Reference

About UUIDs

Everything you need to know about Universally Unique Identifiers — structure, versions, and when to use which.

What is a UUID?

A UUID (Universally Unique Identifier), also known as a GUID (Globally Unique Identifier), is a 128-bit label used to uniquely identify objects in computer systems. Defined in RFC 9562 (which supersedes RFC 4122), UUIDs are represented as 32 hexadecimal digits in the format:

xxxxxxxx-xxxx-Mxxx-Nxxx-xxxxxxxxxxxx

Where M is the version digit (1–7) and N is the variant field (8, 9, a, or b for RFC 4122 UUIDs). A UUID is 36 characters long including the hyphens (32 hex + 4 hyphens).

UUID Structure

FieldBitsDescription
time_low32Low field of timestamp
time_mid16Middle field of timestamp
time_hi_and_version16High field of timestamp + 4-bit version
clock_seq_hi_and_res8Variant bits + high clock sequence
clock_seq_low8Low clock sequence field
node48Spatially unique node identifier

UUID Versions

v1

Time-based

Generated using the current timestamp (100-nanosecond intervals since 15 Oct 1582) and a node identifier (originally MAC address). Successive v1 UUIDs from the same host are sortable.

6ba7b810-9dad-11d1-80b4-00c04fd430c8
✓ Time-sortable⚠ Exposes timestamp
v3

MD5 Name-based

Deterministic — MD5-hash of a namespace UUID and name string. Same input always yields the same UUID. Not cryptographically secure (MD5 is broken), but sufficient for uniqueness.

9073926b-929f-31c2-abc9-fad77ae3e8eb
v4

Random

Most popular

122 bits of cryptographically-secure random data from the OS CSPRNG. The collision probability for 1 billion UUIDs is ~1 in 2.71×1018. No structure or ordering.

550e8400-e29b-41d4-a716-446655440000
✓ Cryptographically random✓ No PII leakage
v5

SHA-1 Name-based

Like v3 but uses SHA-1 instead of MD5. Preferred over v3. Deterministic given same namespace + name. Use DNS namespace for domain names, URL namespace for URLs.

886313e1-3b8a-5372-9b90-0c9aee199e5d
v7

Unix Epoch Time-ordered

New in RFC 9562

The most modern UUID version. Encodes the Unix timestamp in milliseconds in the 48 most-significant bits, making v7 UUIDs lexicographically sortable by time — a huge advantage for database B-tree indexes.

018f3b6a-c000-7000-8000-000000000001
✓ Lexicographically sortable✓ Great for DB primary keys

RFC 4122 & RFC 9562

UUIDs were originally standardized in RFC 4122 (2005). In RFC 9562 (2024), the IETF updated the specification to formally add UUID versions 6, 7, and 8, deprecate v2, and clarify existing behavior. UUID v4 and v7 are the versions recommended for most new use cases.

All UUIDs generated on this site are fully compliant with RFC 9562.

Frequently Asked Questions

Can two UUIDs ever be the same?

In theory, yes, but the probability is so small it's effectively impossible. For v4 UUIDs, generating 1 billion UUIDs per second for 100 years would give a 50% chance of a single collision.

Which UUID version should I use?

Use v4 when you need a random, opaque identifier. Use v7 for database primary keys (time-sortable). Use v5 when you need a reproducible ID from a known namespace+name pair.

Is UUID the same as GUID?

Yes. GUID (Globally Unique Identifier) is Microsoft's name for UUID. They are technically identical in structure; GUIDs are sometimes displayed with uppercase and braces: {550E8400-E29B-...}.

Are the UUIDs generated here secure?

All v4 and v7 UUIDs are generated using crypto.getRandomValues() — the browser's CSPRNG — entirely in your browser. Nothing is sent to our servers.