Provably fair dice
Check every roll
How it works
- 1
The server locks a seed
Before the first roll, the server picks a secret random seed and publishes its SHA-256 fingerprint (the commitment). Once published, the seed cannot change without the fingerprint changing too.
- 2
Both players add their own
Each player's app sends its own random seed when the match starts. So the server alone could not have planned the dice, even if it wanted to.
- 3
Every roll comes from the seeds
Roll number k is HMAC-SHA256 of the match id, both player seeds and k, keyed with the server seed. Biased bytes are skipped, so each face has exactly the same chance.
- 4
The seed is revealed at the end
When the match ends the server seed is published. Anyone can hash it, compare it with the commitment and recompute every roll, as this page does in your browser.
roll(k) = HMAC-SHA256(key = serverSeed, "matchId|seedA|seedB|k|c"); byte b < 252 → die = b mod 6 + 1
Check any seed set
Paste the values from any match. The dice are computed here in your browser; nothing is sent anywhere.