UUID v3 and v5 are “name-based” UUIDs — given the same namespace UUID and the same name string, they always produce the same output UUID. This makes them useful for content addressing, deduplication, and any scenario where the same logical entity should map to the same identifier across systems.
How Name-Based UUIDs Work
The algorithm:
- Concatenate the namespace UUID’s 16 bytes with the name string’s UTF-8 bytes
- Hash the result: MD5 for v3, SHA-1 for v5
- Take the first 16 bytes of the hash
- Set the version nibble (position 76–79) to
0011(v3) or0101(v5) - Set the variant bits (position 64–65) to
10
Because the hash function is deterministic, the same inputs always produce the same UUID. This is fundamentally different from v4 and v7, which use random bits.
Predefined Namespaces
RFC 9562 §6.6 defines four predefined namespaces:
| Namespace UUID | Purpose |
|---|---|
6ba7b810-9dad-11d1-80b4-00c04fd430c8 | DNS — for fully qualified domain names |
6ba7b811-9dad-11d1-80b4-00c04fd430c8 | URL — for absolute URLs |
6ba7b812-9dad-11d1-80b4-00c04fd430c8 | OID — for ISO Object Identifiers |
6ba7b814-9dad-11d1-80b4-00c04fd430c8 | X.500 DN — for X.500 distinguished names |
You can also define your own namespace by generating a UUID v4 once and using it as the namespace for your application or domain.
Generating UUID v5 in Practice
JavaScript — uuid npm package:
import { v5 as uuidv5 } from 'uuid';
const DNS = '6ba7b810-9dad-11d1-80b4-00c04fd430c8';
const id = uuidv5('example.com', DNS);
// Always: "cfbff0d1-9375-5685-968c-48ce8b15ae17"
Python — standard library:
import uuid
DNS = uuid.NAMESPACE_DNS
id = uuid.uuid5(DNS, 'example.com')
# Always: UUID('cfbff0d1-9375-5685-968c-48ce8b15ae17')
Go — google/uuid:
import "github.com/google/uuid"
dns := uuid.NameSpaceDNS
id := uuid.NewSHA1(dns, []byte("example.com"))
// Always: cfbff0d1-9375-5685-968c-48ce8b15ae17
When to Use Namespace UUIDs
Content addressing: Hash a file’s content or URL to produce a stable UUID. The same content always maps to the same UUID, enabling deduplication in object stores or event logs.
Idempotent record creation: When importing records from an external system, use the source system’s string ID as the name and a fixed namespace to produce a deterministic UUID. Re-importing the same record produces the same UUID — no duplicate checks needed.
Synthetic test data: Generate consistent UUIDs in tests by seeding from a known name. Tests are reproducible without storing expected UUIDs in fixtures.
Federated identity: Two systems that agree on a namespace and naming convention can independently generate the same UUID for the same logical entity without coordination.
What Namespace UUIDs Are Not For
- Security tokens — name-based UUIDs are deterministic and therefore predictable if the name is known. Do not use them as secrets.
- Primary keys for user-generated content — if two users submit the same content, they would receive the same UUID. Use v4 or v7 for records that must be distinct regardless of content.
- High-throughput inserts — SHA-1 hashing adds CPU overhead compared to v4/v7 generation. For bulk inserts, v7 is faster.
Custom Namespaces
To define your own namespace, generate a UUID v4 once and document it as your application’s namespace constant:
// Your application's permanent namespace
const MY_APP_NS = '7c9e6679-7425-40de-944b-e07fc1f90ae7'; // generated once, fixed forever
const userId = uuidv5(`user:${email}`, MY_APP_NS);
Store this namespace constant in your codebase — it must never change. Different values produce different UUIDs for the same name.
Related Resources
- RFC 9562 §6.6 — predefined namespace UUIDs
- uuid npm package — v5 implementation
- Python uuid.uuid5() documentation
- google/uuid NewSHA1 documentation
Frequently asked questions
What is a UUID namespace used for?
A namespace UUID scopes the hash when generating deterministic name-based UUIDs (v3 or v5). The same name produces a different UUID in each namespace, preventing collisions across independent systems. RFC 9562 §6.6 defines four predefined namespaces for DNS names, URLs, OIDs, and X.500 DNs.
What is a UUID namespace used for?
A namespace is itself a UUID used as a scope when generating name-based UUIDs (v3 or v5). Hashing the same name in two different namespaces produces two different UUIDs, allowing the same string to produce distinct IDs in different contexts. RFC 9562 Appendix C defines standard namespaces for URLs, DNS names, OIDs and X.500 names.
Should I use v4 or v7?
Use v7 for database primary keys (time-sortable, index-friendly) and v4 for anything where creation order could leak information, like tokens or share links.
What is a UUID namespace?
A UUID namespace is a UUID used as a domain separator when generating name-based UUIDs (v3 or v5). The namespace scopes the hash — the same name in two different namespaces produces two different UUIDs, preventing collisions across independent systems. RFC 9562 defines four predefined namespaces for DNS names, URLs, OIDs, and X.500 DNs. See the RFC 9562 namespace section for the full list.
Should I use UUID v3 or UUID v5?
Use UUID v5 (SHA-1) for all new work. UUID v3 uses MD5, which has known collision vulnerabilities and is not recommended for new designs by NIST. The output format and deterministic behaviour are identical — v5 is strictly safer.