UUID v7 Generator

Time-ordered UUIDs from RFC 9562 — sortable by creation time, ideal as database primary keys.

What is UUID v7?

UUID v7 starts with a 48-bit Unix-epoch millisecond timestamp followed by random bits. IDs generated later always sort after IDs generated earlier, while remaining unpredictable enough for most use cases.

Why use v7 for database keys?

Purely random v4 keys scatter inserts across a B-tree index, causing page splits and cache misses at scale. v7 keys are naturally append-mostly like auto-increment integers, keeping indexes compact — while still being globally unique and generatable by any client without coordination.

v7 vs ULID?

ULID solves the same problem with a different text encoding (Crockford base32). UUID v7 has the advantage of being a standard UUID: it fits every existing uuid column type, driver, and library. If your stack speaks UUID, v7 is the natural choice.

Frequently asked questions

Does my database support UUID v7?

Every database that has a UUID or 16-byte binary column already stores v7 — the version digit is just part of the value, so no schema change is needed. What differs is whether the database can generate one for you. PostgreSQL 18 ships a built-in uuidv7() function; earlier versions need the pg_uuidv7 extension or an application-side generator. MySQL and SQL Server have no native v7 function, so you generate the value in your application and insert it like any other UUID. That application-side path is the most portable option overall, and it is what most teams adopt: libraries exist for Python (uuid7 in 3.14, the uuid6 package before that), JavaScript, Java, Go, Rust and more.

Does UUID v7 leak information?

Yes, by design: the first 48 bits are a Unix millisecond timestamp, so anyone holding the identifier can read when the record was created, down to the millisecond. For most data — orders, events, log entries, internal rows — that is harmless and often useful for debugging. It becomes a problem when the creation time itself is sensitive or commercially revealing: sequential-looking signup IDs let a competitor estimate your growth rate, and a password-reset token that discloses its issue time narrows an attacker's search window. In those cases use v4, whose 122 random bits reveal nothing about when or where the value was made. Both versions live in the same column type, so mixing them per use case costs nothing.

Need a different version? Try the full UUID generator supporting v1, v3, v4, v5 and v7. All versions follow RFC 9562.