A UUID (Universally Unique Identifier) is a 128-bit value used to identify information without requiring a central authority to hand out IDs. It's conventionally written as 32 hexadecimal digits split into five groups separated by hyphens — 8-4-4-4-12 characters, 36 characters total including the hyphens. The format is standardized by RFC 9562 (2024), which obsoletes the older RFC 4122.
How it works
Not all UUIDs are random. The RFC defines several versions, identified by a fixed nibble in the string:
- v1 — timestamp + (usually) the generating machine's MAC address; can leak host identity.
- v3 — deterministic, built from an MD5 hash of a namespace + name (same input always yields the same UUID).
- v4 — the common case: 122 bits of randomness, with 6 fixed bits marking the version and RFC variant.
- v5 — like v3 but hashes with SHA-1 instead of MD5.
- v7 — a newer, sortable format: a millisecond Unix timestamp in the high bits followed by random bits, so UUIDs generated later sort after earlier ones — useful as database primary keys.
In a v4 UUID, the version nibble always appears as the first character of the third group, and the variant nibble (first character of the fourth group) is always 8, 9, a, or b: e.g. d9de9389-f7cf-49ec-ba95-1ed893d375fe — 4 marks version 4, b marks the variant.
Example:
d9de9389-f7cf-49ec-ba95-1ed893d375fe
└┬┘ └┬┘
4 = version b = variant (RFC 9562)
Common pitfalls
- A v4 UUID's randomness depends entirely on the generator's source of entropy — use a cryptographically secure RNG (
crypto.randomUUID()), never Math.random().
- With 122 random bits, collisions are astronomically unlikely: generating roughly 2.71 quintillion (2.71×10¹⁸) v4 UUIDs gives just a 50% chance of one collision — but a broken RNG changes that math completely.
- v1/v3/v5 UUIDs are not random and not secret — never use them as unguessable tokens or session IDs.
- UUIDs are large (16 bytes) and, unlike v7, random v4 values index poorly as a database primary key because insert order and UUID order are unrelated.
Related terms
- SHA-1 — the hash function UUID v5 uses to derive a deterministic ID from a namespace and name.
- MD5 — the hash function UUID v3 uses for the same purpose.
- Unix timestamp — the time source embedded in the high bits of a v1 or v7 UUID.
- ISO 8601 — a human-readable alternative when you need a sortable, timestamped identifier that a person can also read.
See also
- Tool: UUID / ULID Generator — generate v4 UUIDs (and ULIDs) in bulk, validate existing ones, and copy with one click.