A seed published after the fact proves nothing — the server could have picked it once it knew the result. What makes a flip provable is the order: the server publishes SHA-256 of its secret seed before the flip, each player adds their own seed, and the outcome is derived from all of them. Afterwards the secret is revealed and anyone can check both halves. This page does that check, in your browser, without asking us anything.
Every field comes from the flip's verification panel. Nothing is sent anywhere — the computation happens locally.
Fill in the commitment, the server seed and the digest to check a flip.
HMAC-SHA256(serverSeed, "clientSeedA:clientSeedB:n"). The first hex digit of that digest decides the face — even is Heads, odd is Tails. Sixteen equally likely digits, eight per side, so there is no bias. What this does not cover: a server that never publishes a commitment up front, or one that shows you a different commitment afterwards than the one it showed before. Take a screenshot of the commitment if a flip really matters to you.
Nothing to check yet? Flip a coin online with friends — one shared room, one synced toss, and a proof like this one behind every result.