Skip to content

Transparency

Provably Fair

Before a flip begins, the server commits to a secret value by publishing its cryptographic hash. Once the flip is complete, the secret is revealed. Anyone can verify that the original commitment matches and reproduce the result.

  1. 1. Commit

    When a flip is created, the server generates a secret 32-byte server seed and publishes only its SHA-256 hash. The hash is shown on the flip before anyone joins.

  2. 2. Contribute

    The creator and the opponent each contribute a client seed. The opponent’s seed is only added after the commitment is public, so the server cannot choose a seed that favours anyone.

  3. 3. Derive

    The result is HMAC-SHA256(serverSeed, "clientSeed:nonce:gameId"). The first 4 bytes are read as a number; even means HEADS, odd means TAILS.

  4. 4. Reveal

    After the flip, the server seed is published. Anyone can check that it hashes to the original commitment and recompute the result.

Verify a flip

Verification runs entirely in your browser using the same open code as the server. Open a flip from your history to prefill it.

What this does and does not guarantee

  • The server cannot change the server seed after publishing its hash, and it cannot know the opponent’s client seed when it commits.
  • Given the revealed inputs, anyone gets the same result. Each flip uses its own server seed, so revealing one never exposes another.
  • It does not rule out the operator also playing: an operator-controlled account joining a flip could know the seed in advance. The system proves results were not altered; it cannot prove who is behind an account.
  • The mapping (4 bytes mod 2) has no bias because 2³² is divisible by 2. HMAC-SHA256 output is indistinguishable from random, which is a standard cryptographic assumption, not something this page can prove.
  • The algorithm is versioned (currently v1). It never changes silently; a new version gets a new name and old flips keep verifying with the version they used.