What is a UUID, and which version to use
A UUID, or universally unique identifier, is a 128-bit number used to label things without asking a central system for the next free number. Two computers that have never talked to each other can each make a UUID and be confident the two will not clash. There are several versions, and the right one depends on what you need the ID for.
Try it now: UUID Generator.
What a UUID looks like
A UUID is written as 32 hexadecimal digits in five groups, 8-4-4-4-12, which makes 36 characters with the hyphens. The first digit of the third group is the version. In the example below it is 1. One special value is the nil UUID, all zeros, written 00000000-0000-0000-0000-000000000000, which is used to mean that there is no value. A good validator also tells you the version and the variant, and for the time-based versions it can read the creation time back out of the ID.
123e4567-e89b-12d3-a456-426614174000
^ version 1The versions that matter
Version 3 is the older sibling of version 5 and uses MD5 instead of SHA-1. Versions 6 and 8 also exist, but you will meet them far less often.
| Version | How it is made | Use it for |
|---|---|---|
| 1 | Current time plus a node ID | Rarely; it reveals when it was made |
| 4 | 122 random bits | Random IDs: the usual default |
| 5 | SHA-1 hash of a namespace and a name | Stable IDs made from a name |
| 7 | Unix time in milliseconds plus random bits | Database keys that sort by time |
Name-based IDs are repeatable
A version 5 UUID is not random. Hash the same namespace and the same name and you always get the same UUID. For the DNS namespace and the name python.org the result is 886313e1-3b8a-5372-9b90-0c9aee199e5d, on any computer, every time. That is useful when you want an ID for something that already has a unique name, such as a web address.
How unlikely is a collision?
A version 4 UUID has 122 random bits. You would need to create about 2.7 quintillion of them before the chance of any two matching reached 50 percent. In practice a duplicate almost always comes from a bug, such as copying an ID or using a weak random source, and not from bad luck.
Why version 7 suits databases
Random version 4 keys land in random places in a database index, which makes inserts slower as the table grows. A version 7 UUID starts with the time, so new IDs sort after older ones and are added near the end of the index, while the rest stays random so they are still unique. The trade-off is that the ID shows roughly when the record was created. Version 7 was standardised in RFC 9562 in 2024.
What a UUID is not
A UUID is an identifier, not a secret. Do not treat one as a password or an access token. If an ID must be unguessable, it has to come from a secure random source and be handled like a secret, and a version 1 or version 7 UUID is a poor choice because part of it is predictable.