Quick answer: a UUID (universally unique identifier) is a 128-bit value, usually written as 32 hexadecimal digits in five groups, that can be generated anywhere without coordination and still be effectively unique. Create some with the UUID generator.

What a UUID Looks Like

A UUID is written as 8-4-4-4-12 hexadecimal digits, for example 550e8400-e29b-41d4-a716-446655440000. Two of those digits carry information: the first digit of the third group is the version (4 in this example), and the first digit of the fourth group encodes the variant (8, 9, a or b for standard UUIDs).

UUID Versions in Plain English

  • Version 1: built from a timestamp and a node identifier such as a MAC address.
  • Versions 3 and 5: derived from a name using MD5 or SHA-1, so the same name always gives the same UUID.
  • Version 4: almost entirely random, with 122 random bits. This is the most common choice and what Toolbantu generates.
  • Version 7: defined in RFC 9562, it starts with a timestamp so new IDs sort in time order, which is friendlier to database indexes.

How Unique Is Unique?

With 122 random bits, you would need to generate about 2.7 quintillion (2.7 × 1018) version 4 UUIDs before the chance of a single collision reached 50%. For ordinary applications, collisions can be ignored.

When to Use a UUID

  • Primary keys when several servers or clients create records independently.
  • Public identifiers that should not reveal how many records exist, unlike 1, 2, 3.
  • File names, request IDs, correlation IDs and idempotency keys.

Things to Watch For

  • Index performance: fully random v4 keys scatter across a database index. Time-ordered UUIDs such as v7 avoid that.
  • Storage: store UUIDs in a native UUID or 16-byte binary column where possible, not as 36-character text.
  • Not a secret: a UUID is an identifier. Do not rely on it alone to protect access to data. For secrets, generate a strong random password or token.