UUIDs explained: v4, v7 and choosing the right version
A UUID is a 128-bit identifier that any computer can create on its own, with no central counter, and still be practically certain nobody else has made the same one. That is why they end up as database keys, file names, request IDs and order numbers. Most UUIDs you see are version 4, which is pure randomness; version 7, standardised in 2024, adds the time of creation and is quickly becoming the better choice for databases. This guide covers how to read one, how the versions differ, how likely a collision really is, and which to pick.
What a UUID looks like
A UUID is 128 bits, written as 32 hexadecimal digits in five groups separated by hyphens — 8, 4, 4, 4 and 12 digits, 36 characters in all:
3f2a9c1e-5b7d-4e8a-9c21-7d4e5f6a8b90A version 4 UUID.01a0d86f-ca00-7b3e-9f21-6c4d8a0e5b17A version 7 UUID.
The current standard is RFC 9562, published in May 2024, which replaced RFC 4122 from 2005. Letters may be written in upper case, lower case or a mix of both; all three mean the same value.
Databases with a native UUID type, such as PostgreSQL, store the value in 16 bytes rather than as 36 characters of text.
Reading the version
Two digits identify what kind of UUID you have. The first digit of the third group is the version. The first digit of the fourth group is the variant: for every UUID made to the standard it is 8, 9, a or b.
| UUID | Version | What it is |
|---|---|---|
3f2a9c1e-5b7d-4e8a-9c21-7d4e5f6a8b90 | 4 | Random |
01a0d86f-ca00-7b3e-9f21-6c4d8a0e5b17 | 7 | Time-ordered, created on 25 September 2026 at 12:00:00 UTC |
00000000-0000-0000-0000-000000000000 | — | The Nil UUID: all zeros, used to mean “no value” |
ffffffff-ffff-ffff-ffff-ffffffffffff | — | The Max UUID: all ones, used as an upper bound |
The versions
| Version | How it is made | Use today |
|---|---|---|
| 1 | Timestamp and the computer's network (MAC) address | Legacy; it reveals which machine made it |
| 3 | MD5 hash of a namespace and a name | Only to reproduce existing IDs; prefer version 5 |
| 4 | 122 random bits | The default almost everywhere |
| 5 | SHA-1 hash of a namespace and a name | The same name always gives the same UUID |
| 6 | Version 1 reordered so that it sorts by time | Only where version 1 is already in use |
| 7 | Millisecond Unix timestamp plus random bits | New databases and anything that benefits from time order |
| 8 | Layout defined by the application | Experimental or vendor-specific formats |
Version 2 exists for an old security system and is outside the standard's scope. RFC 9562 says implementations should use version 7 instead of versions 1 and 6 where possible.
Version 4: random
A version 4 UUID fixes 6 of its 128 bits to mark the version and variant, and fills the other 122 with random data. The standard asks for a cryptographically secure random number generator, which is what browsers provide through crypto.randomUUID() — the function the nTools generator uses.
With 122 random bits, a collision is not a practical concern. There is a 50% chance of any two matching only after about 2.7 × 10¹⁸ UUIDs — at a billion a second, that takes about 86 years. After a trillion UUIDs, the chance that any two are the same is about 1 in 10 trillion. The realistic risk is a broken random number generator, not the maths.
Version 7: sorted by time
A version 7 UUID puts the Unix time in milliseconds in its first 48 bits, then the version and variant, then 74 bits of randomness or a counter. Because the time comes first, UUIDs created later sort after earlier ones, both as text and as bytes.
In the example above, the first 12 hexadecimal digits, 01a0d86fca00, are 1,790,337,600,000 milliseconds after 1 January 1970: 25 September 2026 at 12:00:00 UTC. The 48-bit timestamp lasts until the year 10889. Within a single millisecond, generators either use random bits or add a counter so that UUIDs from the same process still come out in order.
Support is arriving in the tools people use: PostgreSQL 18, released in September 2025, added a built-in uuidv7() function alongside uuidv4().
Which one to use as a database key
Most databases keep primary keys in a B-tree index, which stays efficient when new keys arrive in order.
- Version 4 keys land at random places in the index. On small tables that does not matter; on large ones, each insert touches a different part of the index, which means more page splits, more cache misses and larger indexes.
- Version 7 keys arrive in time order, so new rows are added near the end of the index, much as with an auto-increment number — while still being creatable anywhere, without asking the database for the next value.
- Auto-increment integers are smaller and fastest, but they need one central counter and reveal how many records exist and in what order they were made.
For a new table that needs UUIDs, version 7 is usually the better choice. Version 4 remains the right one when the creation time must not be visible from the ID.
What a UUID is not
- Not a secret. A version 7 UUID shows when it was created, to the millisecond, to anyone who reads it. A version 4 UUID is hard to guess, but IDs get logged, shared in URLs and shown in interfaces. Links for password resets or private files should use a dedicated random token, not the record's ID.
- Not a source of information. The standard recommends treating UUIDs as opaque values: store and compare them, but do not build logic that depends on reading their parts.
- Not always version 4. Code that expects randomness should not assume it; check the version digit when it matters.
Frequently asked questions
Can two random UUIDs ever be the same?
In theory, yes; in practice, no. You would need around 2.7 × 10¹⁸ version 4 UUIDs for a 50% chance of a single match, provided they come from a proper random number generator.
Is a GUID the same as a UUID?
Yes. GUID is Microsoft's name for the same 128-bit identifier. Windows tools often show it in upper case or wrapped in braces, such as {3F2A9C1E-5B7D-4E8A-9C21-7D4E5F6A8B90}, but the value is the same.
Are UUIDs case-sensitive?
No. 3F2A9C1E-… and 3f2a9c1e-… are the same UUID. Compare them case-insensitively, or store them in a native UUID column, which avoids the question.
Which version does the nTools generator create?
Version 4, using the browser's crypto.randomUUID(). It creates up to 100 at a time, entirely on your device.
Related guides
- IP addresses explained: IPv4, IPv6 and the reserved ranges
- DNS records explained: A, AAAA, CNAME, MX, TXT and NS
- Subnets and CIDR explained: prefixes, masks and usable hosts
- Unix timestamps and time zones explained
- Image formats explained: JPEG, PNG, WebP, AVIF and HEIC
- Password strength explained: length, entropy and passphrases
- QR codes explained: capacity, error correction and print size
- Percentages and VAT explained: adding, removing and stacking