Skip to content

Provably fair dice

Check every roll

How it works

  1. 1

    The server locks a seed

    Before the first roll, the server picks a secret random seed and publishes its SHA-256 fingerprint (the commitment). Once published, the seed cannot change without the fingerprint changing too.

  2. 2

    Both players add their own

    Each player's app sends its own random seed when the match starts. So the server alone could not have planned the dice, even if it wanted to.

  3. 3

    Every roll comes from the seeds

    Roll number k is HMAC-SHA256 of the match id, both player seeds and k, keyed with the server seed. Biased bytes are skipped, so each face has exactly the same chance.

  4. 4

    The seed is revealed at the end

    When the match ends the server seed is published. Anyone can hash it, compare it with the commitment and recompute every roll, as this page does in your browser.

roll(k) = HMAC-SHA256(key = serverSeed, "matchId|seedA|seedB|k|c"); byte b < 252 → die = b mod 6 + 1

Check any seed set

Paste the values from any match. The dice are computed here in your browser; nothing is sent anywhere.

Play online