Flaky test, third failure this week. Root cause: seed data with auto-increment IDs — test B assumed the user from test A still had ID 7. Switched the fixtures to bulk UUIDs; flakes vanished that afternoon. Random IDs decouple tests from insertion order, and v4 UUIDs make collisions a non-event at any sane volume. This guide covers how many you need, bulk workflows, and when random strings serve better.
Part of the developer toolkit guide. Mint in bulk in the UUID generator; human-readable codes in random strings.
The math: 122 bits means stop worrying
v4 UUIDs carry 122 random bits. Birthday-paradox math needs ~2.7 quintillion IDs for 50% collision odds — generating a million per second, you would wait centuries. Practical translation: 10,000 fixture IDs cannot collide (odds ~10⁻²⁸, far below hardware-error rates). Dedupe on insert anyway as belt-and-braces, then forget about it. Variant bits and RFC 4122 formatting (8-4-4-4-12 hex groups) are cosmetic; randomness is the substance.
Bulk workflow: 10,000 IDs into seed scripts
- Mint in bulk with count input in the UUID generator — one click, copy-all, no rate limits, offline.
- Store as strings (CHAR(36) or native UUID columns), indexed. Never truncate for “readability” — truncated UUIDs lose the randomness guarantee.
- Reference across fixtures by literal ID: order #3f… belongs to user #7a… regardless of insertion order. Tests become order-independent.
- Rotate secrets separately: fixture UUIDs are identifiers, not credentials. API keys need entropy plus revocation — different system.
UUID vs random string vs GUID (naming the same thing)
| Need | Use | Why |
|---|---|---|
| DB rows, distributed IDs | UUID v4 | Collision-proof, standard format |
| Human codes (coupons, invites) | Random string, Crockford base32 | Readable, no confusing 0/O, 1/l |
| .NET / Windows APIs | GUID | Same 128-bit value, different name |
| Short URLs | Neither — use counter+hashids | UUIDs waste 36 chars per link |
API keys deserve their own design (prefix for identification like sk_live_, 32+ random bytes, hashed storage, rotation) — a bare UUID works for prototypes, not production secrets. Compare generators in the UUID tool and random string tool side by side.
General guidance only. UUIDs identify; they do not authorize — keep authentication and revocation in dedicated systems.