UUIDv4 vs. UUIDv7: Why RFC 9562 is Replacing RFC 4122
For two decades, UUID Version 4 has been the default choice for distributed software architectures. Defined in RFC 4122, UUIDv4 generates 122 bits of pure pseudorandomness. However, as cloud databases expanded into petabyte scales, UUIDv4 introduced a catastrophic database indexing issue known as B-Tree index page thrashing.
Because UUIDv4 keys are distributed randomly across the hexadecimal space, inserting new rows into an indexed database table (PostgreSQL, MySQL InnoDB, SQLite, or MongoDB) forces the database engine to write to random memory and disk blocks. This scatters memory caches, causes frequent disk I/O flushes, and fragments database indexes by up to 80%.
In May 2024, the Internet Engineering Task Force (IETF) formally ratified RFC 9562, introducing UUID Version 7 to solve this exact problem:
- Entropy: 122 bits of pseudo-random data.
- Ordering: Completely random and unindexed.
- Database Impact: High index fragmentation, random disk writes.
- Best Used For: Session tokens, CSRF tokens, obfuscated public IDs.
- Structure: 48-bit Unix timestamp (ms) + 74 bits of random entropy.
- Ordering: Lexicographically sortable by creation time.
- Database Impact: Append-only sequential inserts; zero B-tree fragmentation.
- Best Used For: Primary keys, distributed event streams, audit logs.
Complete UUID Version Taxonomy (v1 Through v8)
| UUID Version | Core Mechanism | Deterministic / Random | Primary Use Case | RFC Specification |
|---|---|---|---|---|
| Version 1 | 60-bit timestamp + 48-bit MAC address | Time-based (Hardware bound) | Legacy network systems (Privacy leak via MAC) | RFC 4122 |
| Version 2 | POSIX UID/GID + timestamp | DCE Security | Distributed Computing Environment (Rare) | RFC 4122 |
| Version 3 | MD5 hash of namespace + name string | Deterministic | Repeatable namespaced IDs (MD5 deprecated) | RFC 4122 |
| Version 4 | 122 bits of CSPRNG randomness | Completely Random | General-purpose tokens, ephemeral IDs | RFC 4122 / RFC 9562 |
| Version 5 | SHA-1 hash of namespace + name string | Deterministic | Cryptographic namespaced unique identifiers | RFC 4122 / RFC 9562 |
| Version 6 | Reordered v1 timestamp for sorting | Time-based (Reordered) | v1 backwards-compatibility migration | RFC 9562 |
| Version 7 | 48-bit Unix epoch ms + 74-bit random | Monotonic Time-Ordered | Modern Database Primary Keys (Recommended) | RFC 9562 |
| Version 8 | Custom application-specific format | Vendor Defined | Enterprise proprietary time schemas | RFC 9562 |
Collision Mathematics: The Birthday Paradox at 122 Bits
A common developer question is whether two servers generating UUIDv4 IDs concurrently could ever generate the identical identifier. Because a UUIDv4 contains 122 bits of random entropy, the total number of possible unique identifiers is:
2{122} ≈ 5.3169 × 10{36} unique identifiers Applying the standard Birthday Problem collision approximation formula:
p ≈ 1 - e{-(n{2}) / (2 × 2{122})} To incur a one in a billion chance (\(10^-9\)) of a collision, your infrastructure would have to generate over 103 trillion UUIDs. Generating 1 billion UUIDs per second for 85 consecutive years yields less than a 50% probability of a single duplicate.
Frequently Asked Questions About UUIDs & GUIDs
What is the difference between UUID Version 4 and UUID Version 7?
UUIDv4 (RFC 4122) is composed of 122 bits of pseudo-random entropy and 6 metadata bits. While completely collision-resistant, inserting random UUIDv4 keys into relational databases (PostgreSQL, MySQL, SQLite) causes severe B-Tree index page splitting and high disk I/O. In contrast, UUIDv7 (RFC 9562) prefixes a 48-bit Unix timestamp in milliseconds before 74 random bits. This makes UUIDv7 naturally sortable by creation time, maintaining sequential database index locality and boosting insert throughput by 3x to 10x.
Is there any risk of a UUID collision?
The probability of generating two identical UUIDv4 keys is astronomically negligible. With 122 bits of pure entropy, there are 2^122 (approx 5.3 × 10^36) unique values. To achieve a 50% probability of a single collision, a system would have to generate 1 billion UUIDs every second continuously for approximately 85 years.
Are UUIDs and Microsoft GUIDs the exact same thing?
Yes. A GUID (Globally Unique Identifier) is Microsoft's implementation of the Universally Unique Identifier standard. Both are 128-bit identifiers conforming to RFC 4122 / RFC 9562. While Windows programming historically favored uppercase with curly braces (e.g. {21EC2020-3AEA-1069-A2DD-08002B30309D}), their underlying bit structures and algorithms are identical.
Are generated UUIDs cryptographically secure?
Yes. Our generator strictly uses the browser's native window.crypto.getRandomValues CSPRNG (Cryptographically Secure Pseudo-Random Number Generator) or crypto.randomUUID. This pulls hardware-backed entropy from the operating system kernel (/dev/urandom on Linux/macOS, BCryptGenRandom on Windows), preventing predictability.
Can I extract the creation timestamp from a UUID?
Yes, if the identifier is a UUIDv1 (timestamp + MAC address) or UUIDv7 (Unix epoch milliseconds). In UUIDv7, the first 48 bits (12 hexadecimal characters) encode the exact millisecond of generation. Our built-in UUID Inspector automatically extracts and decodes this timestamp into human-readable UTC and local time.
Explore Related Developer & Cryptography Tools
Convert epoch timestamps (seconds, ms, μs, ns) to human-readable dates and timezones.
Format variable naming conventions across camelCase, snake_case, and PascalCase.
Audit hardware systems for TPM 2.0, Secure Boot, and CPU instruction compatibility.
Calculate presentation speech pacing, reading speed, and Flesch-Kincaid readability.
Generate printable guest network connection cards with WPA3 and client-side privacy.
Verify WCAG AA and AAA accessibility contrast ratios for web and software interfaces.