Version 4 or version 7
Version 4 is 122 random bits. It is the one most people mean by UUID, and it is the right answer when the identifier should give nothing away. Two of them made a second apart look no more alike than two made years apart.
Version 7 puts the time first. It starts with 48 bits of the clock, then adds 74 random bits. Sort a column of them and they come out in the order they were made. A database index wants exactly that, because rows written together are then stored together.
The trade is that a v7 tells anyone who reads it when it was made, to the millisecond. For a row id that is usually fine and often useful. For a password reset link it is a leak, so use v4 there.
- Versions
- v4 random, v7 time-ordered, and the nil identifier when you need a placeholder.
- Randomness
- crypto.randomUUID for v4, and crypto.getRandomValues for the random part of v7. Never Math.random.
- Output
- One per line, CSV, a JSON array, or a ready-made SQL insert. You also choose the case and the wrapping.
- Anatomy
- The panel reads the first one back: version, variant, random bits, and a v7's own clock.
Will two ever be the same
Not in any system you will build. You would need about 103 trillion version 4 UUIDs before the chance of even one clash reached one in a billion. Made at a billion a second, that many takes more than a day.
That holds only while the randomness is real. This page uses your browser's cryptographic random source, the kind used to make encryption keys. A UUID made with Math.random has the same shape but far weaker randomness, and it can collide.