Developer

What Is a UUID? Version 4 vs Version 7 Explained

ToolOrbit Engineering 2 min readUpdated
What Is a UUID? Version 4 vs Version 7 Explained

A UUID, or Universally Unique Identifier, is a 128-bit value used to label things without a central authority handing out numbers. Two services on opposite sides of the world can each mint UUIDs and still expect zero collisions. The ToolOrbit UUID Generator produces version 4 UUIDs, the random variant, using your browser's cryptographic randomness.

What a UUID v4 looks like

A UUID is written as 32 hexadecimal digits in five groups separated by hyphens. In version 4, almost all bits are random; a fixed version digit (4) and a variant digit identify the format. That leaves 122 random bits, which is why collisions are astronomically unlikely.

3f29c1a2-9b7e-4d3c-bf10-6a2e5d9c4471
             version 4   variant

Why version 4 is the safe default

  • No coordination needed: any client or server can generate one independently
  • Cryptographically random when sourced from crypto.getRandomValues, as this tool does
  • Excellent for database primary keys, request IDs, idempotency keys, and file names
  • Unguessable, so they do not leak sequence information the way auto-increment IDs do

Generating IDs in bulk

Set the count and the UUID Generator produces a clean list you can copy in one click. This is ideal for seeding test data, pre-allocating keys, or populating a config file. Because generation happens entirely in your browser, no identifiers are ever transmitted or logged anywhere.

Tip: A UUID is not a secret. It is unguessable enough to act as an opaque handle, but you should still authorize requests rather than relying on the ID being hard to find.

Best practices

Store UUIDs as a native UUID or binary(16) column when your database supports it, rather than as a 36-character string, to save space and speed up indexing. Use lowercase consistently, and prefer v4 unless you specifically need the time-ordering of newer schemes like UUID v7 for index locality.

UUID v4 vs v7, and when either is wrong

v4 is random and collision-safe, which makes it the default for client-generated IDs. v7 encodes the timestamp, giving roughly time-ordered values that index well in databases — the better choice when insertion order matters for performance. Avoid UUIDs entirely when the identifier must be human-readable or short (URL paths, support tickets): a 36-character ID is hostile to memory and email.

  • Use v4 for rows, carts, events, anything generated outside the server.
  • Use v7 in tables where sequential insert performance matters.
  • Never use a random UUID as a secret — it is an identifier, not a credential.

Tools mentioned

More reading

View all guides
What Is Base64? How Encoding Works and Common Mistakes
Developer

What Is Base64? How Encoding Works and Common Mistakes

What Base64 encoding actually does, where it is used, and the mistakes that cause broken or oversized output.

2 min readUpdated
encodeURI vs encodeURIComponent: Which One to Use
Developer

encodeURI vs encodeURIComponent: Which One to Use

How percent-encoding works, the difference between encoding a whole URL and a single component, and the mistakes that break links.

2 min readUpdated
How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption
Developer

How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption

What a hash function does, how to choose between SHA-256 and SHA-512, and why hashing is not encryption.

2 min readUpdated
What Is a JWT? Header, Payload and Signature Explained
Developer

What Is a JWT? Header, Payload and Signature Explained

A JSON Web Token has three parts. Learn what the header, payload and signature contain, how to read the claims, and why decoding is not verifying.

2 min readUpdated
What Is HTML Encoding? Entities & Escaping Explained
Developer

What Is HTML Encoding? Entities & Escaping Explained

Learn how HTML encoding works, why escaping prevents XSS and layout breaks, and how to encode and decode named, decimal, and hex entities.

2 min readUpdated
Unix Time Explained: Seconds, Milliseconds and Time Zones
Developer

Unix Time Explained: Seconds, Milliseconds and Time Zones

What a Unix timestamp is, how to tell seconds from milliseconds, how time zones come into it, and the values worth recognising.

2 min readUpdated
Binary, Octal, Decimal and Hex: How Number Bases Work
Developer

Binary, Octal, Decimal and Hex: How Number Bases Work

How positional number bases work, why very large values need exact arithmetic, and the hex and binary values you meet every day.

2 min readUpdated
Regex Basics: How Patterns, Flags and Character Classes Work
Developer

Regex Basics: How Patterns, Flags and Character Classes Work

How a regular expression is built, what the flags change, and the character classes you will use most.

2 min readUpdated