Skip to content
BestCryptoDiceGames
All pages
By
The BestCryptoDiceGames desk
Desk
Dice odds and casino terms
Updated
18 September 2026

The game · Fairness

Provably fair dice: how to check a roll yourself

Provably fair dice lets you prove the casino fixed its secret before you bet and could not change the result afterwards. Here is how the seeds work, a worked example you can repeat, and what a successful check does and does not prove.

The promise of provably fair dice is simple: you do not have to trust the casino, because you can check it. Every roll is calculated from inputs that are locked before you bet, and after the fact you can recalculate the roll yourself. This page shows how that works, with a real calculation you can repeat, and explains exactly what a successful check proves.

The three inputs

Every provably fair dice roll comes from three pieces of data:

InputWho sets itWhen you can see it
Server seedThe casinoOnly as a hash while in use; in full after you rotate
Client seedYou (or a random default)Always
NonceThe game, counting your betsAlways

The trick is the hash. Before you place a single bet, the casino shows you the SHA-256 hash of its server seed. A hash works in one direction: it is easy to compute from the seed and practically impossible to reverse. Once the casino has shown you the hash, it cannot swap the seed for another one without the hash changing. It has committed.

How the roll is calculated

The exact formula varies by site and is published in each game's fairness page. A common implementation, the one used by Stake-style originals, works like this:

  1. Take the message client seed:nonce:0.
  2. Compute HMAC-SHA256 of that message, using the server seed as the key.
  3. Take the first four bytes of the result, each a number from 0 to 255.
  4. Turn them into a fraction between 0 and 1: byte1/256 + byte2/256² + byte3/256³ + byte4/256⁴.
  5. Multiply by 10,001, round down, and divide by 100. That gives a roll from 0.00 to 100.00.

Other sites use a different step 4 or 5, for example reading hexadecimal characters until they find a value under a million. The principle is always the same: fixed inputs in, one deterministic number out.

A worked example you can repeat

Here is a real calculation with made-up seeds, so you can run it in any HMAC-SHA256 tool and get the same numbers.

  • Server seed: a3f1c07e5d9b2e48f6a1d3c5b7e9f0a2c4e6a8b0d2f4a6c8e0b2d4f6a8c0e2f4
  • Hash shown before betting (SHA-256 of the server seed): e7c198194a805b40270d38fb8b0b264c5436c8d917aa30bcf75290f790835cab
  • Client seed: myluckyseed
NonceHMAC begins withFirst four bytesFractionRoll
091fbe79c…145, 251, 231, 1560.57025057.03
1e4a2b690…228, 162, 182, 1440.89310889.31
25cd5fe28…92, 213, 254, 400.36264036.26

If you bet roll under 49.50 on these three nonces, you lose, lose, win. Nothing about your bet changes the roll: the target only decides whether the number counts as a win.

How to verify your own rolls

On a real site the steps are:

  1. Before playing, open the fairness panel and note the hashed server seed. Set a client seed of your own if you like.
  2. Play as normal. Each bet's nonce is shown in your bet history.
  3. Rotate the seed pair in the fairness panel when you finish. The casino reveals the old server seed in full and shows the hash of a new one.
  4. Check the hash. Compute SHA-256 of the revealed server seed and compare it with the hash you noted. They must match exactly.
  5. Recalculate a few rolls. Use the site's verify tool or an independent calculator with the same formula, and compare the rolls with your bet history.

If step 4 fails, the casino changed its seed and the game is not provably fair. If step 5 fails, either the formula you used differs from the site's or the results were altered; check the formula first.

The DuckDice lobby with Original Dice pinned at the top
DuckDice puts its own Original Dice first in the lobby, ahead of slots and sports. It is a dice site that added a casino, not the other way round.

What a successful check proves

A matching hash and matching rolls prove three things:

  • The server seed existed before your first bet.
  • The casino did not change it while you played.
  • Each result follows from the seeds and nonce, not from a decision made after you bet.

It does not prove:

  • That the game has no edge. The edge is in the payout, 1.98× instead of 2× at 50%, and is fully visible.
  • That the casino will pay out. Fair rolls and a fair cashier are separate questions. That is why our ranking of crypto dice games scores the licence and the terms, not the game.
  • That provider games are fair in the same way. Studio games are tested by labs; you cannot verify them seed by seed.

Why your client seed matters

If the casino chose both seeds, in theory it could search for a server seed that produces an unlucky sequence for the default client seed. Setting your own client seed removes that possibility, because the casino commits to its server seed before it knows yours. It takes ten seconds: type any string you like into the client seed field before you start a session.

Sites in our list with provably fair dice

These dice sites run in-house dice with a fairness panel. The ranking and the rules behind it are the same as on the home page.

Provably fair and responsible play

Knowing the rolls are honest can make dice feel safer than it is. A fair game with a 1% edge still takes about 1% of everything you wager, and it does so at the speed you play. Keep a deposit limit, keep auto-bet on a stop-loss, and read how crypto dice works before you trust any system. If you want the numbers for a particular target, the dice odds calculator has them all.