Skip to content

How UUIDs work

Published

A UUID (Universally Unique Identifier) is a 128-bit identifier used to uniquely identify resources across distributed systems.

UUID Structure

UUIDs are represented as 32 hexadecimal digits in five hyphen-separated groups following the 8-4-4-4-12 format, totaling 36 characters.

Version: v4
Variant: RFC 9562
Info: Uses cryptographically secure random numbers.

UUID Structure

35dfc931
-
3127
-
430e
-
a9bb
-
a600d74eadd9
Time Low

32 bits: Low field of the timestamp

3    5    d    f    c    9    3    1
0011 0101 1101 1111 1100 1001 0011 0001
Time Mid

16 bits: Middle field of the timestamp

3    1    2    7
0011 0001 0010 0111
Time High & Version

16 bits: 4 bits version + 12 bits high field of timestamp

4    3    0    e
0100 0011 0000 1110
Clock Sequence

16 bits: 2 bits variant + 14 bits clock sequence to help avoid duplicates

a    9    b    b
1010 1001 1011 1011
Node

48 bits: Node identifier

a    6    0    0    d    7    4    e    a    d    d    9
1010 0110 0000 0000 1101 0111 0100 1110 1010 1101 1101 1001

Example UUID

550e8400-e29b-41d4-a716-446655440000
              ↑    ↑
              │    └─ Variant bits (first 2 bits of clock sequence)
              └────── Version (first 4 bits of time high)

Breaking it down:

Understanding Variant Bits

The variant uses the first 2 bits (MSB0, MSB1) of the clock sequence field:

Bits Hex Variant Description
0xxx 0-7 NCS Reserved Network Computing System (NCS) backward compatibility, includes Nil UUID
10xx 8-9, A-B RFC 9562 The variant specified in this document (most common)
110x C-D Microsoft Reserved Microsoft Corporation backward compatibility
111x E-F Future Reserved Reserved for future definition, includes Max UUID

UUID Versions

At a Glance

VersionTime-OrderedDeterministicPrivacy-SafeDB PerformanceRecommendation
4✗✗✓✗Default choice
5✗✓ SHA-1✓✗Name mapping
6✓ Gregorian (1582)✗✗ MAC address✓v1 migration
7✓ Unix (1970)✗⚠ Timing exposure✓✓Recommended if timing exposure is acceptable
8Implementation dependentCustom use
Legacy versions
1✓ Gregorian (1582)✗✗ MAC address⚠Legacy (use v6)
2✗✗✗✗Legacy DCE
3✗✓ MD5✓✗Legacy (use v5)

Legend: ✓ = Yes | ✗ = No | ⚠ = Depends/Varies

Time-Based Versions

v1 - Original time-based UUID

v6 - Improved time-based UUID

v7 - Modern time-based UUID

Random Version

v4 - Random UUID

Name-Based Versions

v3 - MD5 name-based

v5 - SHA-1 name-based

v8 - Custom name-based

Legacy Versions

v2 - DCE Security

Technical Specifications

Version Timestamp Algorithm Random Bits
1 60b (100ns, 1582) Timestamp + MAC 0
2 — DCE Security —
3 — MD5(namespace + name) 0
4 — CSPRNG 122
5 — SHA-1(namespace + name) 0
6 60b (100ns, 1582) Timestamp + MAC (reordered) 0
7 48b Unix (ms, 1970) Timestamp + random 74
8 Custom Implementation-defined 0–122

References