Guide
What Does Provably Fair Mean? Seeds, Hashes and a Worked Example
How provably fair crypto games work: server seed, client seed, nonce and SHA-256, a worked dice example you can reproduce, and what it does not prove.

Provably fair means a casino commits to a game result before you bet and lets you check afterwards that it did not change it. The casino shows you a SHA-256 hash of a secret server seed, you add your own client seed, and each bet’s result is calculated from both plus a counter called the nonce. When the server seed is revealed, anyone can recompute every result. What it proves is narrow: the outcome was not altered after your bet. It says nothing about the house edge, the licence, or whether the casino will pay you.
This guide explains the parts (seeds, nonce, hashes), walks through a worked example you can reproduce on your own computer using the method Stake documents publicly, and lists what provably fair does not cover. It is part of our crypto gambling guides.
What does provably fair mean?
In a normal online casino you trust a random number generator (RNG) that you cannot inspect. Independent labs test it, a regulator may audit it, and you rely on that chain of trust. A provably fair game replaces part of that trust with maths you can run yourself.
The idea is a commit-and-reveal scheme. Before any bet, the casino picks a secret value (the server seed) and publishes only its hash, a fingerprint that cannot be reversed. You then choose or accept a client seed. Every result comes from combining the two seeds with a bet counter. Later the casino reveals the server seed; you hash it, confirm the fingerprint matches what you were shown at the start, and recompute your results. If one number differs, the game was not fair.
The phrase is mostly used for in-house crypto casino games such as dice, crash, limbo, plinko, mines and keno. Third-party slots and live dealer tables work differently, as explained further down.
The building blocks: RNG, seeds, nonce and hashes
Random number generators
Every casino game needs a source of unpredictable numbers. Regular online casinos run an RNG on their own servers or on the game studio’s servers. In a provably fair system the random numbers are derived from the seeds instead, so the “randomness” can be recreated by anyone who has the inputs.
Server seed
A secret random string generated by the casino. At Stake it is a random 64-character hexadecimal string. You only see its hash while the seed is in use. Revealing it early would let you calculate future results, so it stays hidden until you rotate to a new pair.
Client seed
Your input. Stake’s documentation says your browser creates one at registration and recommends that you replace it with your own, so that your influence is included in the randomness. Because the casino committed to its server seed before you set the client seed, it cannot pick a server seed that produces bad results for a client seed it did not know.
Nonce
A number that goes up by one with every bet on the same seed pair. It is what makes bet 1, bet 2 and bet 3 different without changing either seed.
Cursor
Some games need more random numbers than one hash provides. Stake uses 4 bytes per number, so a 32-byte hash gives 8 numbers; the cursor counts extra rounds of hashing when a game needs more, for example a blackjack hand that deals more than 8 cards.
Hashes and HMAC
SHA-256 turns any input into a 64-character fingerprint. The same input always gives the same output, a one-character change gives a completely different output, and you cannot work backwards from the output to the input. HMAC-SHA256 is a keyed version: it mixes a secret key (here the server seed) with a message (here your client seed, nonce and cursor) and outputs 32 bytes that nobody could predict without the key.
How the provably fair algorithm works, step by step
Implementations differ between casinos, but Stake publishes its method in full and many crypto casinos use the same pattern. The sequence for one dice bet looks like this:
- The casino generates a server seed and shows you its SHA-256 hash.
- You set a client seed. The nonce starts counting from your first bet on this pair.
- For each bet, the casino computes HMAC-SHA256 with the server seed as the key and the text “client seed:nonce:cursor” as the message.
- The first 4 bytes of that output become a number between 0 and 1: byte 1 divided by 256, plus byte 2 divided by 256 squared, plus byte 3 divided by 256 cubed, plus byte 4 divided by 256 to the fourth power.
- The game turns that number into an outcome. For Stake’s dice, which has 10,001 possible results from 00.00 to 100.00, the documented formula is the number times 10,001, divided by 100.
- When you rotate seeds, the old server seed is revealed and a new hashed one takes its place. You can now verify every bet made on the old pair.
Games with many outcomes reuse the same output. A card game multiplies each number by the cards left in the deck (52, then 51, and so on), and games where results cannot repeat, such as mines or keno, use a Fisher-Yates shuffle so each tile or number is drawn once.
Worked example you can reproduce
The values below are made up for this guide and were never used at any casino. Every number comes from running the documented algorithm, so you can check each one yourself.
| Input | Value |
|---|---|
| Server seed (secret until rotation) | 4111eee21f8d9da5d1712e76ce5046d49c4ae033414de2429025cb90f6d67409 |
| Hashed server seed (shown before betting): SHA-256 of the seed text | d12968a815f23de63f4e1883ded75f495d6b013bef895dec9c5d08b18fd9b1dd |
| Client seed (chosen by the player) | my-own-seed-42 |
| Nonce, cursor | 1, 0 |
Step 1: check the commitment
Hash the revealed server seed with SHA-256, treating it as plain text. The result must equal d12968a8…fd9b1dd. If it does, the casino used this exact seed from the moment it showed you the hash.
Step 2: compute the HMAC
Run HMAC-SHA256 with the server seed as key and the message my-own-seed-42:1:0. The output for nonce 1 is 4ed5fe64fefb32ce74ac265de4b096243d9a88e4f723f22ec29bd043081955fd.
Step 3: turn bytes into a number
The first four bytes are 4e, d5, fe and 64 in hex, which are 78, 213, 254 and 100 in decimal. So the number is 78/256 + 213/65,536 + 254/16,777,216 + 100/4,294,967,296 = 0.30795278…
Step 4: turn the number into a dice roll
0.30795278 × 10,001 ÷ 100 = 30.798358…, which the game shows as 30.79 when it cuts the value to two decimals. If you had bet on “roll under 50”, this bet would win; on “roll over 50”, it would lose.
The next two bets
| Nonce | First 4 bytes (decimal) | Number 0-1 | Dice roll |
|---|---|---|---|
| 1 | 78, 213, 254, 100 | 0.30795278 | 30.79 |
| 2 | 119, 19, 45, 74 | 0.46513637 | 46.51 |
| 3 | 162, 141, 120, 14 | 0.63497115 | 63.50 |
Check it on your own computer
With Python 3 installed, this one line prints the hash and the first roll (change the 1 to 2 or 3 for the other bets):
python -c “import hmac,hashlib;s=’4111eee21f8d9da5d1712e76ce5046d49c4ae033414de2429025cb90f6d67409′;print(hashlib.sha256(s.encode()).hexdigest());b=hmac.new(s.encode(),b’my-own-seed-42:1:0′,hashlib.sha256).digest();f=sum(b[i]/256**(i+1) for i in range(4));print(f*10001/100)”
The same calculation in Node.js uses crypto.createHmac(‘sha256’, serverSeed), which is the call shown in Stake’s implementation page. If your result does not match a casino’s verifier, check for a space in the client seed, the wrong nonce (some sites start at 0, others at 1) or a different game formula.
The same seeds in other games
The dice example uses only the first 4 bytes of each hash. Other games read the same numbers through a different formula, which Stake also publishes. Using the seed pair above:
| Game | Documented formula | Input | Result |
|---|---|---|---|
| Limbo | 1 ÷ number × 0.99 (a 1% house edge), cut to two decimals, minimum 1.00x | Nonce 2: 0.46513637 | 2.12x |
| Roulette | number × 37, rounded down, for pockets 0 to 36 | Nonce 3: 0.63497115 | Pocket 23 |
| Plinko, 8 rows | each number × 2, rounded down: 0 = left, 1 = right | Nonce 1: all 8 numbers from one hash | L, R, L, R, L, R, R, L |
The limbo line shows where the house edge lives. A raw number of 0.465 would give 2.15x without the 0.99 factor; the formula shaves 1% off every possible result, and you can see it in the published code. The plinko path uses all 32 bytes of the nonce 1 hash: eight numbers of 4 bytes each, one per row. With four rights and four lefts, the ball ends in the middle slot of the nine at the bottom.
That is the real value of a published formula. You can read off the house edge and check that the game applies it the same way on every bet, rather than taking a “99% RTP” label on trust.
Games that need more than eight numbers
One HMAC output is 32 bytes, enough for eight numbers of 4 bytes each. A blackjack hand with splits, a keno draw or a mines board with many mines can need more. That is where the cursor comes in: for the ninth number onwards, the message becomes “client seed:nonce:1”, then “:2”, and so on, each producing another 32 bytes. The nonce stays the same because it is still one bet.
When you verify a long game by hand, this is the step people miss. If your ninth card does not match, check that you moved on to cursor 1 rather than starting a new nonce. Games that draw without repeats, such as mines, also shrink the multiplier as they go: the first mine position uses the number times 25 tiles, the second times 24, and so on.
Why the client seed stops the casino cheating
Imagine a casino that wanted to rig a provably fair game. With a hash commitment alone, it could still generate millions of server seeds offline, calculate which one produces a losing run, and commit to that one. The client seed blocks this. Because you set or change your seed after the hash is shown, the casino cannot know which message will be hashed, so it cannot test seeds in advance against your future bets.
The same logic explains why you should change the client seed yourself instead of keeping the default. A default seed generated by the casino’s own page is, in principle, something the casino could know. Changing it costs nothing and closes the gap. Changing the client seed also rotates the pair at many casinos, which reveals the old server seed for checking.
How to verify your own bets at a casino
- Open the fairness or seed settings in the game and note the hashed server seed and your client seed before you play.
- Set your own client seed. Any string works; a random word plus numbers is enough.
- Play. Each bet slip should show the nonce it used.
- Rotate the seed pair. The casino now reveals the old server seed.
- Check that its SHA-256 hash equals the hash you noted in step 1.
- Recompute a few bets with the casino’s verifier, an independent verifier, or the script above. Pick bets you lost as well as ones you won.
Keep your own record of the hashed server seed. A verifier hosted by the casino is convenient, but checking the commitment against a hash you saved yourself is what makes the proof independent.
What provably fair does NOT prove
Most marketing stops at “provably fair, so you can trust us”. The system is narrower than that:
- It does not prove the odds are good. The algorithm can show that a dice roll was not changed. It does not tell you the payout table. A game that pays 1.98x on a 50% chance returns 99% over time (0.5 × 1.98); one that pays 1.90x returns 95%. Both are equally “provably fair”.
- It does not prove the casino will pay. Withdrawal delays, account closures, bonus rule disputes and KYC requests sit outside the game maths. The licence, the operator company and the terms decide those.
- It does not cover provider slots or live tables. A slot from a studio such as Pragmatic Play, or a live table streamed from a studio, uses its own certified RNG or physical cards and wheels. A casino that calls itself “provably fair” usually means its in-house originals only.
- It proves nothing until the seed is revealed. While you keep betting on the same pair, the seed stays hidden. If you never rotate it, you never verify anything.
- It depends on your client seed. If you keep a seed that the casino’s own page generated, you rely on that page not having picked it with knowledge of the server seed. Setting your own seed removes that doubt.
- It verifies only the published formula. You confirm that the result matches the documented method. Whether the screen displayed the same result, and whether the bet settled at the stated multiplier, you check on the bet slip yourself.
- It does not make anyone more likely to win. Recording results or switching seeds cannot predict the next outcome. Systems sold as “provably fair predictors” are scams.
Red flags: when “provably fair” is only a label
The term has no legal definition, so any site can use it. These signs suggest the claim is weaker than it sounds:
- No hash before the bet. If the casino does not show a hashed server seed until after you play, it has not committed to anything.
- You cannot change the client seed. Without your input, the server seed alone decides every result.
- No published formula. A verifier button with no documentation of how bytes become results cannot be checked independently.
- Seeds that never rotate. If you cannot reveal the current server seed by starting a new pair, you can never verify past bets.
- Studio slots labelled provably fair. Some sites put the badge on the whole lobby. Unless a game shows its own seed settings, it is not covered.
- Verifier only on the casino’s domain. It may well be honest, but you should still be able to repeat the calculation with standard SHA-256 and HMAC tools, as in the example above.
Glossary
| Term | Meaning |
|---|---|
| Hash | Fixed-length fingerprint of any data; SHA-256 gives 64 hex characters |
| Commitment | Publishing a hash of a secret so it cannot be changed later without detection |
| Server seed | The casino’s secret input, revealed on rotation |
| Client seed | The player’s input, editable at any time |
| Nonce | Bet counter for the current seed pair |
| Cursor | Extra hashing rounds when a game needs more than 8 numbers |
| Rotation | Ending a seed pair: the old server seed is revealed, a new hashed one starts |
| Fisher-Yates shuffle | Method that draws items without repeats, used for cards, mines and keno |
| House edge | The share of each bet the game keeps on average; 1% in the limbo formula above |
Provably fair games: pros and cons
| Pros | Cons |
|---|---|
| You can check each result yourself, without trusting a lab report | Only covers in-house games, not the slot and live lobbies most players use |
| Commitment is fixed before the bet, so results cannot be edited afterwards | Says nothing about payouts, house edge, withdrawals or licensing |
| Usually a low, clearly stated house edge on simple games such as dice | Verification takes effort, and few players rotate seeds and check |
| Works the same way at any casino that uses the published method | Formulas differ by site, so one site’s verifier may not match another’s games |
Provably fair casinos vs regular crypto casinos
Provably fair casinos
Crypto-first casinos built their reputations on in-house games with published seeds. Stake’s originals (dice, crash, plinko, mines and others) all use the documented method above. BC.Game and FortuneJack offer their own provably fair originals, and Winz.io lists provably fair crash and plinko titles. Read our reviews of Stake, BC.Game, FortuneJack and Winz.io for licence, coins and withdrawal details. PrimeDice, one of the first provably fair dice sites and run by the Stake founders, is closed: it stopped taking bets on 8 October 2025.
Ordinary crypto casinos
Many casinos that accept Bitcoin are standard online casinos with a crypto cashier. Their games come from licensed studios, and fairness rests on the studio’s certified RNG, testing by independent labs such as GLI or eCOGRA, and the regulator. That model is not worse, it is just a different kind of trust: you rely on a third party’s audit instead of your own calculation.
| Point | Provably fair originals | Provider slots and RNG tables | Live dealer |
|---|---|---|---|
| Who produces the result | Seeds plus a published formula | The game studio’s RNG | Physical cards, wheels or dice on camera |
| Can you verify one result? | Yes, after seed rotation | No | Only by watching the stream |
| Who checks the system | You, plus anyone else | Test labs and regulators | Studio procedures, regulators |
| Typical games | Dice, crash, limbo, plinko, mines, keno | Slots, video poker, RNG roulette and blackjack | Blackjack, roulette, baccarat, game shows |
Which games are provably fair?
The provably fair label is common on these game types at crypto casinos:
- Dice: pick a target and over or under; the simplest game to verify. See our crypto dice guide.
- Crash and limbo: a multiplier rises until it “crashes”; the crash point comes from the seeds. Some multiplayer crash games instead publish the last hash of a long pre-generated chain and play the rounds backwards through it.
- Plinko: each row’s left or right bounce is one random number.
- Mines and keno: tile or number positions come from a shuffle driven by the seeds.
- Card originals: hi-lo, in-house blackjack, baccarat and video poker deal from a deck shuffled by the seeds.
- Roulette and wheel originals: one number multiplied by the count of pockets or segments.
House edge: the number provably fair cannot fix
Expected return equals the chance of winning times the payout. Work it out from the game’s own numbers before you play. A dice bet with a 49.5% chance and a 2.00x payout returns 0.495 × 2.00 = 0.99, so a 1% house edge. Over 1,000 bets of 0.0001 BTC (0.1 BTC wagered in total), the expected loss is 0.001 BTC, whatever the seeds say. Provably fair guarantees that the 1% is applied honestly to random results, not that you will finish ahead.
| Win chance | Payout at a 1% edge | Payout at a 3% edge |
|---|---|---|
| 90% | 1.1000x | 1.0778x |
| 49.5% | 2.0000x | 1.9596x |
| 10% | 9.9000x | 9.7000x |
| 1% | 99.0000x | 97.0000x |
The payout for any chance is (100% minus the edge) divided by the chance. If a dice game’s multipliers sit below the 1% column, the edge is higher than 1%, even though every roll is provably fair.
Compare that with bonus wagering. If a bonus needs 0.4 BTC of turnover on a game with a 1% edge, the expected cost of clearing it is about 0.004 BTC. Many casinos also exclude or reduce the contribution of originals such as dice towards wagering, so check the terms first.
Provably fair and crypto casino banking
Crypto-only casinos
Some casinos accept only cryptocurrency and keep balances in coins. Provably fair originals are common at this type of site because their players already check hashes on block explorers. Crypto-only does not mean unregulated: most hold an offshore licence from Curaçao, Anjouan or the Tobique Gaming Commission.
Hybrid casinos
Others accept cards, e-wallets and crypto, and may convert crypto deposits into a fiat balance. Their game lobbies lean towards studio slots and live tables, so provably fair games are a small part of the offer or absent. Our Bitcoin casino list shows which type each brand is.
Either way, deposits and withdrawals are not provably fair in any sense. A blockchain transaction is public and final, but the decision to approve your payout is the casino’s.
How to choose a casino for provably fair games
- Read the fairness documentation first. It should name the hash function, show how bytes become results and give the formula for each game.
- Test the verifier on a small bet. Play a few rounds at the minimum stake, rotate the seeds, and recompute them with an independent tool.
- Check the licence on the regulator’s register. Our licence guides show how for Curaçao, Anjouan and Tobique.
- Read how originals count towards bonus wagering. Many casinos reduce or exclude dice-type games.
- Look at withdrawal limits and identity rules. A fair game is no use if a big win is capped or held for weeks.
- Set limits before you play. Fast originals such as dice and limbo allow hundreds of bets an hour, so expected losses add up quickly even at a 1% edge.
Can provably fair casinos solve every problem?
No. Provably fair addresses one specific fear: that a casino edits results after you bet. The common complaints about crypto casinos are about something else: delayed or refused withdrawals, bonus terms applied after a win, sudden identity checks, and accounts closed for “irregular play”. None of those is touched by seed hashing.
So treat provably fair as one item on a checklist, next to a licence you can verify on the regulator’s register, a known operator company, published withdrawal limits, and a complaint route. Our rating method covers how we weigh those factors.
Playing originals responsibly
Provably fair originals are among the fastest games in any casino. Auto-bet tools can place a dice bet every second, and a strategy that doubles the stake after each loss can empty a balance in one short losing streak, however fair the seeds are. Decide on a session budget in your own currency, use the casino’s deposit and loss limits, and stop when the budget is gone. If gambling stops being fun, Gamblers Anonymous (gamblersanonymous.org) offers free support, and our responsible gambling page lists self-exclusion options. Gambling is for adults only.
FAQ
What is a provably fair casino?
A casino whose in-house games let you check each result. It commits to a hashed server seed before you bet, combines it with your client seed and a nonce, and reveals the server seed when you rotate seeds so you can recompute every outcome.
Are provably fair games easier to win?
No. Provably fair proves that a result was not changed after your bet. The house edge is set by the payout table, and a provably fair dice game with a 1% edge still costs you about 1% of everything you wager over time.
What is a server seed and a client seed?
The server seed is a secret random string chosen by the casino and shown to you only as a SHA-256 hash until you rotate it. The client seed is your input, which you can change at any time. Results come from both, plus a nonce that counts your bets.
Why can’t I verify a bet before it is settled?
Because the server seed must stay secret while it is in use. If you could see it, you could calculate the results of future bets. You verify after rotating to a new seed pair, when the casino reveals the old seed.
Are slots and live casino games provably fair?
Usually not. Slots and RNG tables from game studios rely on certified random number generators tested by independent labs, and live dealer games use physical cards and wheels. The provably fair label normally covers a casino’s in-house originals only.
Does provably fair mean the casino is safe?
No. It says nothing about the licence, the operator company, withdrawal limits or how disputes are handled. Check those separately before you deposit.
Can I play provably fair games on my phone?
Yes. The originals at crypto casinos run in a mobile browser, and the seed settings and verifier are in the same fairness menu. Checking a hash by hand is easier on a computer, but any SHA-256 tool works.
Sources
- Stake: Provably fair implementation (HMAC_SHA256, server seed, client seed, nonce, cursor)
- Stake: Provably fair conversions (bytes to floats, Fisher-Yates shuffle)
- Stake: Provably fair game events (dice: float x 10001 / 100)
- NIST FIPS 180-4: Secure Hash Standard (SHA-256)
- RFC 2104: HMAC keyed-hashing for message authentication
- Node.js crypto.createHmac documentation
- Stake licences page (Medium Rare N.V.)
- PrimeDice closure discussed on Bitcointalk (Aug 2025; betting ended 8 Oct 2025)
- Gaming Laboratories International (GLI)
- eCOGRA
- Gamblers Anonymous