Every result in this casino is fixed before you bet and can be recomputed by you afterwards, in your own browser, with the same code the server uses. This page explains how and lets you do it.
Three things decide a bet: our secret server seed, your client seed and a counter, the nonce. They go into one HMAC-SHA256, keyed with the server seed. Its 32 bytes give eight numbers between 0 and 1, four bytes each; a game that needs more asks for further rounds of the same message with a round counter appended.
Those numbers pick the reel stops, the ball's direction at every peg, the dice roll, the order of a shuffled deck, where the mines are or the crash point. The return setting of a game shapes its paytable, never the numbers.
Because the server seed is committed before you bet (as its hash) and your client seed is yours, neither side can steer a result: we cannot change the seed afterwards, and you cannot know the numbers in advance.
numbers = HMAC_SHA256(key = server seed, message = "client seed:nonce") numbers 8 to 15: message "client seed:nonce:1", then ":2" and so on one number = byte1/256 + byte2/256^2 + byte3/256^3 + byte4/256^4 shuffle (cards): Fisher-Yates from the back, swap i with floor(number x (i + 1))
The server seed is 32 random bytes, written as 64 hex characters. You never see it while it is in use; you see its SHA-256 hash, and every bet you make records that hash.
When you rotate your seeds, the server seed is revealed and a new one takes over. Hash the revealed seed and compare: it has to match the hash you saw before and the hash on every bet made under it. If it matched, the seed was fixed before you played.
Where the next pair is already committed, its hash is shown as well, before you choose the client seed it will run with.
The client seed is your half. Type any text of 1 to 64 characters (no spaces or colons) and it goes into every message. A random one is set for you when you open your wallet or rotate without typing one.
A new client seed always comes with a new server seed, so no bet is ever decided by a pair you did not see committed first.
The nonce counts the bets on one seed pair: 0, 1, 2 and so on. It is part of the message, so every bet on the pair gets different numbers from the same seeds.
A round (a blackjack hand, a mines board, a free spin session, a crash flight) uses the numbers of one nonce in order: everything it deals is fixed the moment it opens. Free spins that a spin triggered continue the numbers right after the spin's own.
The global jackpot draws its own number from the same pair and nonce with the message "client seed:nonce:jackpot", so it never shifts the game's numbers.
You need nothing but this page. Every computation runs in your browser.
Prefer your own tools? Any HMAC-SHA256 implementation gives the same numbers; the game code is the same the server runs.
The pair your bets use right now, and the pairs you have revealed.
Open your wallet to get your seeds.
Your last bets and rounds. Verify fills the verifiers with everything the bet recorded: seed pair, nonce, options, return setting and the server seed hash.
Open your casino wallet to see your bets here.
Seeds and bets belong to a casino wallet. Open your wallet
Enter a revealed server seed, its client seed and the nonce of a bet, or click Verify on a bet above. The return percent is the one the game showed when you played: it sets the paytable, never the reel stops or the ball's path.
Every bet and every round opening draws for the global jackpot with its own message. Enter the seed pair and the nonce (Verify on a bet fills them in, with the chance the bet had) and compare the roll with the chance.
roll = HMAC_SHA256(key = server seed, message = "client seed:nonce:jackpot"), first 4 bytes as a number in [0, 1) hit when roll < chance
Rounds are replayed from the revealed server seed and every move you made, exactly as the server played them. The log shows the server time of every move.
No finished rounds yet.
Every bet records the rules version of its game. When the rules of a game change (a new paytable, another way to pay), its version goes up, and the verifiers check every bet with the rules it was played under, never with the newer ones. Return settings are not rules changes: each bet records its own. Changes since launch:
The rocket's multiplier follows the server clock from the moment the round opened. A cash out counts at the server time your request ARRIVES, not at the moment you pressed and not at what your screen showed. Your connection's delay is yours; the server never guesses it.
That arrival time is logged with the move and shown in the round log above, next to the counter at that moment. The replay uses exactly that time, so you can compare it with your own clock and see what the delay cost or gave.
m(t) = e^(t / 10 s), rounded down to 0.01 2x after 6.9 s, 10x after 23 s, 100x after 46 s, 10,000x after 92 s
The crash point is drawn from one fair number when the round opens and is secret until the round ends. A cash out at multiplier c wins exactly when c is at or below the point, and pays c. An auto cash out set before the launch fires at its target on the server clock, with no delay at all.
If the rocket explodes while your cash out is still on its way but the request arrived at or before the explosion, the cash out is honoured at its arrival time. A request that arrives after the explosion is a loss.
Play for fun, with money you can spare. The house keeps a small edge on every game, so over time the casino wins. Set a daily loss limit or take a break in your wallet whenever you like.