What a UUID is
A UUID (Universally Unique Identifier, also known as a GUID in the Microsoft world) is a 128-bit identifier designed so that any system can generate one on its own — no central server, no database round trip — with a practically zero chance of repeating one that already exists. It's written as 32 hexadecimal digits in five groups of 8, 4, 4, 4, and 12 characters:
017f22e2-79b0-7cc3-98c4-dc0c0c07398f
↑ ↑
version variant
The format is defined by RFC 9562, published in 2024, which replaced 2005's RFC 4122 and added versions 6, 7, and 8. Two positions are fixed in every standard UUID: the first digit of the third group is the version (how it was generated), and the first digit of the fourth group is the variant (which in today's UUIDs is always 8, 9, a, or b).
The versions
| Version | How it's generated | Current use |
|---|---|---|
| 1 | 60-bit timestamp + the machine's MAC address | Legacy; exposes the MAC and creation time |
| 3 | MD5 hash of a namespace + a name | Deterministic IDs; v5 is preferred |
| 4 | 122 random bits | The most common: IDs that carry no information |
| 5 | SHA-1 hash of a namespace + a name | Same name → same UUID, every time |
| 6 | Like v1, with the timestamp reordered to sort correctly | Migrating from v1 |
| 7 | Unix timestamp in milliseconds + 74 random bits | Database primary keys |
| 8 | Free-form, defined by each application | Special cases |
This tool generates the two versions worth using in almost any project today: v4 when all you need is a unique identifier, and v7 when it also helps for identifiers to sort by creation time. The detailed comparison — including the impact on database indexes and what each one gives away — is in UUID v4 vs. v7: Which to Use and Why It Matters for Your Database.
How to use the tool
- Generate: pick the version and how many (up to 100 per batch), then copy them all in one click. The uppercase and no-hyphens options are for systems that expect a different format; the value itself is the same.
- v7 in bulk: within a single millisecond, the 12 bits after the timestamp act as a counter, as RFC 9562 allows, so a batch generated at once comes out already sorted.
- Inspect: paste any UUID — with or without hyphens, in braces, or with a
urn:uuid:prefix — and the tool shows its canonical form, version, variant, and, for versions 1, 6, and 7, the date and time it was created.
Can they collide?
A UUID v4 has 122 random bits, or about 5.3 × 10³⁶ possible values. Thanks to the birthday paradox, the chance of at least one collision grows with the square of how many you generate — but it starts from such an enormous number that in practice it isn't a risk:
| UUID v4s generated | Probability of at least one collision |
|---|---|
| a billion (10⁹) | ≈ 1 in 10¹⁹ |
| a trillion (10¹²) | ≈ 1 in 10¹³ |
| a quadrillion (10¹⁵) | ≈ 1 in 10 million |
| 2.7 × 10¹⁸ | ≈ 50% |
Reaching a 50% chance would mean generating a billion UUIDs per second for about 86 years. The real-world risk isn't mathematical, it's in the implementation: a generator that doesn't use a cryptographic source (like Math.random()), or a cloned virtual machine starting with the same generator state. This tool uses the browser's crypto.getRandomValues().
UUIDs in databases
Storing a UUID as text (CHAR(36)) takes 36 bytes per row plus indexes; as binary, 16. The most popular engines support them directly:
| Engine | Recommended type | Server-side generation |
|---|---|---|
| PostgreSQL | uuid (16 bytes) | gen_random_uuid() (v4); uuidv7() from PostgreSQL 18 |
| MySQL | BINARY(16) | UUID() generates v1; UUID_TO_BIN() and BIN_TO_UUID() convert |
| SQL Server | uniqueidentifier | NEWID() (random), NEWSEQUENTIALID() (sequential) |
| SQLite | 16-byte BLOB or TEXT | No built-in function: generate in the application |
In application code, crypto.randomUUID() (browsers and Node.js) and uuid.uuid4() (Python) produce v4. For v7, Python includes it from version 3.14 (uuid.uuid7()); in other languages you'll usually need a library.
A UUID is not a password
Even though a well-generated UUID v4 is very hard to guess, RFC 9562 explicitly warns against assuming UUIDs are secret. Many implementations don't use a cryptographic source, v1 and v7 are largely predictable, and identifiers tend to end up in URLs, logs, and API responses. For password reset links, session tokens, or API keys, the right tool is a dedicated random token, generated with the same care as a password.
Privacy
UUIDs are generated in your browser using the device's own cryptographic API and are never sent to a server. They aren't generated when the site is built, either: every visit gets fresh values.