What Is a UUID? Versions, Format and When to Use One
Short answer
A UUID (universally unique identifier) is a 128-bit ID written as 32 hexadecimal digits in five groups, like 3f2b8c1e-9d4a-4c7b-8e21-5a6f0d9c7b13. It lets systems create IDs independently without a central counter. Version 4 UUIDs are random, with 122 random bits, and version 7 adds a timestamp so IDs sort by creation time. UUIDs are defined in RFC 9562.
Databases, APIs, file systems and distributed apps constantly need IDs that never clash. A simple counter (1, 2, 3…) works on one server, but breaks down when many devices create records at the same time, or when you merge data from several sources. UUIDs solve this: any computer can generate one at any time and be confident nobody else has the same value.
What a UUID looks like
A UUID is 128 bits, usually written as 36 characters: 32 hexadecimal digits (0–9, a–f) in groups of 8-4-4-4-12, separated by hyphens.
3f2b8c1e-9d4a-4c7b-8e21-5a6f0d9c7b13
- The first digit of the third group is the version. Here it is 4, so this is a version 4 (random) UUID.
- The first digit of the fourth group shows the variant. For standard UUIDs it is 8, 9, a or b.
UUIDs are case-insensitive; lowercase is the usual convention. Some systems strip the hyphens (32 characters) or wrap the value in braces, and our UUID generator can produce those formats too.
UUID versions
| Version | How it is made | Typical use |
|---|---|---|
| v1 | Timestamp plus a node ID (historically the MAC address) | Legacy systems; can reveal when and where it was created |
| v3 / v5 | Hash of a namespace and a name (MD5 / SHA-1) | The same input always gives the same UUID |
| v4 | Random | The most common general-purpose choice |
| v6 | Reordered v1 timestamp | Sortable replacement for v1 |
| v7 | Unix timestamp in milliseconds plus random bits | Database keys that sort by creation time |
| v8 | Custom, vendor-specific layout | Special cases |
RFC 9562, published in 2024, replaced the older RFC 4122 and added versions 6, 7 and 8. It also defines two special values: the nil UUID (all zeros) and the max UUID (all f’s).
How unique is a random UUID?
A version 4 UUID has 122 random bits (6 bits are fixed for the version and variant), giving 2122, or about 5.3 × 1036 possible values. Using the standard “birthday problem” approximation, if you generated one billion v4 UUIDs, the chance that any two match would be roughly 1 in 1019. You would need to generate around 100 trillion before the odds of a single duplicate reached one in a billion.
That only holds if the random numbers are good. UUIDs should be generated with a cryptographically secure random source. Our generator uses the browser’s crypto API, the same source used for the password generator.
v4 versus v7: which should you use?
Use v4 when you just need an unpredictable unique ID, such as a public identifier in a URL or an idempotency key for an API request.
Consider v7 for database primary keys. Random v4 values are inserted all over a database index, which can make indexes larger and inserts slower on very large tables. Version 7 starts with a timestamp, so new IDs arrive in roughly increasing order, which databases handle more efficiently, and you can sort records by creation time. The trade-off is that a v7 UUID reveals approximately when it was created.
UUID versus GUID
GUID (globally unique identifier) is the name Microsoft uses, for example in Windows and .NET. In practice a GUID is a UUID; the formats are the same. Some Microsoft tools display GUIDs in uppercase with braces, like {3F2B8C1E-9D4A-4C7B-8E21-5A6F0D9C7B13}.
How to generate a UUID
- Online: the UUID generator creates one or many v4 UUIDs, with uppercase, no-hyphen and brace options.
- JavaScript (browsers and Node.js):
crypto.randomUUID(). In browsers it is available in secure contexts (HTTPS). - Python:
import uuid; uuid.uuid4(). - PostgreSQL:
gen_random_uuid(). - Command line:
uuidgenon macOS and most Linux systems.
How to check that a string is a valid UUID
To validate user input or data from another system, check the shape with a regular expression. This pattern accepts versions 1 to 8 with the standard variant, ignoring case:
^[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
You can try it against sample values in the regex tester with the case-insensitive flag. A pattern only checks the format; it cannot tell you whether an ID actually exists in your database, so still look the record up before trusting it.
Things UUIDs are not good for
- Secrets: a UUID is an identifier, not a password or API key. Even random v4 values can end up in logs and URLs. For secret tokens, generate dedicated random values; for checking integrity, use a hash from the hash generator. Read how to create strong passwords for the difference.
- Human-friendly IDs: 36 characters are hard to read aloud or type. Order numbers and invoice numbers are usually better as short sequences.
- Small random choices: to pick a number in a range, use the random number generator; for draws, see how to pick a random winner.
Storing UUIDs
As text, a UUID takes 36 bytes; as binary, only 16. Many databases have a native UUID type (PostgreSQL’s uuid, for example) that stores it compactly and validates the format. In JSON, UUIDs are sent as strings; see how to fix invalid JSON if your payloads are not parsing.
Frequently asked questions
What is a UUID used for?
It is a unique ID that any system can create on its own, used for database records, API requests, files, sessions and devices.
Can two UUIDs be the same?
In theory yes, but for properly generated random v4 UUIDs the probability is so small it can be ignored in practice.
What is the difference between UUID v4 and v7?
v4 is fully random. v7 starts with a timestamp, so values sort by creation time, which suits database indexes.
Is a GUID the same as a UUID?
Yes. GUID is Microsoft’s name for the same 128-bit identifier format.
Are UUIDs case-sensitive?
No. Uppercase and lowercase hex digits represent the same value, though lowercase is the usual convention.