- Home
- Built-in Tools
- Platform ID Decoder
Last updated: · By Ned Walsch
Platform ID Decoder: Get Creation Time From Any ID
Most platform IDs are timestamps in disguise. A Discord, Twitter/X, Instagram, Mastodon or TikTok ID, a Bluesky post code, a ULID, KSUID, UUID v1/v6/v7 or MongoDB ObjectId stores the moment it was created in its leading bits, so the ID alone tells you when an account, post, message or record was made, even after the content is deleted. Paste IDs or links below, one per line; decoding runs entirely in your browser. Reddit and YouTube IDs hold no timestamp, and the tool says so instead of guessing.
On this page
How can an ID reveal when something was created?
Large platforms need IDs that many servers can mint at once without colliding, and that sort by time. Twitter’s 2010 answer, “Snowflake”, packs a timestamp, a worker number and a sequence number into 64 bits so that IDs are “roughly sortable” Twitter Engineering: Announcing Snowflake (1 Jun 2010). Discord, Instagram, Mastodon and others copied the idea with their own epochs and bit splits, and newer standards such as ULID, KSUID, UUIDv7 and the AT Protocol’s TIDs put the time first for the same reason. Read the time bits, add the epoch, and you have the creation time — no API, account or network request needed.
- Paste an ID or a link. Links are best, because the domain tells the decoder which platform it is.
- Check the detected type and confidence badge. A bare number can belong to several platforms; pick one from the menu or use an alternative reading if the first is wrong.
- Record the UTC time. UTC is the evidence; the local column only converts it to your device’s time zone. Export CSV or JSON for your notes, or use the Timestamp Converter to turn the UTC value into other formats.
ID formats at a glance
| Format | Looks like | Epoch | Time bits | Other fields | Source |
|---|---|---|---|---|---|
| Discord | 64-bit decimal | 1 Jan 2015 (1420070400000 ms) | bits 63–22: ms | worker (5), process (5), increment (12) | Discord Developer Docs: Snowflakes (fetched 8 Oct 2026) |
| Twitter / X | 64-bit decimal | 4 Nov 2010 01:42:54.657 UTC (1288834974657 ms) | ID ≫ 22: ms | datacenter (5), worker (5), sequence (12) | twitter-archive/snowflake IdWorker.scala (2010–2012) |
| Instagram media/user | 64-bit decimal (media ID may carry “_userID”) | 1314220021721 ms (24 Aug 2011) | top 41 bits: ms (ID ≫ 23) | shard (13), sequence (10) | Mike Krieger, “Sharding @ Instagram”, SFPUG slides (Apr 2012) |
| Instagram shortcode | 11 base64-url characters | as Instagram media ID | decode to media ID first | — | community-documented |
| Mastodon | 64-bit decimal | Unix (1970) | top 48 bits: ms (ID ≫ 16) | sequence data (16) | mastodon/mastodon lib/mastodon/snowflake.rb (fetched 8 Oct 2026) |
| TikTok | 64-bit decimal | Unix (1970) | top 32 bits: seconds | low 32 bits undocumented | Ryan Benson, “Tinkering with TikTok Timestamps” (11 Aug 2020) (independent research) |
| Bluesky / AT Protocol TID | 13 base32-sortable characters | Unix (1970) | 53 bits: µs | clock ID (10) | AT Protocol spec: Timestamp Identifiers (fetched 8 Oct 2026) |
| ULID | 26 Crockford base32 characters | Unix (1970) | 48 bits: ms | randomness (80) | ULID specification (GitHub, fetched 8 Oct 2026) |
| KSUID | 27 base62 characters | 13 May 2014 (1400000000 s) | 32 bits: s | payload (128) | segmentio/ksuid README and ksuid.go (fetched 8 Oct 2026) |
| UUID v1 / v6 | 36-char hex | 15 Oct 1582 | 60 bits: 100 ns | clock sequence (14), node (48) | RFC 9562: Universally Unique IDentifiers (May 2024) |
| UUID v7 | 36-char hex | Unix (1970) | 48 bits: ms | rand_a (12), rand_b (62) | RFC 9562: Universally Unique IDentifiers (May 2024) |
| MongoDB ObjectId | 24 hex characters | Unix (1970) | 4 bytes: s | process-unique value (5 bytes), counter (3 bytes) | MongoDB Manual: ObjectId() (fetched 8 Oct 2026) |
| base36 (t3_… “fullname” prefix) | — | none — sequential | decimal row number | reddit-archive/reddit r2/lib/db/thing.py (archived source) | |
| YouTube video | 11 base64-url characters | — | none | — | YouTube Data API: Videos resource (fetched 8 Oct 2026) |
How is each platform’s ID laid out?
Discord
Discord’s documentation gives the layout bit by bit: bits 63–22 are milliseconds since the Discord epoch, “the first second of 2015 or 1420070400000”, then a 5-bit internal worker ID, a 5-bit internal process ID and a 12-bit increment. Its worked example, 175928847299117063, decodes to 2016-04-30 11:18:25.796 UTC Discord Developer Docs: Snowflakes (fetched 8 Oct 2026). Discord says it uses Twitter’s snowflake format for its IDs, so a discord.com/channels/server/channel/message link decodes into three creation times. For what that tells you about account age and sock-puppet clusters, see the Discord OSINT guide.
Twitter / X
The original generator sets twepoch = 1288834974657L with 5 datacenter bits, 5 worker bits and 12 sequence bits, so the timestamp starts at bit 22 twitter-archive/snowflake IdWorker.scala (2010–2012). X still describes its IDs as 64-bit “Snowflake” numbers that encode a timestamp, worker number and sequence number X API docs: X IDs (fetched 8 Oct 2026). X’s own API sample shows post 1212092627178287104 with created_at 2019-12-31T19:26:16.000Z X API docs: data dictionary sample (fetched 8 Oct 2026); the ID decodes to 19:26:16.568, the same second. IDs minted before Snowflake went live in late 2010 are smaller sequential numbers with no embedded time; they decode to implausible dates and are flagged.
Instagram’s co-founder Mike Krieger presented the scheme in 2012: 41 bits of time in milliseconds, 13 bits of shard ID and 10 bits of sequence, generated in PostgreSQL with our_epoch bigint := 1314220021721 and (now_millis - our_epoch) << 23 Mike Krieger, “Sharding @ Instagram”, SFPUG slides (Apr 2012). That is how media IDs (and newer, large user IDs) decode. Instagram has not published how post shortcodes map to IDs; the widely used method — treat the shortcode as base64 with the alphabet A–Z a–z 0–9 - _ — is community-documented, so treat shortcode dates as a strong lead and confirm against the post. Small user IDs are sequential and carry no time.
Mastodon
Mastodon’s source explains its IDs as “6 bytes (48 bits) of millisecond-level timestamp” followed by “2 bytes (16 bits) of sequence data”, with the epoch at 1970 mastodon/mastodon lib/mastodon/snowflake.rb (fetched 8 Oct 2026). Paste a status URL like https://instance/@user/ID. Other fediverse software uses different ID schemes, so a Mastodon-style URL on a non-Mastodon server may not decode correctly.
TikTok
TikTok has not documented its ID format. DFIR researcher Ryan Benson showed in 2020 that the 32 most significant bits of a video ID are a Unix timestamp in seconds, usually within 5 seconds of the post’s createTime and at most 18 seconds apart in his tests Ryan Benson, “Tinkering with TikTok Timestamps” (11 Aug 2020); Bellingcat’s open-source TikTok timestamp tool is based on that research Bellingcat tiktok-timestamp (GitHub). The decoder reads TikTok video and photo IDs from URLs and also decodes a comment_id parameter the same way, but whether comment IDs follow this layout is unverified, and none of it is officially documented. The TikTok OSINT guide covers where else dates hide.
Bluesky / AT Protocol TIDs
The AT Protocol spec defines a TID as a 64-bit integer, written as 13 characters of the base32-sortable alphabet 234567abcdefghijklmnopqrstuvwxyz, whose top bit is 0, next 53 bits are microseconds since the Unix epoch and final 10 bits are a random clock identifier AT Protocol spec: Timestamp Identifiers (fetched 8 Oct 2026). Post links (bsky.app/profile/…/post/TID) and at:// URIs end in a TID record key. The same spec warns that uniqueness cannot be guaranteed on an open network — a TID is chosen by the user’s software, so it can be back-dated.
ULID and KSUID
A ULID is 26 Crockford base32 characters: a 48-bit Unix time in milliseconds followed by 80 random bits ULID specification (GitHub, fetched 8 Oct 2026). A KSUID is 27 base62 characters encoding 20 bytes: a 32-bit timestamp in seconds whose epoch is “adjusted to May 13th, 2014” (epoch 1400000000 in the code) and a 128-bit random payload segmentio/ksuid README and ksuid.go (fetched 8 Oct 2026).
UUID v1, v6 and v7
RFC 9562 defines UUIDv1 and v6 around a 60-bit count of 100-nanosecond intervals since 1582-10-15 (v6 stores it in big-endian order so it sorts), plus a 14-bit clock sequence and a 48-bit node, and UUIDv7 around a 48-bit Unix timestamp in milliseconds followed by random bits RFC 9562: Universally Unique IDentifiers (May 2024). A v1 node is often the MAC address of the machine that generated it unless the multicast bit is set, which marks a random node. Versions 3, 4 and 5 contain no time.
MongoDB ObjectId
An ObjectId is 12 bytes: a 4-byte timestamp in seconds since the Unix epoch, a 5-byte random value unique to the machine and process, and a 3-byte counter starting from a random value MongoDB Manual: ObjectId() (fetched 8 Oct 2026). The specification notes that the 5-byte field originally held a machine ID and process ID before drivers standardised on a random value MongoDB specifications: BSON ObjectID (fetched 8 Oct 2026).
Reddit and YouTube: no timestamp
Reddit’s open-sourced code builds IDs by converting a sequential database number to base36 (to36(self._id)) and prefixing a type for “fullnames” such as t3_ reddit-archive/reddit r2/lib/db/thing.py (archived source). Higher numbers are newer, but there is no clock inside, so the tool shows the decimal row number only. YouTube’s Data API simply calls the video ID “the ID that YouTube uses to uniquely identify the video”; the publish time lives in snippet.publishedAt, which “might be different than the time that the video was uploaded” YouTube Data API: Videos resource (fetched 8 Oct 2026).
How sure is the auto-detection?
- High — the type came from a URL, or the format is unambiguous (UUID with a valid version, ObjectId, ULID) and the date is plausible.
- Medium — only one platform reading of a bare number gives a plausible date, or a 13/27-character string matches the TID or KSUID alphabet.
- Low — several platforms fit (most often Discord versus Twitter/X), or an 11-character string could be a YouTube ID or an Instagram shortcode. Alternatives are listed with their dates; click one to re-read that line.
- Forced — you chose the type. If the date falls outside that platform’s lifetime the row warns you.
“Plausible” means between the platform’s epoch (or launch) and tomorrow. That rule alone separates many cases: a TikTok-sized number decodes to a future date as a Discord or Twitter ID, so it is rejected for those.
What can’t an ID tell you?
- Who made it, or where. Worker, process and shard numbers identify internal servers, not people or places.
- The exact publish time in every case. An ID records when the server minted it. Scheduled posts, drafts, edits and re-uploads can differ, and TikTok IDs drift by seconds.
- Proof against fabrication. TIDs, ULIDs, KSUIDs and UUIDs are generated by client software and can be set to any time. Platform snowflakes from Discord or X are minted by the platform, which makes them much harder to fake — but a screenshot of an ID is only as trustworthy as the screenshot.
- Your local time. The “Local” column uses your browser’s time zone; quote the UTC value in reports.
How was the decoder tested?
The same engine file that runs this page (id-decoder-engine.js) was run in Node.js against published examples, and the page itself in headless Chromium:
- Discord’s documentation example
175928847299117063→ 2016-04-30T11:18:25.796Z, worker 1, process 0, increment 7. - X’s data-dictionary sample post
1212092627178287104→ 2019-12-31T19:26:16.568Z (the API reports 19:26:16). - RFC 9562 Appendix A vectors
C232AB00-9414-11EC-B3C8-9F6BDECED846(v1),1EC9414C-232A-6B00-B3C8-9F6BDECED846(v6) and017F22E2-79B0-7CC3-98C4-DC0C0C07398F(v7) → all 2022-02-22T19:22:22Z (2:22:22 PM GMT-05:00). - ULID
01ARYZ6S41TSV4RRFFQ69G5FAV→ 1469918176385 ms, as in the ulid/javascript README ulid/javascript README (fetched 8 Oct 2026); KSUID0ujtsYcgvSTl8PAuAdqWYSMnLOv→ timestamp 107608047, 2017-10-09 21:00:47 −07:00, payloadB5A1CD34…345C9735, as in the KSUID README. - MongoDB’s
ObjectId("6592008029c8c3e4dc76256c"), which its manual builds fromnew Date("2024-01-01")→ 2024-01-01T00:00:00Z, and00000020…→ 32 seconds after the epoch. - The TID spec’s valid and invalid examples (e.g.
3jzfcijpj2z2avalid;3JZFCIJPJ2Z2A,zzzzzzzzzzzzzinvalid) and2222222222222= 0. - Ryan Benson’s Bill Nye video
6854717870488702213→ 2020-07-29T02:06:13Z, 4 seconds from the createTime his post quotes for a Bill Nye video. - 2,500 encode-decode round trips across Discord, Twitter/X, Instagram, Mastodon and TikTok layouts, plus URL extraction for every supported site, hostile input (
<img onerror>,javascript:) and a 500-row cap.
Sources
- Discord Developer Docs: Snowflakes (fetched 8 Oct 2026)
- Twitter Engineering: Announcing Snowflake (1 Jun 2010)
- twitter-archive/snowflake IdWorker.scala (2010–2012)
- X API docs: X IDs (fetched 8 Oct 2026)
- X API docs: data dictionary sample (fetched 8 Oct 2026)
- Mike Krieger, “Sharding @ Instagram”, SFPUG slides (Apr 2012)
- mastodon/mastodon lib/mastodon/snowflake.rb (fetched 8 Oct 2026)
- Ryan Benson, “Tinkering with TikTok Timestamps” (11 Aug 2020)
- Bellingcat tiktok-timestamp (GitHub)
- AT Protocol spec: Timestamp Identifiers (fetched 8 Oct 2026)
- ULID specification (GitHub, fetched 8 Oct 2026)
- ulid/javascript README (fetched 8 Oct 2026)
- segmentio/ksuid README and ksuid.go (fetched 8 Oct 2026)
- RFC 9562: Universally Unique IDentifiers (May 2024)
- MongoDB Manual: ObjectId() (fetched 8 Oct 2026)
- MongoDB specifications: BSON ObjectID (fetched 8 Oct 2026)
- reddit-archive/reddit r2/lib/db/thing.py (archived source)
- YouTube Data API: Videos resource (fetched 8 Oct 2026)
Vendor and platform statements are reported as published; TikTok’s layout and Instagram’s shortcode mapping come from independent research, as marked above.
Frequently asked questions
How do I find out when a Discord account, server or message was created?
Copy its ID (Developer Mode → Copy ID) or paste a discord.com/channels/… link. Every Discord ID is a snowflake whose top 42 bits count milliseconds since the Discord epoch, 1 January 2015 00:00 UTC, so the decoder shows the creation time to the millisecond, plus the worker, process and increment fields. A message link decodes the server, channel and message separately.
Can I see when a tweet was posted from its ID, even if it was deleted?
Yes, for tweets created after Snowflake IDs arrived in late 2010. Paste the x.com or twitter.com status link or the number: shifting the ID right by 22 bits and adding Twitter’s epoch, 1288834974657 ms, gives the creation time in UTC to the millisecond. The ID alone is enough, so it still works when the post is gone. Older, pre-Snowflake IDs are sequential and carry no time.
How do I get the upload date of a TikTok video from its link?
Paste the full tiktok.com/@user/video/… URL. The first 32 bits of the 64-bit video ID are a Unix timestamp in seconds, a method documented by DFIR researcher Ryan Benson in 2020 and used by Bellingcat’s TikTok timestamp tool. It is usually within a few seconds of TikTok’s own createTime. Short vm.tiktok.com links must be opened first, because the page does not fetch anything.
Does an Instagram post link contain its date?
Indirectly. The shortcode in instagram.com/p/… or /reel/… is the post’s 64-bit media ID written in a URL-safe base64 alphabet. Converting it back gives the media ID, whose top 41 bits are milliseconds since Instagram’s custom epoch 1314220021721, a layout Instagram described in 2012. The shortcode-to-ID step is community-documented rather than officially published, and long shortcodes from private posts do not decode.
What does the code at the end of a Bluesky post link mean?
It is a TID, the AT Protocol’s Timestamp Identifier: 13 base32-sortable characters encoding a 64-bit number whose next 53 bits after the top bit are microseconds since 1970 and whose last 10 bits are a random clock ID. The decoder shows the record key’s time to the microsecond. Because users’ software chooses record keys, a TID can be set to any time and is not proof of when a post was made.
Which UUIDs contain a timestamp?
Versions 1, 6 and 7. UUIDv1 and v6 store a 60-bit count of 100-nanosecond intervals since 15 October 1582, and v1 may also expose the network card address of the machine that made it. UUIDv7 starts with a 48-bit Unix timestamp in milliseconds. Versions 3, 4 and 5 are hashes or random numbers with no time inside, and the tool says so.
Why does a bare number show more than one possible date?
Discord, Twitter/X, Instagram, TikTok and Mastodon all use 64-bit numeric IDs with different epochs and bit shifts, so the same digits decode to different dates on each platform. The tool keeps only readings that fall between the platform’s launch and today, picks the first, marks it low confidence and lists the others. Paste the full URL, add a prefix such as twitter:, or choose the platform to remove the doubt.
Is anything I paste uploaded or logged?
No. Decoding is plain JavaScript arithmetic that runs in your browser; there are no network requests when you decode, and Max Intel stores nothing. The shareable link puts the IDs in the address bar, so only share it with people who may see them.