What Is a UUID? Versions, Format and When to Use One

Rows of servers lit in blue in a data centre
Photo: “Free computer server room image” by rawpixel.com · CC0 1.0 · via Openverse (rawpixel)

Short answer

A UUID (universally unique identifier) is a 128-bit ID written as 32 hexadecimal digits in five groups, like 3f2b8c1e-9d4a-4c7b-8e21-5a6f0d9c7b13. It lets systems create IDs independently without a central counter. Version 4 UUIDs are random, with 122 random bits, and version 7 adds a timestamp so IDs sort by creation time. UUIDs are defined in RFC 9562.

Databases, APIs, file systems and distributed apps constantly need IDs that never clash. A simple counter (1, 2, 3…) works on one server, but breaks down when many devices create records at the same time, or when you merge data from several sources. UUIDs solve this: any computer can generate one at any time and be confident nobody else has the same value.

What a UUID looks like

A UUID is 128 bits, usually written as 36 characters: 32 hexadecimal digits (0–9, a–f) in groups of 8-4-4-4-12, separated by hyphens.

3f2b8c1e-9d4a-4c7b-8e21-5a6f0d9c7b13

UUIDs are case-insensitive; lowercase is the usual convention. Some systems strip the hyphens (32 characters) or wrap the value in braces, and our UUID generator can produce those formats too.

UUID versions

VersionHow it is madeTypical use
v1Timestamp plus a node ID (historically the MAC address)Legacy systems; can reveal when and where it was created
v3 / v5Hash of a namespace and a name (MD5 / SHA-1)The same input always gives the same UUID
v4RandomThe most common general-purpose choice
v6Reordered v1 timestampSortable replacement for v1
v7Unix timestamp in milliseconds plus random bitsDatabase keys that sort by creation time
v8Custom, vendor-specific layoutSpecial cases

RFC 9562, published in 2024, replaced the older RFC 4122 and added versions 6, 7 and 8. It also defines two special values: the nil UUID (all zeros) and the max UUID (all f’s).

How unique is a random UUID?

A version 4 UUID has 122 random bits (6 bits are fixed for the version and variant), giving 2122, or about 5.3 × 1036 possible values. Using the standard “birthday problem” approximation, if you generated one billion v4 UUIDs, the chance that any two match would be roughly 1 in 1019. You would need to generate around 100 trillion before the odds of a single duplicate reached one in a billion.

That only holds if the random numbers are good. UUIDs should be generated with a cryptographically secure random source. Our generator uses the browser’s crypto API, the same source used for the password generator.

v4 versus v7: which should you use?

Use v4 when you just need an unpredictable unique ID, such as a public identifier in a URL or an idempotency key for an API request.

Consider v7 for database primary keys. Random v4 values are inserted all over a database index, which can make indexes larger and inserts slower on very large tables. Version 7 starts with a timestamp, so new IDs arrive in roughly increasing order, which databases handle more efficiently, and you can sort records by creation time. The trade-off is that a v7 UUID reveals approximately when it was created.

UUID versus GUID

GUID (globally unique identifier) is the name Microsoft uses, for example in Windows and .NET. In practice a GUID is a UUID; the formats are the same. Some Microsoft tools display GUIDs in uppercase with braces, like {3F2B8C1E-9D4A-4C7B-8E21-5A6F0D9C7B13}.

How to generate a UUID

How to check that a string is a valid UUID

To validate user input or data from another system, check the shape with a regular expression. This pattern accepts versions 1 to 8 with the standard variant, ignoring case:

^[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

You can try it against sample values in the regex tester with the case-insensitive flag. A pattern only checks the format; it cannot tell you whether an ID actually exists in your database, so still look the record up before trusting it.

Things UUIDs are not good for

Storing UUIDs

As text, a UUID takes 36 bytes; as binary, only 16. Many databases have a native UUID type (PostgreSQL’s uuid, for example) that stores it compactly and validates the format. In JSON, UUIDs are sent as strings; see how to fix invalid JSON if your payloads are not parsing.

Frequently asked questions

What is a UUID used for?

It is a unique ID that any system can create on its own, used for database records, API requests, files, sessions and devices.

Can two UUIDs be the same?

In theory yes, but for properly generated random v4 UUIDs the probability is so small it can be ignored in practice.

What is the difference between UUID v4 and v7?

v4 is fully random. v7 starts with a timestamp, so values sort by creation time, which suits database indexes.

Is a GUID the same as a UUID?

Yes. GUID is Microsoft’s name for the same 128-bit identifier format.

Are UUIDs case-sensitive?

No. Uppercase and lowercase hex digits represent the same value, though lowercase is the usual convention.

Sources