Part of the complete guide: Provably fair: the complete guide
The problem each one solves
| Ingredient | Who controls it | What it stops |
|---|---|---|
| Server seed | The operator, hidden until later | Stops the operator choosing results after seeing your bet, because its hash is committed first |
| Client seed | You | Stops the operator knowing the final result in advance, because you contribute input they cannot predict |
| Nonce | A counter | Stops every bet from producing the same result, and lets you replay each bet in order |
The server seed
A long random string chosen by the casino. Before you play, you are shown only its SHA-256 hash, which locks it in without revealing it. When you later change ("rotate") your seed pair, the casino reveals the old server seed, and you can hash it yourself to confirm it matches what you were shown. If it matches, the casino could not have altered the seed after seeing your bets.
The client seed
A string you control, which you can usually change at any time. Without it, a casino that knew its own server seed could compute every future result and choose when to let you win. Adding your input means the result depends on something the casino did not choose. Set your own, instead of accepting a default, and change it when you like.
The nonce
Starts at 0 and increases by one with every bet using the current seed pair. Because the inputs are the same otherwise, the nonce is what makes bet number 1 different from bet number 2. It also lets you verify bets one by one, in the order they happened. When you rotate seeds, the nonce restarts at 0.
How they combine
- 1The casino computes HMAC-SHA256 using the server seed as the key and the text "clientSeed:nonce" (sometimes with an extra round number) as the message.
- 2This gives 32 random-looking bytes, shown as 64 hexadecimal characters.
- 3The first few bytes are converted to a number between 0 and 1.
- 4The game maps that number to an outcome: for example a dice roll from 0.00 to 100.00.
Our provably fair calculator performs the HMAC and mapping, and compares the hashed server seed you paste with the one it computes. Formulas differ by site, so use the one the site publishes.
A short walk-through
Suppose the site shows you the hash of its server seed, you set the client seed "my-seed" and place bet number 0. After you rotate seeds, the site reveals the server seed. You hash it: it matches the hash you were shown. You compute HMAC-SHA256 with that seed as the key and "my-seed:0:0" as the message, take the first four bytes, convert to a fraction and apply the dice formula. If the result equals what the site showed for bet 0, that bet was computed honestly.
Common mistakes and gaps
- Never changing the client seed, so a default is used.
- Trusting the site's own "verify" button instead of an independent tool.
- Forgetting that the nonce restarts when you change seeds.
- Using the wrong formula for the game. Check the site's documentation.
- Assuming the system proves the odds are fair. It does not.
Example: three bets, three nonces
| Bet | Message hashed | Result (demo values) |
|---|---|---|
| 1st bet | my-client-seed:0:0 | dice roll 37.40 |
| 2nd bet | my-client-seed:1:0 | dice roll 21.27 |
| 3rd bet | my-client-seed:2:0 | dice roll 81.45 |
With server seed "cd-demo-server-seed". Only the nonce changed between the bets, yet the results are completely unrelated.
Good practice for players
- Set your own client seed and change it occasionally.
- Screenshot the hashed server seed before you play.
- Rotate seeds to reveal the old one and verify.
- Keep bet records so you can verify after rotation.
Ready?
A weekly draw you can check yourself.
$5 tickets, a public random value, and every result published with the data to recompute it.
Frequently asked questions
What is a server seed in provably fair?
A secret random value from the casino. Its hash is shown before you play and the seed is revealed after you rotate.
What is the client seed for?
So you contribute input that the casino cannot predict, which stops it from choosing results alone.
What is a nonce?
A counter that increases with each bet, so every bet has a different input.
How do I check a bet?
Hash the revealed server seed to confirm the commitment, then recompute the result with the published formula.
Can I change my client seed?
Usually yes, at any time. Changing it normally also rotates the server seed.
Why is the server seed hidden at first?
So you cannot predict results, while the hash proves the site cannot change it.
Is the nonce always from zero?
It depends on the site. Check its documentation.