By the Withuse team · Updated
What is UUID v3?
UUID v3 hashes a namespace UUID together with a name (any string) using MD5, then formats the digest as a UUID. Given the same namespace and name, every system in the world derives the identical UUID — no coordination needed.
v3 or v5?
Both are name-based; v5 uses SHA-1 instead of MD5. RFC 9562 recommends v5 unless you need v3 for compatibility with an existing system. Neither is meant for security — the hash only provides deterministic uniqueness, not secrecy.
Standard namespaces
Four well-known namespace UUIDs are predefined: DNS (for domain names), URL, OID, and X.500. You can also supply any UUID of your own as a custom namespace to create your own deterministic ID space.
Frequently asked questions
Is UUID v3 secure?
No, and it was never meant to be. UUID v3 hashes the namespace and name with MD5, a function broken for collision resistance since 2004 — but the security property that matters here is different: the input is not secret. Anyone who knows the namespace and the name can compute the identical UUID in one line of code, which is the entire point of a name-based UUID. Treat v3 values as derived public identifiers, never as tokens, capability keys, or anything that grants access. If you need an unguessable value, use v4, whose 122 random bits come from a cryptographically secure source. If you only need determinism, prefer v5 — same idea, SHA-1 instead of MD5.
Which namespace should I use?
Use one of the four predefined namespaces when your name genuinely belongs to that space: DNS for hostnames, URL for full URLs, OID for ISO object identifiers, X.500 for directory names. They exist so that two independent systems hashing the same domain arrive at the same UUID. For anything else — internal entity keys, file paths, tenant identifiers — generate one random v4 UUID, treat it as your application's private namespace constant, and commit it to your codebase. That gives you a deterministic ID space nobody else will collide with, and it makes the derivation reproducible for anyone reading your code later.
Need a different version? Try the full UUID generator supporting v1, v3, v4, v5 and v7. All versions follow RFC 9562.