Tool
Provably fair dice verifier
This provably fair dice verifier recomputes dice rolls from a revealed server seed, your client seed and the nonce. Choose HMAC-SHA256, the scheme Stake documents, or HMAC-SHA512, which the DiceSim simulator uses. You can check up to 1,000 nonces at once and confirm that the server seed matches the hash you were shown before playing. All hashing happens in your browser.
Seeds
Shown by the casino after you rotate the seed pair
The hash shown before you played, checked against SHA-256 of the server seed
Up to 1,000
The prefilled seeds are demo values. Every hash is computed on this page; seeds are not sent to DiceSim or anywhere else.
Computing...
How provably fair dice verification works
Before you play, the casino picks a random server seed and shows you a hash of it. You choose a client seed. Each bet uses a nonce that starts at 0 and goes up by one per bet. When you rotate the seed pair, the casino reveals the server seed, and anyone can recompute every roll made with it.
There are two checks. The hash check shows that the server seed was fixed before your bets. The roll check shows that each result came from that seed, your client seed and the nonce. If both pass, the casino could not pick results after seeing your bets.
The Stake-style HMAC-SHA256 scheme
Stake’s provably fair implementation page builds bytes with createHmac('sha256', serverSeed) over the message ${clientSeed}:${nonce}:${currentRound}, uses 4 bytes per game result and lists dice among the games that use a single round (cursor 0). Its game events page translates a dice float as (float * 10001) / 100. This verifier keeps the first two decimals of that number, which gives 10,001 possible rolls from 0.00 to 100.00.
Other sites may use a different hash, message format or rounding. If your rolls do not match in either mode, check the site’s own fairness page for its algorithm.
Worked example with demo seeds
Server seed 4f3a2d1c9b8e7f60a1b2c3d4e5f60718293a4b5c6d7e8f9012345678abcdef01, client seed dicesim-demo. Its SHA-256 hash is 66611f3e929417626a4140b7de6bc78e8ca8bdaca5ebce3bbdcc688f60a38cea.
For nonce 0 with HMAC-SHA256 the message is dicesim-demo:0:0. The first four bytes are 4, 76, 53, 108, so the float is 0.0167878522 and the roll is floor(167.8953) / 100 = 1.67.
| Nonce | Message | SHA-256 roll | SHA-512 roll |
|---|---|---|---|
| 0 | dicesim-demo:0:0 | 1.67 | 38.81 |
| 1 | dicesim-demo:1:0 | 13.88 | 13.16 |
| 2 | dicesim-demo:2:0 | 59.99 | 10.37 |
| 3 | dicesim-demo:3:0 | 14.60 | 89.86 |
| 4 | dicesim-demo:4:0 | 91.88 | 56.14 |
Paste the demo seeds into the verifier above to reproduce these rows. The how provably fair dice works guide covers the commit and reveal scheme in more detail.
What stays on your device
The verifier runs on this page with the same roll code as the DiceSim simulator. It does not call the DiceSim API, so the seeds you paste are not sent to us or stored anywhere. A revealed server seed is no longer used for future bets, so pasting one into a verifier does not let anyone predict your next rolls.
FAQ
Provably fair verifier questions
How do I verify a Stake dice roll?
Rotate your seed pair on Stake so the old server seed is revealed. Paste that server seed, the client seed and the nonce of the bet into the verifier and pick HMAC-SHA256. The roll shown for that nonce should match the result in your bet history. Paste the hashed server seed you saw before playing to confirm the casino did not change it.
Are my seeds sent anywhere?
No. The hashes are computed by JavaScript on this page. The verifier makes no network requests with your seeds, so they are not sent to DiceSim or to any other server.
Why does my roll not match?
Common causes are a nonce that is off by one, a client seed with an extra space, a server seed from a different pair, or the wrong algorithm. Try the neighbouring nonces and check that the seed hash matches.
What is the difference between the SHA-256 and SHA-512 modes?
Only the hash function inside the HMAC. Both use the server seed as the key, clientSeed:nonce:0 as the message and the first four bytes of the result for the roll. HMAC-SHA256 is the scheme in Stake's published implementation. HMAC-SHA512 is what the DiceSim simulator uses by default.
Can I verify a server seed before it is revealed?
No. Before rotation you only have its hash, and a hash cannot be reversed. That is the point of the scheme: the casino commits to the seed without showing it, then reveals it so you can check every bet made with it.
Related pages
- How provably fair dice worksThe commit, reveal and verify steps explained.
- Crypto dice calculatorPayout, streak odds and risk of ruin for a strategy.
- Dice odds by win chanceWhat each win chance pays and how often it loses in a row.
- Dice bot simulatorReplay seeds through a Lua strategy with provably fair rolls.
- Lua dice bot scriptsFree strategy scripts to run on any seed pair.
- All dice calculators and toolsMartingale, losing streak, payout and house edge calculators.