What is a UUID?
A UUID (Universally Unique Identifier) is a 128-bit value written as 32 hexadecimal digits in five groups, such as 550e8400-e29b-41d4-a716-446655440000. Anyone can generate one independently, without a central registry, and still be practically certain it is unique. Microsoft calls the same thing a GUID. UUIDs are defined in RFC 9562 (2024), which replaced RFC 4122.
The first digit of the third group is the version (the 4 in 41d4 above), and the first digit of the fourth group encodes the variant (8, 9, a or b for standard UUIDs).
UUID v4 vs v7
| Version | Contents | Good for |
|---|---|---|
| v4 | 122 random bits | General-purpose IDs that should not be guessable or reveal anything |
| v7 | 48-bit Unix timestamp in milliseconds + random bits | Database primary keys (sorted by creation time) |
| v1 | Timestamp + node ID (often the MAC address) | Legacy systems; leaks the host's MAC address |
Because v4 values are completely random, inserting them as primary keys scatters writes across a B-tree index, which can hurt insert performance and cache locality. v7 UUIDs sort by creation time, so new rows land at the end of the index, much like an auto-increment key — while remaining globally unique.
Can two UUIDs collide?
A v4 UUID has 122 random bits, or about 5.3 × 1036 possible values. By the birthday bound you would need to generate roughly 2.7 × 1018 v4 UUIDs before the chance of even one duplicate reaches 50% — about 86 years at one billion UUIDs per second. In practice, a collision is far more likely to come from a broken random number generator than from chance.
Generate a UUID in code
| Language | Code |
|---|---|
| JavaScript | crypto.randomUUID() (v4) |
| Python | str(uuid.uuid4()) |
| Java | UUID.randomUUID() (v4) |
| C# / .NET | Guid.NewGuid() (v4), Guid.CreateVersion7() (.NET 9+) |
| PostgreSQL | gen_random_uuid() (v4), uuidv7() (PostgreSQL 18+) |
| MySQL | UUID() (v1) |
| Linux / macOS | uuidgen |
Frequently asked questions
Can I use a UUID as a password or secret token?
A v4 UUID from a secure random source is hard to guess, but it carries only 122 random bits and was not designed as a secret — not every library guarantees a cryptographically secure source. Use a dedicated token generator for secrets, and never use v1 or v7 UUIDs, which contain a readable timestamp.
Should UUIDs be uppercase or lowercase?
RFC 9562 says UUIDs should be output in lowercase and compared case-insensitively. Some environments, such as the Windows registry, display GUIDs in uppercase and often wrap them in braces — use the options above to match.
Can I get the creation time from a UUID v7?
Yes. The first 48 bits of a v7 UUID are a Unix timestamp in milliseconds. Paste a v7 (or v1 / v6) UUID into “Inspect a UUID” above to see the embedded time. For example, 0192f3a4-5b6c-7d8e-… was created at 2024-11-03T20:08:07.788Z.