The standard UUID string 550e8400-e29b-41d4-a716-446655440000 is 36 characters — bulky in URLs, log lines, and user-visible IDs. The underlying 128-bit value can be encoded much more compactly without losing any information.

Encoding Options Compared

FormatLengthURL-safeRound-trips to UUIDExample
Hyphenated hex (standard)36 chars✗ (hyphens ok, but verbose)—550e8400-e29b-…
Hex (no hyphens)32 chars✓✓550e8400e29b…
Base64url (no padding)22 chars✓✓VQ6EAOKbQdSnFkZlVEAA
Base5822 chars✓✓7XAkgLsn4KzCzQ5sV9
ULID text26 chars✓✗ (different format)01ARZ3NDEKTSV4RRFFQ69G5FAV

Base64url (RFC 4648 §5) is the most standard choice: uses A-Z, a-z, 0-9, -, _ — no characters that need percent-encoding in URLs. A UUID’s 16 bytes encode to exactly 22 characters without padding.

Base58 (used by Bitcoin and IPFS) omits ambiguous characters 0, O, I, l — easier to transcribe but no formal standard.

Base64url Encoding in JavaScript

import { parse, stringify } from 'uuid';

function uuidToBase64url(id) {
  const bytes = parse(id); // Uint8Array of 16 bytes
  const bin = String.fromCharCode(...bytes);
  return btoa(bin).replace(/\+/g, '-').replace(/\//g, '_').replace(/=/g, '');
}

function base64urlToUuid(b64) {
  const bin = atob(b64.replace(/-/g, '+').replace(/_/g, '/'));
  const bytes = Uint8Array.from(bin, c => c.charCodeAt(0));
  return stringify(bytes);
}

const id = 'c232ab00-9414-11ec-b3c8-9e6bdeced846';
const short = uuidToBase64url(id);     // "wjKrAJQUEey7yJ5r3s7YRg"
const back  = base64urlToUuid(short);  // "c232ab00-9414-11ec-b3c8-9e6bdeced846"

Base64url in Python

import uuid, base64

def uuid_to_b64url(u: uuid.UUID) -> str:
    return base64.urlsafe_b64encode(u.bytes).rstrip(b'=').decode()

def b64url_to_uuid(s: str) -> uuid.UUID:
    padding = '=' * (-len(s) % 4)
    return uuid.UUID(bytes=base64.urlsafe_b64decode(s + padding))

u = uuid.uuid7()
short = uuid_to_b64url(u)   # 22-char string
back  = b64url_to_uuid(short)  # original UUID

Using Shortened UUIDs in Express / Fastify Routes

// Route with 22-char Base64url ID
app.get('/posts/:id', (req, res) => {
  const uuid = base64urlToUuid(req.params.id);
  const post = db.posts.findById(uuid);
  res.json(post);
});

The database stores the full UUID; the URL shows the compact form. Links look like /posts/wjKrAJQUEey7yJ5r3s7YRg instead of /posts/c232ab00-9414-11ec-b3c8-9e6bdeced846.

NanoID — When You Don’t Need UUID Round-Trips

If you only need a short, URL-safe random ID and don’t need to convert back to a UUID, NanoID generates 21-char strings using a custom alphabet. NanoID values are not UUIDs — they can’t be stored in a uuid column — but they are shorter and simpler when cross-database portability is not required.

Frequently asked questions

What is the shortest way to encode a UUID in a URL?

Base64url encoding reduces a UUID from 36 characters (hyphenated string) to 22 characters with no padding. Strip the trailing == padding — the length is always 22. Alternatively, Base58 also produces 22 characters with no padding and no special URL characters. Both are fully reversible to the original 16-byte UUID. The uuid npm package includes uuidStringify and uuidParse for byte-level access.

What formats can a UUID be represented in?

A UUID can be represented as: the standard hyphenated string (8-4-4-4-12 hex), a 32-character hex string with no hyphens, a Base64 or URL-safe Base64 string (22 characters), a URN (urn:uuid:…), or raw 16-byte binary. The hyphenated string is the canonical form defined by RFC 9562.

Should I use v4 or v7?

Use v7 for database primary keys (time-sortable, index-friendly) and v4 for anything where creation order could leak information, like tokens or share links.

How do I shorten a UUID for use in a URL?

Encode the UUID's 16 raw bytes as URL-safe Base64 (no padding): a 36-char UUID becomes a 22-char string. In JavaScript: btoa(String.fromCharCode(...uuid.parse(id))).replace(/\+/g,'-').replace(/\//g,'_').replace(/=/g,''). The uuid npm package includes uuid.stringify() and uuid.parse() for the byte-level operations. Any encoding that round-trips through the 16 raw bytes preserves all UUID information.

Is it safe to expose UUID v7 in URLs?

With caution. UUID v7 embeds a millisecond creation timestamp — anyone who sees the URL knows approximately when the resource was created. For public-facing URLs (blog posts, public profiles), this is usually acceptable. For sensitive resources (password reset links, private document shares), use UUID v4, which reveals nothing about creation time. See RFC 9562 §9 (Security Considerations) for the full guidance.