}
  • 7F1C2F9E-3B6A-4C1D-9E2F-1A2B3C4D5E6F
  • 7f1c2f9e3b6a4c1d9e2f1a2b3c4d5e6f

text

hello world

  • <script>alert("xss")</script>
  • ' OR '1'='1' --
  • 💥 hello world

Try it right now

Check out the output below, then edit the schema or crank up the chaos!

Equivalent request
output
ready
Press “Generate data”.

Works with the databases you already use. PostgreSQLMySQLSQLite

Don't use one of those? Suggest another one! features@chaosdata.net.

Free limits

Use it without an account. Accounts and API keys are coming soon.

No account

60 requests per minute per client address.
Up to 100 rows per table.

Accounts (coming soon)

300 requests per minute, plus API keys and usage history, when accounts open.

Join the waitlist

FAQ

Will it break my schema constraints?

No. Declared constraints are always respected: NOT NULL, UNIQUE, primary and foreign keys, VARCHAR(n) lengths, UNSIGNED, enum membership and simple CHECK ranges. Anomalies target the things your schema doesn't say: the assumptions your code makes.

Will the generated data actually load?

Yes. Output is ordered parent-first with valid foreign keys, wrapped in a transaction, and emitted in the syntax your database expects. If a generated row couldn't load, that's a bug.

What exactly gets injected?

Emoji and combining marks, bidi and zero-width characters, long-but-legal strings, boundary and negative numbers where nothing forbids them, extreme timestamps, malformed emails and dates, and XSS/SQL-injection payloads. The JSON response reports how many anomalies were injected.

Is it free? Do I need an account?

Yes. The quick-generate endpoint is open with no account and no credit card, limited to 60 requests per minute per client address. Accounts are not open yet; when they launch they will raise that to 300 requests per minute and add API keys and usage history. Join the waitlist to hear when.

Can I reproduce a specific dataset?

Pass a seed and you'll get the exact same bytes every time. The seed is echoed in the metadata and in the SQL header.