Implementing

Conformance checklist

Level: the spec's keyword; spec = stated without a keyword; advice = these pages, not the spec.

Generating

RuleLevel
Variant 0: 43-bit ms timestamp, then 57 random bitsspec
Timestamp past 2⁴³ − 1: keep the low 43 bits, don't errorSHOULD
Variant 1: all 100 payload bits randomspec
CSPRNG for both variantsadvice
Fixed bits: UUID version 0x8, UUID variant 0b10, TNID variant 0b00 or 0b01MUST
Name: 1–4 characters, null-padded at the low endMUST

TNID strings

RuleLevel
Format: name, ., 17 data charactersMUST
Reject: anything else, including whitespace and non-ASCIIMUST
Case-sensitive: never change casespec
Not base64: don't use a base64 libraryspec

UUID form and 128-bit values

RuleLevel
UUID form: read either case, write lowercaseRFC 9562
Byte order: big-endianspec
Version and variant: exactly 0x8 and 0b10, not just the high bitMUST
Name bits: reject all-null, or non-null after nullMUST
Reserved variants: accept TNID variants 2 and 3; opaque payloadSHOULD

Extensions

Optional. An implementation that provides one MUST follow it exactly.

RuleLevel
V0/V1 encryption: FF1, AES-128, radix 16, 25 digits, empty tweak, 10 roundsMUST
Byte-identical output for the same input and keyMUST
Already in the target variant: return the input unchangedSHOULD
Blocklist matching: case-insensitive substrings of the 17 data characters; patterns unmodifiedMUST
Escaping a match: new random bits; advance the timestamp if the match is within characters 1–7SHOULD
Giving up: error, never block indefinitelyMUST
With encryption: check both the variant 0 and variant 1 data stringsSHOULD

Testing

Pass every test vector, must-reject cases included; also in test-vectors.json.