Site uses a different format?
Roll result
Runs in your browser. Nothing is sent anywhere.
How a roll is made
1Server seed
Site picks a secret
2SHA-256, shown first
Shows you its fingerprint
15f59d72…338f
3Client seed + nonce
You add your seed
my-lucky-seed : 42
4HMAC-SHA256
Mixed together
1045441f…9cdd
58 hex ÷ 2³²
Turned into a roll
6.36
Why it works: the hash locks the site in before you bet. Later it reveals the seed; if the hash of that seed matches, nothing was swapped.
What “provably fair” does not prove
- That the odds are goodA box can be fully verifiable and still pay back 70% of its price.
- That the odds didn't changeScreenshot the odds table before opening big boxes.
- That item values are realA "$400" prize that sells back for $250 changes the maths.
- That you'll get paidPayouts are a trust question. That's why we score them separately.
The full explanationShow
Before you play, the site commits to a secret server seed by showing you its SHA-256 hash. A hash is a fingerprint: anyone can compute it from the seed, but nobody can work backwards, and no one can find a second seed with the same fingerprint.
Your result comes from HMAC-SHA256(serverSeed, "clientSeed:nonce"). You control the client seed, and the nonce counts up by one each open. The first 8 hex characters become a number, divided by 2³² to give a roll between 0 and 1, which lands on a prize according to the odds table.
When you rotate seeds, the site reveals the old server seed. Hash it: if it matches what you were shown, the site couldn't have changed your results. Some CS2 sites also mix in a public value like a future EOS block hash; sites opening real sealed card packs use the physical pack instead of seeds.