Provably Fair Explained: How to Check a Casino Round
Provably fair means the casino locks in each result before you bet, by publishing a cryptographic fingerprint of it, and then reveals the data that produced it, so anyone can recompute the result and confirm nothing was changed. It proves the round wasn't altered. It doesn't make the odds generous or guarantee a withdrawal. We recompute the rounds of the provably fair games we track from each casino's own fairness data, more than 12.5 million so far, and this guide explains what that checking involves and how to do it yourself.
Key takeaways
- Definition: provably fair means the result is fixed and committed to (as a hash) before you bet, and the data behind it is revealed afterwards so you can recompute it.
- The pieces: a server seed (the casino's secret), its SHA-256 hash (the commitment), usually a client seed (yours) and a nonce (the bet counter).
- How to check: hash the revealed server seed and compare it with the hash shown before your bet, then run the game's published formula on the seeds to get the result.
- What it can't prove: it doesn't lower the house edge, doesn't cover third-party slots, and says nothing about whether the casino pays withdrawals.
- Our checks: 12,587,519 rounds of seven multiplier games across five casinos, each recomputed from the casino's own fairness data.
What does provably fair mean?
Provably fair is a way of running a casino game so that the player can check each result after it happens. Before a round, the casino commits to a secret value by publishing its hash, a fingerprint that can’t be reversed. After the round, it reveals the secret. You hash it yourself, confirm it matches the fingerprint you were shown, and run the game’s formula to confirm the result.
The point is timing. The casino can’t pick a result after seeing your bet, because the value that decides it was fixed, and publicly fingerprinted, before you placed it. Change one character of the secret and the hash changes completely, so a swapped seed is caught the moment you check.
How it works: server seed, client seed and nonce
Most provably fair games use the same four pieces:
| Piece | Who sets it | What it does |
|---|---|---|
| Server seed | The casino | The secret that decides results; kept hidden until revealed |
| Server seed hash | The casino | SHA-256 of the server seed, shown before you bet: the commitment |
| Client seed | You (or your browser) | Mixed into every result, so the casino can’t pre-plan outcomes for you |
| Nonce | Counter | Goes up by one with each bet, so every bet on the same seeds differs |
The game combines them, usually with HMAC-SHA256, and turns the output into a result with a published formula: a dice roll, a card, a crash point. When you rotate to a new client seed, the casino reveals the old server seed and you can check every bet made with it.
Three designs we check in practice
Multiplayer crash games can’t use your personal client seed, because every player shares the same round. They fix fairness in other ways, and we recompute rounds from all three kinds:
- A hash chain with a public salt. The casino generates a long chain of hashes up front, each one the hash of the next, and plays it backwards. Before the first round it names a salt it can’t control, such as a future Bitcoin block hash. Gamdom Crash, BC.Game Crash and Shuffle Crash work like this. One revealed hash lets you recompute every earlier round.
- A server seed plus a public randomness beacon. Duel Crash commits to a hashed server seed, then mixes it with a value from drand, a public beacon run by independent organisations, that didn’t exist when bets closed.
- A verifiable random function. Rollbit’s X-Crash and X-Roulette use the same setup: each round’s random value is published together with a cryptographic proof that it came from Rollbit’s committed key.
Different mechanics, same promise: the result was fixed by something the casino couldn’t adjust after seeing the bets.
How to verify provably fair results yourself
- Collect the data. From the game’s fairness or verify panel, copy the server seed hash shown before your bet, the revealed server seed, your client seed and the nonce. For a crash round, take the round’s hash and the published salt.
- Check the commitment. Run the revealed server seed through a SHA-256 tool. The output must equal the hash you were shown before betting. If it doesn’t, stop there: the seed was changed.
- Recompute the result. Apply the casino’s published formula. For most games that means an HMAC-SHA256 of the seeds and nonce, a few hex characters turned into a number, and that number turned into the outcome.
- Compare. The result you calculate must equal the result the game showed, to the last decimal.
Use an independent tool for steps two and three. A casino’s built-in verifier runs the casino’s own code, so it can’t catch the casino.
What we found checking 12.5 million rounds
Every round in our multiplier-game trackers is recomputed from the casino’s own fairness data before it’s stored; a round that doesn’t reproduce is logged and left out. Here’s the running total:
| Game | Rounds recomputed | How each round is fixed |
|---|---|---|
| Gamdom Crash | 6,788,936 | Hash chain + salt |
| Shuffle Crash | 4,034,202 | Seed chain + Bitcoin block salt |
| Duel Crash | 1,317,307 | Server seed + drand beacon |
| Shuffle Slide | 395,429 | Seed chain + Bitcoin block salt |
| BC.Game Crash | 34,224 | Hash chain + salt |
| Rollbit X-Roulette and X-Crash | 17,421 | Verifiable random function |
At Shuffle, Gamdom, BC.Game and Rollbit, no round we derived has ever disagreed with a result the casino published. At Duel, the earliest rounds in its public history, roughly the first 23,600, follow an older version of the formula than the one Duel publishes today, so they don’t reproduce with the current script and aren’t in our records. Later rounds reproduce; the very few that don’t are logged for a closer look and kept out. That kind of version change is common and legitimate, but it’s exactly why checking beats trusting: a formula page describes the present, not every round ever played.
What provably fair can’t prove
Provably fair is a strong check on one thing, and it’s easy to read more into it:
- Odds: the formula includes the house edge. A verified game at 3% still keeps 3% of what’s wagered over time.
- Scope: it covers a casino’s in-house games and the few provably fair slots some studios sell. Most slots and all live tables aren’t provably fair, however the casino labels its lobby.
- Payouts: a result can verify perfectly on a casino that delays or refuses withdrawals.
- Checking: if you never rotate your client seed, the server seed is never revealed, and nothing gets checked.
For those gaps you still need the usual checks, and they answer the other question players ask, how to see if a casino is legit: a licence number you can look up on the regulator’s own register, a withdrawal record without a pattern of stalled payouts, and terms you can live with. Our casino reviews go through all three for each casino. Our guide to whether online slots are rigged covers how non-provably-fair games are tested instead.
Can a provably fair setup still work against you?
Yes, in the details around the maths rather than the maths itself. The commitment only protects you if the server seed hash is shown before you bet; a hash that appears afterwards proves nothing. A client seed the casino fills in and you never change gives you no say in the result. And a seed that’s never rotated is never revealed, so it’s never checked. Critics also point out that a casino could, in theory, generate many server seeds and quietly keep the ones it likes before committing. Hash chains and public beacons make that far harder, which is one reason the crash games above use them.
That’s also why so few players get any protection from it in practice: on forums the common answer to “does anyone actually check?” is no. A check you never run can’t catch anything.
Does provably fair mean you can’t lose?
No. It means the game can’t cheat you on a single round, which is different from the game being worth playing. It gives no strategy edge either: in a crash game every cash-out target carries the same built-in edge, and verifying past rounds tells you nothing about the next crash point, which sits behind a seed or hash that hasn’t been revealed yet. Every provably fair casino game still has a house edge built into the formula you’re verifying, so over time it returns less than you stake. And a verified history doesn’t predict anything: as we showed in our piece on the gambler’s fallacy, past rounds don’t change the next one’s odds.
If gambling stops being fun, GamCare and Gambling Therapy offer free, confidential help.
Frequently asked questions
Are online casinos provably fair?
Some of their games are, most aren't. Provably fair covers a casino's own in-house games, usually crash, dice, limbo, plinko and mines at crypto casinos, where the casino publishes the seeds and formula. Most slots and live tables from outside studios aren't; they rely on certified random number generators and lab audits instead. A few studios, BGaming being the best known, do sell provably fair slots, but they're the exception. A casino that calls itself provably fair means those originals, not its whole lobby.
How to check provably fair?
Find the round's fairness data in the game's verify or fairness panel: the server seed hash shown before the bet, the revealed server seed, your client seed and the nonce. Hash the revealed seed with SHA-256 and confirm it matches the earlier hash. Then feed the seeds into the formula the casino publishes and check that the result equals what you saw. Any online SHA-256 and HMAC tool can do the first two steps.
How to determine if a game is fair?
For a provably fair game, recompute a few rounds from the published seeds: if the results match, the game did what it promised. Then read the formula for its house edge, because a verified game can still be expensive. For games that aren't provably fair, look for a named testing lab certificate and a published return to player, and check that the operator's licence is real.
What is the least rigged game in a casino?
The closest thing to it is a provably fair game with a small house edge, because you can check every result and the built-in cost is low. Duel's crash game, for example, runs at a 0.1% edge, and rounds on its current formula can be recomputed from the server seed and a public randomness beacon; its earliest rounds used an older version. No casino game is free of an edge, so least rigged still means you lose slowly on average, not that you win.
How do I verify my game?
Open the bet in your history, copy its fairness data, and recompute it. Many casinos include a built-in verifier, but using an independent tool is the real test, because a casino's own checker can only show you what it chooses to. Before relying on a result, rotate your client seed so the casino's server seed is revealed, since most casinos only reveal a seed once you change it.
Set a budget before you play. Free, confidential help is available from GamCare and Gambling Therapy.