Developer Tools

What Is a UUID? How UUID v4 Works and When to Use It

Learn what a UUID is, how random UUID v4 values are structured, when to use them, and why UUIDs are identifiers rather than secrets.

A UUID is a 128-bit identifier designed to be generated without a central numbering service. UUID version 4 fills the non-reserved bits with random or pseudorandom data, which makes it convenient for distributed systems, test records, filenames, and correlation IDs.

What does UUID mean?

UUID means Universally Unique Identifier. The current IETF standard defines a UUID as 16 octets, or 128 bits. Its common text form contains 32 hexadecimal digits in five groups: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.

The term GUID is commonly used in Microsoft ecosystems. In everyday development it often refers to the same familiar identifier shape, although binary serialization conventions can differ in specific systems.

How UUID v4 is structured

In UUID v4, 122 bits are random or pseudorandom; six bits are reserved for the version and variant. The first hexadecimal digit of the third group is 4. The first digit of the fourth group is one of 8, 9, a, or b for the IETF variant.

3f2a6d71-48e1-4b37-9d5a-7f26a0c821ce

That layout helps software recognize the UUID type. It does not encode a creation time, database location, or owner in a version 4 value.

Generate a UUID v4 online

  1. Open the UUID Generator.
  2. Choose how many values you need.
  3. Generate the UUIDs with the browser's cryptographic random source.
  4. Copy or download them.
  5. Validate your application's storage and case-normalization rules.

Hyphenated lowercase text is a common interchange form, but UUID comparisons should follow the rules of the system receiving the value.

When should you use a UUID?

  • Creating identifiers independently across services or devices.
  • Preparing fixtures and test records without a shared sequence.
  • Assigning public-facing resource IDs that should not reveal a simple row count.
  • Correlating logs and requests across components.
  • Naming temporary artifacts where a collision would be inconvenient.

For time-ordered database keys, investigate UUID v7 or another storage-aware identifier. The current UUID standard recommends UUID v7 over time-based versions 1 and 6 when possible, but application and database support should guide the choice.

A UUID is not a password or access token

Uniqueness and secrecy are different properties. A UUID can be hard to guess when generated well, but applications should not treat an identifier alone as authorization. Use a purpose-built cryptographic token with suitable entropy, expiration, storage, and verification rules for password resets, sessions, API access, and other security decisions.

Can UUIDs collide?

No finite identifier space offers a mathematical guarantee that independently generated values never collide. With high-quality random UUID v4 generation, accidental collisions are extremely unlikely for ordinary workloads, but systems with severe safety consequences should still define duplicate handling and enforce uniqueness where appropriate.

Frequently asked questions

Is a UUID v4 always unique?

It is designed to make accidental duplication extraordinarily unlikely when generated with high-quality randomness, not to provide an absolute guarantee. Enforce a unique constraint and define collision handling where duplicates would matter.

Can a UUID reveal when it was created?

Version 4 does not encode a timestamp. Other versions have different layouts: UUID v7 is time ordered and includes a Unix-epoch millisecond timestamp, so select a version according to application requirements.

Should UUID text be uppercase or lowercase?

Hexadecimal UUID text is case-insensitive in normal comparison. Lowercase is a common canonical display choice. Store and compare consistently, and do not create separate records merely because letter case differs.

Sources checked

UUID structure and version 4 requirements were checked against RFC 9562 on August 12, 2026; consult the RFC for implementation-level validation rules.