Use UUIDv4 for a new, independent identifier; use UUIDv3 or UUIDv5 when the same namespace and canonical name must always produce the same identifier; use UUIDv1 only when embedding creation time and a node value is appropriate. UUIDs identify objects, but none of the four versions should be treated as a password, bearer token, or authorization capability. RFC 9562 (May 2024) is the current IETF UUID specification: read the standard.
UUID versions at a glance
| Version | How it is made | Use it when | Important caveat |
|---|---|---|---|
| v1 | 60-bit timestamp from the Gregorian UUID epoch, clock sequence, and node field | You specifically need a time-associated identifier | A MAC-derived node can expose host information, and the timestamp reveals creation ordering |
| v3 | MD5 over a namespace UUID and canonical name, with UUID version and variant bits set | You need a stable name-to-UUID mapping and v3 interoperability | Namespace and name canonicalization must never change |
| v4 | Random or pseudorandom bits, with required version and variant bits | You need a fresh identifier without encoding a name or time | Quality of the random source matters; random values have poor database-index locality |
| v5 | SHA-1 over a namespace UUID and canonical name, with UUID version and variant bits set | You need deterministic name-based IDs using the standard v5 algorithm | Do not substitute another hash and still call the result v5 |
RFC 9562 also defines UUIDv6 and UUIDv7, time-ordered alternatives worth evaluating when index locality matters. They are not replacements for a deterministic name mapping.
Choose the right UUID version
Choose v4 for independent IDs
Generate v4 when an object needs a new identifier that is unrelated to an input name. After the version and variant bits are fixed, 122 bits remain random. Distributed generation is practical when every host uses a trustworthy cryptographic random source, but uniqueness is an engineering assumption, not an integrity guarantee.
Choose v3 or v5 for repeatable IDs
Both versions hash a namespace UUID and a name. The same namespace and exactly the same canonical name bytes produce the same UUID on every conforming implementation. Pick v3 for compatibility with systems that require MD5-based UUIDs; pick v5 for the SHA-1-based standard definition. If an application requires a newer hash algorithm, RFC 9562 directs you to UUIDv8 rather than relabeling the result v5.
#1 Best Overall
Choose v1 only for time-associated values
UUIDv1 stores a 60-bit count of 100-nanosecond intervals since 00:00:00 on 15 October 1582, plus a clock sequence and node field. The clock sequence helps avoid duplicates after clock rollback or node changes. A node may be an IEEE 802 MAC address or a randomly derived value. Do not expose v1 values when timestamp, network-interface, or manufacturer information is sensitive.
Consider v6 or v7 for ordered database keys
Random v4 values can scatter inserts through a B-tree or similar index. RFC 9562 identifies this locality concern and standardizes v6 and v7 as time-ordered alternatives. The RFC does not provide a universal benchmark, so measure your own workload before promising a performance improvement. Also avoid making a name-based UUID the primary key if the name can later change.
Generate UUIDs in common languages
Python
Python’s standard library implements all four requested versions:
from uuid import uuid1, uuid3, uuid4, uuid5, NAMESPACE_URL
print("v1:", uuid1())
print("v4:", uuid4())
# The name is a URL in this example. Keep this canonicalization rule stable.
name = "https://example.com/users/42"
print("v3:", uuid3(NAMESPACE_URL, name))
print("v5:", uuid5(NAMESPACE_URL, name))
uuid3 and uuid5 return the same value each time you run the program with the same namespace and name. A changed case, Unicode normalization form, trailing slash, URL encoding, or whitespace creates a different name and therefore a different UUID.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Node.js
Recent Node.js releases provide v4 through the built-in crypto module. For v1, v3, and v5, use a UUID package that explicitly documents RFC 9562-compatible implementations, or implement the standard carefully rather than silently producing a nonstandard value.
import { randomUUID } from 'node:crypto';
console.log('v4:', randomUUID());
With the popular uuid package, the equivalent deterministic and time-based calls are:
import { v1, v3, v4, v5 } from 'uuid';
console.log('v1:', v1());
console.log('v4:', v4());
console.log('v3:', v3('https://example.com/users/42', v3.URL));
console.log('v5:', v5('https://example.com/users/42', v5.URL));
Pin and review the package version in production. The namespace and canonicalization policy are part of your data contract, not merely library settings.
Command line
On systems with a UUID utility, a v4 command commonly looks like this:
Free tools Windows power users keep installed
One-click scans. No signup required.
uuidgen
Command-line tools differ in whether they support v1, v3, or v5 and in the option names they use. Check the installed tool’s manual and verify the result’s version nibble (the first hexadecimal digit of the third group).
Implement deterministic v3 and v5 correctly
- Select a namespace. Use a standard namespace such as DNS, URL, OID, or X.500 when it matches your data, or create and permanently document an application-specific namespace UUID.
- Define the name grammar. Decide whether names are URLs, email addresses, database keys, or another format. Specify case folding, Unicode normalization, whitespace handling, separators, escaping, and whether a URL’s scheme, host, port, path, query, and trailing slash are significant.
- Convert to canonical octets. Every implementation must hash the same byte sequence. Visually identical strings are not necessarily byte-identical.
- Hash namespace plus name. v3 uses MD5 as required by its definition; v5 uses SHA-1. The UUID version and variant bits are then applied to the hash output.
- Freeze the contract. Changing normalization rules later creates a second set of UUIDs for existing names. Version the naming scheme or migrate explicitly.
For example, decide whether HTTPS://Example.com/a and https://example.com/a/ are the same resource before generating any IDs. UUID algorithms cannot infer your application’s identity rules.
Validate a generated UUID
- It has the conventional 36-character textual form: eight-four-four-four-twelve hexadecimal characters separated by hyphens.
- The first hexadecimal digit of the third group identifies the version:
1,3,4, or5. - The first hexadecimal digit of the fourth group has the RFC variant pattern (binary
10in its two most significant bits), normally displayed as8,9,a, orb. - For v3 and v5, regenerate from the recorded namespace and canonical name and compare byte-for-byte.
- For v4, confirm that the runtime uses a secure operating-system random source; do not replace it with timestamps, counters, or predictable pseudo-random code.
Parsing and formatting validation proves that a value looks like a UUID. It does not prove that a v4 collision is impossible or that a UUID is secret.
Privacy and security boundaries
UUIDs are identifiers, not secrets
RFC 9562 states: “Implementations SHOULD NOT assume that UUIDs are hard to guess.” Do not put a UUID in a password-reset capability, session cookie, download authorization URL, or API credential unless it is protected by a separate, properly designed security mechanism. UUID bits also do not provide an integrity check that a person can reliably inspect.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
Reduce v1 metadata exposure
A v1 timestamp allows ordering and approximate creation-time analysis. A MAC-derived node can disclose information about a network interface or its manufacturer. If v1 is required, use the standard’s privacy guidance, consider a randomly derived node, and keep the value out of public interfaces when that metadata is sensitive.
Plan for collisions appropriately
Collision probability depends on the version, random-source quality, namespace/name correctness, and volume. Treat uniqueness as an engineering property: enforce a unique database constraint, handle a rejected insert, and monitor generation failures. Never interpret “unique” as “unguessable.”
Database and distributed-system considerations
Primary keys and locality
v4 spreads inserts across an index. That can increase page splits or cache misses for some workloads, while sequential integer keys can create hot spots in others. UUIDv6 or v7 may offer a better time-ordered shape, but the right choice depends on your database, index design, insertion pattern, and hardware. Benchmark representative traffic rather than assuming a universal gain.
Replication and retries
Generate an ID before sending a request when an idempotency key must survive retries. For a name-derived resource, v5 can make retries converge on one ID; for a new event, v4 gives each event its own value. Keep the namespace and canonical name available for audit and replay.
Storage format
Store UUIDs in the database’s native 128-bit type when available. Otherwise store 16 raw bytes rather than a 36-character string if your indexing and tooling support that representation. Convert to the standard textual form at API boundaries and document byte order for any binary interchange.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting
“The same name produced different v5 values”
Compare the namespace UUID, Unicode normalization, case conversion, whitespace, URL normalization, encoding, and trailing separators. Log the canonical byte representation (without exposing sensitive names) and add cross-language test vectors.
Rank #4
- Used Book in Good Condition
“My v1 values reveal a host”
Inspect the node field and stop publishing v1 values where that metadata is sensitive. Use v4, v5, or a privacy-conscious v1 configuration according to the requirement; changing only the display format does not remove embedded information.
“The value parses but has the wrong version”
Check the generator’s API and inspect the third group. A random-looking value is not necessarily v4, and hashing a name with a custom algorithm does not make a v5 UUID.
“The database became slower after switching to UUIDs”
Measure index size, page splits, cache hit rate, insert latency, and query plans. Compare v4 with an ordered design such as v6 or v7 and with your previous key type under the same workload. RFC 9562 identifies locality as a concern but does not prescribe a benchmark result.
“I used a UUID as an access token”
Replace it with a dedicated, revocable authorization mechanism and treat the UUID only as a record identifier. Rotate any credential that may already have been exposed.
Or skip the browser setup
If your workflow needs screenshots of UUID-generator pages, documentation, or test results, ScreenshotNeo provides a single HTTP request instead of maintaining browser automation. It accepts consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf to Claude, Cursor, and other MCP clients.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
See the ScreenshotNeo API documentation for options such as full-page capture, CSS selectors, device presets, custom CSS or JavaScript, waits, headers, cookies, blocking rules, PDF settings, caching, signed links, asynchronous jobs, bulk capture, and usage reporting. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Frequently Asked Questions
Can two different UUID versions have the same textual value?
The version and variant bits distinguish conforming values, so a value’s version is encoded in its text. A generator or parser should still validate both fields rather than relying on appearance alone.
Should I use v3 or v5 for new applications?
Use v5 when you control both sides and need the standard SHA-1 name-based form; use v3 when compatibility with an existing MD5-based UUID system is required. In either case, freeze canonicalization rules.
Can UUIDv7 replace UUIDv4?
Only when time ordering is useful to your application. v4 remains the suitable choice for an independent random identifier; v7 carries time information and has different privacy and ordering characteristics.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

