uuid.lol

UUID v2 has no official generator

The specification reserved the version but never defined it well enough to implement interoperably, so nothing here would be a real v2.

Use UUID v4 for a random ID, or UUID v7 for a sortable one.

If what you wanted from v2 was the time-and-node layout, UUID v6 carries exactly those fields and sorts by creation time, which makes it the modern answer. UUID v1 holds the same fields in the original, unsorted order.

What v2 was supposed to be

v2 is the DCE Security UUID. It takes the v1 layout and replaces the low 32 bits of the timestamp with a local identifier, typically a POSIX user or group ID, and the clock sequence low byte with a domain number.

Trading away those timestamp bits drops the resolution to roughly seven minutes, and RFC 4122 described the format without specifying the behaviour, so implementations never agreed. RFC 9562 lists v2 as reserved and points elsewhere.

What is a UUID?

A UUID is a Universally Unique IDentifier: a 128-bit number used to identify something without coordinating with anyone else. It is usually written as 32 hexadecimal characters in five hyphenated groups.

UUIDs come in several versions. v4 is random, v1 and v6 encode a timestamp and a MAC address, v3 and v5 hash a name inside a namespace, and v7 encodes a Unix millisecond timestamp followed by random bits.

Why use UUIDs?

UUIDs can be generated anywhere, by anyone, with no central authority, and still be safely assumed not to collide. That makes them useful for distributed systems, offline clients, and merging data from separate databases.

They are also instantly recognisable, which makes them easy to pick out of logs.

Some databases (for example Postgres) store a UUID as a 128-bit integer rather than a 36-character string, so using one as a primary key costs far less than it looks.

What are the downsides?

Uniqueness is probabilistic, not guaranteed. The odds of two v4 UUIDs colliding are negligible, but they are not zero.

Some versions leak information. A v1 or v6 UUID contains the MAC address of the machine that generated it and the moment it was generated, which is enough to correlate a device across systems. You can see exactly what a UUID gives away with the UUID decoder.

Time-ordered IDs are also partly guessable, so they are a poor choice for anything that doubles as a secret, such as a password reset token.