UUID / GUID Generator
Generate secure, cryptographically random Version 4 UUIDs (Universally Unique Identifiers) for databases and web development.
Generated UUID v4 List
What is a UUID and Why Does It Matter?
A UUID (Universally Unique Identifier), also known as a GUID (Globally Unique Identifier) in Microsoft contexts, is a 128-bit label used in computing to identify information uniquely without requiring a central authority. The standard format is 32 hexadecimal characters displayed in five groups separated by hyphens: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.
The key property of a UUID is its statistical uniqueness — the probability of generating two identical UUID v4 values is so astronomically small (approximately 1 in 5.3 × 10³⁶) that it's practically treated as impossible. This makes UUIDs ideal for distributed systems where multiple servers or clients need to create records simultaneously without coordinating through a central ID-issuing service.
UUID Versions: v1, v3, v4, and v5 Explained
The UUID specification defines five versions, each using a different method of generation:
- UUID v1 (Time-based): Combines the current timestamp with the generating machine's MAC address. Globally unique in theory but can expose the MAC address — a privacy concern. Used in older database systems.
- UUID v3 (Name-based, MD5): Generates a deterministic UUID by hashing a namespace and a name string using MD5. The same input always produces the same UUID. Useful for generating consistent identifiers for known resources.
- UUID v4 (Random): Generated from 122 bits of cryptographically secure random data. This is the most widely used version today — it's what this generator creates. No MAC address, no timestamp — pure randomness.
- UUID v5 (Name-based, SHA-1): Like v3 but uses SHA-1 hashing instead of MD5. Preferred over v3 where deterministic generation is required.
Common Use Cases for UUIDs in Software Development
- Primary Keys in Databases: Using UUIDs as primary keys (instead of auto-incrementing integers) allows records to be created independently across distributed services without ID collision, and enables safe data merging across database shards.
- Session Tokens: Web applications use UUIDs as session identifiers, password reset tokens, and email verification tokens. Their randomness makes them resistant to brute-force guessing.
- Distributed Systems & Microservices: In a microservices architecture, different services (orders, users, products) need to assign IDs independently. UUIDs solve the coordination problem elegantly.
- File and Asset Naming: UUIDs are used to name uploaded files (images, documents) to avoid naming conflicts and to prevent predictable URL enumeration by malicious actors.
- Tracking Events: Analytics platforms assign UUID v4 to each event, page view, or session to uniquely track user behaviour without personally identifiable information.
UUID v4 vs Auto-Increment IDs: A Comparison
| Feature | UUID v4 | Auto-Increment Integer |
|---|---|---|
| Uniqueness scope | Global | Per-table only |
| Requires database for generation | No | Yes |
| Exposes record count | No (security benefit) | Yes (security risk) |
| Database index performance | Slightly slower (random insertion) | Faster (sequential) |
| Storage size | 16 bytes (binary) or 36 chars | 4–8 bytes |
Is UUID v4 truly unique?
UUID v4 is statistically unique, not mathematically guaranteed unique. With 2¹²² possible values (~5.3 × 10³⁶), the probability of generating a duplicate is effectively zero in practice. To put it in perspective: if you generated 1 billion UUIDs per second for the next billion years, the probability of a single collision would still be negligible. For all practical purposes, treat UUID v4 as unique.