550e8400-e29b-41d4-a716-446655440000. Thirty-two hex digits that are, for all practical purposes, unique across every computer that will ever generate them — no coordination required. That property makes UUIDs the default identifier for distributed systems. But not all UUIDs are built the same.
Why they work
A UUID packs 122 bits of randomness (in v4) into a standard format. The collision math is overwhelmingly in your favor: you'd need to generate about a billion UUIDs per second for a century before reaching even a minuscule collision chance. Uniqueness without a central counter means any service, device, or offline client can mint IDs independently and merge later without conflicts.
Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →
The versions that matter
- v1 — timestamp + MAC address. Generated from the current time and the machine's network address. Ordered by creation time (nice for databases) but leaks when and where the ID was created — a genuine privacy concern, and largely obsolete today.
- v4 — random. 122 random bits. Unpredictable, private, and the right default for most uses: session IDs, API keys' public parts, entity identifiers. Its only flaw is randomness itself — indexes fragment because new IDs scatter randomly.
- v7 — timestamp + random. The modern best of both: a millisecond timestamp prefix (sortable, index-friendly) plus random bits (no MAC leak, unguessable remainder). For new database primary keys, v7 is now the recommended choice.
Versions 3 and 5 (namespace-hashed) are deterministic — same input, same UUID — useful for deriving stable IDs from names rather than generating fresh ones.
When not to use UUIDs
UUIDs are 36 characters of string (or 16 bytes binary) — overkill for small-scale needs. A single-database app is often better served by auto-incrementing integers: smaller, faster to index, and human-friendly in URLs and logs. And never use UUIDs as secrets alone: v4 is unguessable but not access control — pair identifiers with actual authorization.
Generate them locally
The UUID generator & validator mints v4 UUIDs in your browser and validates existing ones — useful when debugging "is this string actually a UUID, and which version?" Randomness stays on your device, which is exactly where ID generation should happen.