uuid.lol

UUID v4 Generator

Press c to copy or r for a new one

Generate in bulk

What is UUID v4?

A v4 UUID is random. 122 of its 128 bits come straight from a random source; the other six identify the version and variant.

In every modern browser and runtime that source is a cryptographically secure generator, which makes a v4 unpredictable as well as unique. On an older or unusual platform falling back to a weaker generator, the same value is still unique but no longer unguessable, so do not treat one as a secret without checking.

When should you reach for v4?

v4 is the sensible default when you want an identifier and nothing more. It carries no timestamp and no machine identity, so it leaks nothing about where it came from.

The tradeoff is that v4s do not sort. Using one as a primary key scatters inserts randomly across a B-tree index, which hurts write throughput on large tables. If that matters, use UUID v7, which keeps the randomness but puts a timestamp in front.

If you are weighing a v4 against a ULID, a KSUID or a Snowflake, the format comparison lays out what each one costs you.

Generate one in code

TypeScript

// Built in to every current browser and to Node 19+.
crypto.randomUUID();

Python

import uuid

uuid.uuid4()

Go

import "github.com/google/uuid"

id := uuid.New()

Rust

// uuid = { version = "1", features = ["v4"] }
use uuid::Uuid;

Uuid::new_v4();

SQL (Postgres)

-- gen_random_uuid() is built in from Postgres 13.
SELECT gen_random_uuid();

What is a UUID?

A UUID is a Universally Unique IDentifier: a 128-bit number used to identify something without coordinating with anyone else. It is usually written as 32 hexadecimal characters in five hyphenated groups.

UUIDs come in several versions. v4 is random, v1 and v6 encode a timestamp and a MAC address, v3 and v5 hash a name inside a namespace, and v7 encodes a Unix millisecond timestamp followed by random bits.

Why use UUIDs?

UUIDs can be generated anywhere, by anyone, with no central authority, and still be safely assumed not to collide. That makes them useful for distributed systems, offline clients, and merging data from separate databases.

They are also instantly recognisable, which makes them easy to pick out of logs.

Some databases (for example Postgres) store a UUID as a 128-bit integer rather than a 36-character string, so using one as a primary key costs far less than it looks.

What are the downsides?

Uniqueness is probabilistic, not guaranteed. The odds of two v4 UUIDs colliding are negligible, but they are not zero.

Some versions leak information. A v1 or v6 UUID contains the MAC address of the machine that generated it and the moment it was generated, which is enough to correlate a device across systems. You can see exactly what a UUID gives away with the UUID decoder.

Time-ordered IDs are also partly guessable, so they are a poor choice for anything that doubles as a secret, such as a password reset token.