Skip to content

UUID Generator guide

Tool guide. Updated .

How the XGM UUID Generator creates UUID v4, UUID v7 and ULID identifiers, how they differ, which to use for database keys, and how to decode a UUID.

What a UUID is

A universally unique identifier (UUID), also called a GUID in Microsoft ecosystems, is a 128-bit value written as 32 hexadecimal digits in five groups, such as 018f3a2e-7b1c-7d2a-9f4e-2b6c8a1d3e5f. Systems create UUIDs independently, without a central counter, and the chance of two random UUIDs colliding is negligible. That makes them popular as database keys, request IDs and file names.

RFC 9562 (2024) replaced the original RFC 4122 and added new versions, most importantly v7. Four bits of every UUID store the version, and two or three bits the variant, which is why the thirteenth hex digit shows the version number.

Layout of a UUID v7A UUID v7 stores a 48-bit Unix millisecond timestamp first, then the version nibble, random bits, the variant bits and more random bits.48 bits: Unix time in milliseconds018f3a2e-7b1c: sorts values by creation time4 bits: version (7)The first hex digit of the third group12 bits: randomRest of the third group2 bits: variant (10)First hex digit of the fourth group is 8, 9, aor b62 bits: randomRemainder of the value
A UUID v7 stores a 48-bit Unix millisecond timestamp first, then the version nibble, random bits, the variant bits and more random bits.

How to use the UUID Generator

  1. Open the UUID Generator and choose the identifier type: UUID v4, UUID v7 or ULID.
  2. Choose how many to generate and whether letters should be uppercase.
  3. Press Generate and copy the identifiers.
  4. To inspect an existing UUID, paste it into Decode a UUID to see its version, variant and embedded time.

Values are generated with the browser's secure random source and are not sent anywhere, so they can be used directly as identifiers in test data or configuration.

Choosing between v4, v7 and ULID

Identifier types
TypeStructureSortable by timeBest for
UUID v4122 random bitsNoGeneral identifiers where order does not matter
UUID v748-bit ms timestamp + random bitsYesDatabase primary keys, event and log IDs
ULID48-bit ms timestamp + 80 random bits, 26 Crockford base32 charactersYesCompact, sortable IDs in URLs and filenames
UUID v1Timestamp + node identifier (often a MAC address)PartlyLegacy systems; can leak host information. XGM uses a random node id, so it leaks nothing
UUID v3 / v5MD5 or SHA-1 of a namespace UUID and a nameNoThe same name must always give the same id; v5 for anything new

Random v4 keys scatter inserts across a database index, which causes page splits and cache misses on large tables. Time-ordered v7 keys append near the end of the index, similar to auto-increment integers, while keeping the benefits of UUIDs. For new systems that store UUIDs as primary keys, v7 is usually the better default.

v7 reveals creation time

Anyone who sees a v7 UUID or a ULID can read when it was created, to the millisecond. If that is sensitive, for example for user account IDs shown in URLs, use v4 for public identifiers.

Decoding a UUID

The version digit tells you how a UUID was made. For v1 and v7, the decoder also extracts the timestamp and shows it as a date. The variant is shown as well: values that follow RFC 9562 are labelled as such, while the NCS, Microsoft and future variants from older specifications are labelled as reserved.

Decoding is useful when debugging. A v7 key in a log line tells you when the record was created without a database query, and an unexpected v1 UUID in a new system points to an old library or a component that still uses time-and-node identifiers. The nil and max UUIDs show up as placeholders in test data and default values.

Reading the version and variant
018f3a2e-7b1c-7d2a-9f4e-2b6c8a1d3e5f
               ^    ^
               |    variant: 9 → binary 10xx (RFC 9562)
               version: 7

f47ac10b-58cc-4372-a567-0e02b2c3d479
               ^    ^
               |    variant: a → RFC 9562
               version: 4 (random)
Special values
ValueMeaning
00000000-0000-0000-0000-000000000000Nil UUID, often used as "no value"
ffffffff-ffff-ffff-ffff-ffffffffffffMax UUID, defined in RFC 9562

Generating UUIDs in code

Most platforms generate v4 UUIDs natively, and v7 support is spreading quickly in standard libraries and database extensions. When a platform lacks v7, small, well-maintained libraries implement RFC 9562; avoid writing your own timestamp packing unless you test it against the specification's examples. Whatever you use, make sure the random part comes from a cryptographically secure generator.

UUIDs in common environments
// Browser and Node.js: v4
crypto.randomUUID()

# Python 3: v4 (uuid7 is available in newer versions)
python3 -c "import uuid; print(uuid.uuid4())"

-- PostgreSQL: v4 built in
SELECT gen_random_uuid();

Generate identifiers where the record is created, usually in the application, so the ID is known before the database insert. That makes it possible to create related records, send events and return the new ID to the client without an extra round trip. It also works for offline clients that sync later.

In distributed systems, UUID v7's millisecond timestamp comes from each machine's clock. Values from machines with skewed clocks still sort roughly by time but not perfectly, so do not rely on UUID order alone for strict event ordering.

Storing UUIDs

Store UUIDs in a native UUID type where the database has one, such as uuid in PostgreSQL, or as 16 bytes of binary. The 36-character text form takes more than twice the space and makes indexes larger and slower. Convert to text only at the edges of the system, in APIs and logs.

PostgreSQL table with a UUID key
CREATE TABLE orders (
  id uuid PRIMARY KEY,
  created_at timestamptz NOT NULL DEFAULT now(),
  customer_email text NOT NULL
);

-- application generates UUID v7 values, for example for an order from anna@example.com
  • Compare UUIDs case-insensitively in text form; RFC 9562 recommends lowercase output.
  • Do not use UUIDs as secrets. v4 values are hard to guess, but they are designed as identifiers, not access tokens.
  • Do not parse meaning out of v4 UUIDs; only v1, v6 and v7 carry timestamps.

FAQ

Can two UUIDs be the same?

In theory yes, in practice no. Random v4 UUIDs have 122 random bits; generating billions per second for many years still gives a negligible chance of a collision.

Is a GUID the same as a UUID?

Yes. GUID is Microsoft's name for the same 128-bit identifier format.

Should I use UUID v7 for primary keys?

Usually yes for new systems. Time-ordered values keep database indexes compact and inserts fast, unlike random v4 keys.

What is a ULID?

A 128-bit identifier with a 48-bit millisecond timestamp and 80 random bits, written as 26 base32 characters. It sorts by time and is shorter than a UUID in text form.

Can I get the creation time from a UUID v4?

No. v4 is fully random. Only time-based versions such as v1, v6 and v7 contain a timestamp.

Are generated UUIDs sent to XGM?

No. They are generated in your browser and never uploaded.

Uppercase or lowercase?

Both represent the same value. RFC 9562 recommends lowercase when generating, and comparisons should ignore case.

Can a UUID be used as an API key?

It is better not to. Generate secrets with a secure random generator and enough length, and treat identifiers and secrets as different things.

How many UUIDs can I generate at once?

The generator creates batches for test data and seeding. For very large volumes, generate them in code, where the same random source is available without copying from a page.

Why does my v7 UUID look similar to the previous one?

UUIDs generated in the same millisecond share their first 12 hex digits, the timestamp. The random part after the version digit still makes each value unique.

What are versions 6 and 8?

Version 6 reorders the v1 timestamp for sorting, and version 8 is a free-form format for custom layouts. Both are defined in RFC 9562.

Sources