I use a uuid v4 to generate custom userId that is then stored in the session cookie for facilitate authorisation and authentication. I also store this userId in the database to uniquely identify users. On some of my api's i have the server return that userId as a means to identify users. For example, if i built a reddit clone and i have an end point that returns all the posts from a particular subreddit with each post having the userId of the author. Is this bad practice? I don't want to use the auto generated primary key for each table to uniquely identify users, because since its sequential, it can be guessed.