UUIDs explained: v4, v7 and choosing the right version

Updated:

A UUID is a 128-bit identifier that any computer can create on its own, with no central counter, and still be practically certain nobody else has made the same one. That is why they end up as database keys, file names, request IDs and order numbers. Most UUIDs you see are version 4, which is pure randomness; version 7, standardised in 2024, adds the time of creation and is quickly becoming the better choice for databases. This guide covers how to read one, how the versions differ, how likely a collision really is, and which to pick.

What a UUID looks like

A UUID is 128 bits, written as 32 hexadecimal digits in five groups separated by hyphens — 8, 4, 4, 4 and 12 digits, 36 characters in all:

The current standard is RFC 9562, published in May 2024, which replaced RFC 4122 from 2005. Letters may be written in upper case, lower case or a mix of both; all three mean the same value.

Databases with a native UUID type, such as PostgreSQL, store the value in 16 bytes rather than as 36 characters of text.

Reading the version

Two digits identify what kind of UUID you have. The first digit of the third group is the version. The first digit of the fourth group is the variant: for every UUID made to the standard it is 8, 9, a or b.

UUIDVersionWhat it is
3f2a9c1e-5b7d-4e8a-9c21-7d4e5f6a8b904Random
01a0d86f-ca00-7b3e-9f21-6c4d8a0e5b177Time-ordered, created on 25 September 2026 at 12:00:00 UTC
00000000-0000-0000-0000-000000000000—The Nil UUID: all zeros, used to mean “no value”
ffffffff-ffff-ffff-ffff-ffffffffffff—The Max UUID: all ones, used as an upper bound

The versions

VersionHow it is madeUse today
1Timestamp and the computer's network (MAC) addressLegacy; it reveals which machine made it
3MD5 hash of a namespace and a nameOnly to reproduce existing IDs; prefer version 5
4122 random bitsThe default almost everywhere
5SHA-1 hash of a namespace and a nameThe same name always gives the same UUID
6Version 1 reordered so that it sorts by timeOnly where version 1 is already in use
7Millisecond Unix timestamp plus random bitsNew databases and anything that benefits from time order
8Layout defined by the applicationExperimental or vendor-specific formats

Version 2 exists for an old security system and is outside the standard's scope. RFC 9562 says implementations should use version 7 instead of versions 1 and 6 where possible.

Version 4: random

A version 4 UUID fixes 6 of its 128 bits to mark the version and variant, and fills the other 122 with random data. The standard asks for a cryptographically secure random number generator, which is what browsers provide through crypto.randomUUID() — the function the nTools generator uses.

With 122 random bits, a collision is not a practical concern. There is a 50% chance of any two matching only after about 2.7 × 10¹⁸ UUIDs — at a billion a second, that takes about 86 years. After a trillion UUIDs, the chance that any two are the same is about 1 in 10 trillion. The realistic risk is a broken random number generator, not the maths.

UUID generator

Version 7: sorted by time

A version 7 UUID puts the Unix time in milliseconds in its first 48 bits, then the version and variant, then 74 bits of randomness or a counter. Because the time comes first, UUIDs created later sort after earlier ones, both as text and as bytes.

In the example above, the first 12 hexadecimal digits, 01a0d86fca00, are 1,790,337,600,000 milliseconds after 1 January 1970: 25 September 2026 at 12:00:00 UTC. The 48-bit timestamp lasts until the year 10889. Within a single millisecond, generators either use random bits or add a counter so that UUIDs from the same process still come out in order.

Support is arriving in the tools people use: PostgreSQL 18, released in September 2025, added a built-in uuidv7() function alongside uuidv4().

Which one to use as a database key

Most databases keep primary keys in a B-tree index, which stays efficient when new keys arrive in order.

For a new table that needs UUIDs, version 7 is usually the better choice. Version 4 remains the right one when the creation time must not be visible from the ID.

What a UUID is not

Frequently asked questions

Can two random UUIDs ever be the same?

In theory, yes; in practice, no. You would need around 2.7 × 10¹⁸ version 4 UUIDs for a 50% chance of a single match, provided they come from a proper random number generator.

Is a GUID the same as a UUID?

Yes. GUID is Microsoft's name for the same 128-bit identifier. Windows tools often show it in upper case or wrapped in braces, such as {3F2A9C1E-5B7D-4E8A-9C21-7D4E5F6A8B90}, but the value is the same.

Are UUIDs case-sensitive?

No. 3F2A9C1E-… and 3f2a9c1e-… are the same UUID. Compare them case-insensitively, or store them in a native UUID column, which avoids the question.

Which version does the nTools generator create?

Version 4, using the browser's crypto.randomUUID(). It creates up to 100 at a time, entirely on your device.

Related guides