Provably Fair Explained: How to Verify a Crypto Casino Bet
The short answer
Provably fair is a cryptographic commit and reveal system. Before you bet, the casino shows you a SHA-256 hash of a secret server seed; each result is then calculated from that server seed, a client seed you can choose and a nonce (a bet counter). When the seed is revealed, you can recompute every result yourself and confirm the casino could not have changed the outcome after you placed the bet.
It proves that individual results were not manipulated. It does not lower the house edge, and it only applies to the casino’s own in-house games.
Why does provably fair exist?
At a traditional online casino you trust a random number generator (RNG) that you cannot see, plus a test lab certificate. Crypto-native casinos added a second layer: a way for the player to check each result with nothing more than a hash function. The idea comes from a standard cryptographic tool called a commitment scheme, which lets one party commit to a value while keeping it hidden and reveal it later. A good commitment is “hiding” (you cannot work out the value from the commitment) and “binding” (the committer cannot later swap in a different value).
The three ingredients
| Ingredient | Who controls it | What it does |
|---|---|---|
| Server seed | Casino | Secret random value. You only see its SHA-256 hash until you rotate it |
| Client seed | You (or a random default) | Mixed into every result so the casino cannot pre-select outcomes for you |
| Nonce | Counter | Goes up by one with every bet on the same seed pair, so each bet gets a fresh result |
The hash of the server seed is the commitment. Because SHA-256 is a one-way function, you cannot work backwards from the hash to the seed, and the casino cannot find a different seed that produces the same hash. So once you have seen the hash, the server seed is locked.
How a result is generated
The exact recipe differs between casinos, so always read the fairness page of the site you use. A common pattern looks like this:
- The casino computes
HMAC-SHA256(key = server seed, message = client seed + ":" + nonce). - The output is a 64-character hexadecimal string.
- The casino takes a fixed part of that string (for example the first few bytes), converts it into a number and scales it to the game. For a dice game that might be a number from 0 to 99.99. For a card game, successive chunks map to cards.
HMAC is a standard construction that combines a hash function with a secret key. HMAC-SHA256 simply means HMAC using SHA-256. It is available in every major programming language.
How to verify a bet yourself, step by step
- Before you play, open the fairness or seed settings and write down the hashed server seed.
- Set your own client seed. Type anything random. This matters: if you only ever use a seed the casino generated, you are trusting the casino to pick it fairly.
- Play and note the nonce of any bet you want to check (bet history usually shows it).
- Rotate the seed pair. The casino now reveals the old server seed in plain text and shows a new hash for the next round.
- Check the commitment. Hash the revealed server seed with SHA-256 using any trusted tool. The result must exactly match the hash you wrote down in step 1. If it does not match, stop playing there.
- Recompute the result. Run the HMAC with the revealed server seed, your client seed and the nonce, then apply the casino’s documented conversion formula. You should get the same roll, crash point or card as your bet history.
Here is a minimal Python example for steps 5 and 6. Swap in your own values and the casino’s conversion rule:
import hashlib, hmac
server_seed = "revealed-server-seed"
client_seed = "my-client-seed"
nonce = 42
# Step 5: does the revealed seed match the hash shown before you played?
print(hashlib.sha256(server_seed.encode()).hexdigest())
# Step 6: the raw result for this bet
digest = hmac.new(server_seed.encode(), f"{client_seed}:{nonce}".encode(), "sha256").hexdigest()
print(digest)
# Then apply the casino's published formula to turn the digest into a game result.
Many casinos also offer a built-in verifier. That is convenient, but for a real check use an independent tool or your own code, because a verifier hosted by the casino is still the casino.
What provably fair does not tell you
Provably fair is useful, but it is narrower than the marketing suggests.
- It only covers in-house games. Slots, live dealer tables and most other games come from third-party studios that use their own RNGs. Those games are not provably fair in this sense, even on a site that advertises provably fair.
- It does not change the house edge. A dice game with a 1% edge is still a 1% edge game. Verification shows the casino did not cheat on a roll. It does not make the game favourable.
- It does not check the conversion formula for you. If the published formula is unclear or the payout table is worse than advertised, the hash check still passes. Read the game’s rules and payout table as well.
- It does not guarantee payment. A perfectly fair dice game is no help if the casino will not process your withdrawal. Licensing, terms and complaint history still matter (see how to choose a crypto casino).
- It only works if you actually check. The protection comes from the possibility of verification. A sample check now and then, especially after a session that felt off, is enough for most players.
Red flags on a fairness page
- No way to set your own client seed.
- No hashed server seed shown before you bet.
- The server seed is never revealed, or only revealed on request through support.
- No documented formula for turning the hash into a result.
- The verifier only works on the casino’s own website.
Any one of these means the system cannot do its job. We note how each casino handles this in its review, as described on our methodology page.
Does provably fair mean I will win more?
No. Over many bets, the house edge decides the expected result, provably fair or not. If you want to compare games, compare the house edge or return to player (RTP) figures, and if you take a bonus, run the numbers in our wagering requirements guide.
A note on responsible play
Fair games still cost money over time. Gambling is for adults 18+ only. Set deposit and loss limits before you play, and see our responsible gambling page if it stops being fun.
Sources
- Commitment scheme (definition, hiding and binding): https://en.wikipedia.org/wiki/Commitment_scheme
- HMAC (definition and HMAC-SHA256 naming): https://en.wikipedia.org/wiki/HMAC
- NIST FIPS 180-4, Secure Hash Standard (SHA-256): https://csrc.nist.gov/pubs/fips/180-4/upd1/final
- Python documentation, hmac module: https://docs.python.org/3/library/hmac.html
- Wizard of Odds, house edge definition: https://wizardofodds.com/gambling/house-edge/