Skip to content
The Payout Ladder

Last updated:

the casino

Compiled by The editors

Terms, registers and two real-money accounts Last updated: 16 September 2026

Seeds, hashes and one nonce

Provably Fair Check: Recomputing One Round Yourself, Step by Step

A provably fair round can be rebuilt from three inputs and one hash function. Here is the procedure by hand, a worked example with real numbers, and what a match does and does not prove.

A provably fair check lets you confirm that a round's result was fixed before your bet and was not altered afterwards. You do not have to trust a badge that says so. You need three inputs, a hashing tool and some patience, and the result either matches or it does not.

The procedure below is a generic one built on HMAC-SHA256. Each game describes its own formula on its fairness page, and nothing here says that any named casino uses this exact scheme. Treat it as a way to understand the idea, then follow the formula printed for the game you play.

The method is easiest to follow in games with a single random draw per round, such as dice or a coin flip. Games that deal several cards or place several tiles use the same seeds but read more of the output, so their formulas are longer. The principle of commit first, reveal later stays the same.

  1. 1 an identity-check clause stands in the terms 9 of 12
  2. 2 that clause names the moment the check begins 6 of 12
  3. 3 a money amount is written into the clause 2 of 12
  4. 4 a time limit for sending documents appears in the terms 4 of 12
  5. 5 the licence register shows the licence against the casino’s own domain 7 of 12
The five criteria and how many of the 12 ranked casinos meet each. Bonus size, game counts and any advertised speed stay outside the points.

The three inputs

The server seed and its hash

The server seed is a random string chosen by the game before you play. It stays secret while it is in use, but its SHA-256 hash is shown to you in advance. A hash works in one direction only: anyone can turn the seed into the hash, while nobody can work backwards from the hash to the seed. Showing the hash first is a commitment, since the seed revealed later must produce exactly that hash.

The client seed

The client seed is your contribution. Many fairness panels let you type your own or accept a random one. Because it is mixed into every result, the game cannot have picked outcomes that suit it without knowing your seed, which is why setting a fresh one yourself is worth the few keystrokes.

The nonce

The nonce is a counter. It goes up by one with each bet placed on the same pair of seeds, so every round gets a different input even though the seeds stay the same. Some games start counting at 0 and others at 1, a detail that matters when you recompute a round.

A provably fair check, step by step

  1. Before your first bet, copy the server seed hash shown in the fairness panel and keep it somewhere outside the game.
  2. Set or note your client seed.
  3. Play, and note the nonce of any round you want to verify.
  4. Rotate the seeds once you are done. The game then reveals the server seed it used and commits to a new one.
  5. Hash the revealed server seed with SHA-256 and check that every character agrees with the string you kept from step 1.
  6. Compute HMAC-SHA256 with the server seed as the key and your client seed, a colon and the nonce as the message.
  7. Turn the output into a result using the formula the game prints, and compare it with the round in your history.

Any HMAC-SHA256 calculator will do, as will the hashing library of a scripting language you already have. Paste values rather than retyping them, since one wrong character is enough to break the comparison, and keep the seeds, the nonce and your result together in one note so the round can be rechecked later.

A worked example with real numbers

The seed below is short to keep it readable; real server seeds are longer.

  • Server seed: 5e2b9c14a7d03f68. Its SHA-256 hash begins 914e17f2c81eee7a, and that is the string you would have saved before playing.
  • Client seed: reader-seed-42.
  • Nonce: 1, giving the message reader-seed-42:1.
  • HMAC-SHA256 output begins f9059c41.

A common way to reach a dice result from 0 to 99.99 takes the first eight hexadecimal characters, reads them as one number, divides by 4,294,967,296 (two to the power of 32), multiplies by 100 and keeps two decimals. Here f9059c41 is 4,177,894,465; divided by 4,294,967,296 that is 0.97274 and a little more, so the roll is 97.27.

With the nonce at 2, the message becomes reader-seed-42:2. The output begins b6589656, which is 3,059,258,966, and the roll is 71.22. Two rounds, two different results, both fixed the moment the server seed was committed and the client seed was set.

When your numbers do not match

Before concluding anything, rule out the usual slips. The key and the message may be swapped. The separator may be a hyphen instead of a colon, or the nonce may start at 0. A stray space copied with the seed changes every character of the output, and some tools expect upper-case hexadecimal. Only when the game's own formula, applied carefully, still gives a different result do you have a real mismatch to report.

What a match proves, and what it leaves alone

A match proves one narrow thing: the result of that round followed from a server seed committed before your bet and a client seed you controlled. The game could not have picked the outcome after seeing your stake.

It proves nothing about the edge built into the formula. How results map to payouts is where a game's return lives, and the arithmetic of return and edge works the same whether or not a round is verifiable.

It also says nothing about taking money out. A casino whose every round checks out can still set a minimum per request, ask for documents at a certain amount, cap what leaves per week or pay a large sum in parts. Those rules come from its terms, and the amount ladder on the home page follows them floor by floor. The same applies to licences: a verified hash is not a register entry for a licence, and the way the ranking is scored rests on terms and registers, not on fairness panels.

Habits that keep the check meaningful

  • Set your own client seed before a session rather than accepting one you never looked at.
  • Save the server seed hash first, outside the game, so a revealed seed can be compared with something the game could not edit.
  • Rotate after a session and verify a sample of rounds, including any unusually large win or loss.
  • Write down the nonce of rounds that matter while they are fresh; long histories are hard to search later.

The same modesty applies to this site: its editors and sources describe rules from terms, and no page claims that a verifiable game changes those rules.

There is also a limit to what one person can check. Verifying a handful of rounds shows those rounds were committed in advance; it cannot show anything about rounds you did not recompute. The commitment works the same way for every round, though, so a game that altered results could be caught on whichever round a player happened to pick.

A check done now and then keeps its value. A seed pair that is never rotated never reveals its server seed, and then nothing can be verified at all.

Frequently asked questions

Questions people actually type

Do I need special software for a provably fair check?

No. Any tool that computes SHA-256 and HMAC-SHA256 is enough, including the hashing functions built into common scripting languages. What matters more is using the exact formula the game prints on its fairness page: the order of key and message, the separator, where the nonce starts and how the output is turned into a result.

Does a verified round mean the game has a good return?

No. A successful recomputation only confirms that the outcome was settled by committed seeds and stayed untouched once you had bet. The return depends on how results are mapped to payouts, which is a separate figure shown in the game's info panel. A game can be fully verifiable and still carry a large edge on every bet you place.

Can a provably fair check tell me anything about withdrawals?

No. Minimums, document requests, caps per period and instalments all come from the operator's terms, not from seeds and hashes. A round that verifies perfectly has no bearing on how much you can request or when documents are asked for. Read the clauses that cover the amount you plan to take out.
Our pick Open the casino