← Coin Flip

Verify a coin flip

A seed published after the fact proves nothing — the server could have picked it once it knew the result. What makes a flip provable is the order: the server publishes SHA-256 of its secret seed before the flip, each player adds their own seed, and the outcome is derived from all of them. Afterwards the secret is revealed and anyone can check both halves. This page does that check, in your browser, without asking us anything.

The values

Every field comes from the flip's verification panel. Nothing is sent anywhere — the computation happens locally.

Result

Fill in the commitment, the server seed and the digest to check a flip.

How the proof works

  1. Commit. When a room opens, the server generates a secret server seed and publishes only its SHA-256 hash. The hash reveals nothing about the seed, but it pins the server to that exact value — it can no longer swap in a different one later.
  2. Contribute. Each player's browser generates a client seed, which you can replace with anything you like. The server has already committed, so it cannot pick its seed to suit yours.
  3. Derive. The result of round n is HMAC-SHA256(serverSeed, "clientSeedA:clientSeedB:n"). The first hex digit of that digest decides the face — even is Heads, odd is Tails. Sixteen equally likely digits, eight per side, so there is no bias.
  4. Reveal. When the match ends, the server publishes the server seed. Hash it: it must match the commitment from step 1. Recompute the HMAC: it must match the digest published with your result. Both hold, or something is wrong.

What this does not cover: a server that never publishes a commitment up front, or one that shows you a different commitment afterwards than the one it showed before. Take a screenshot of the commitment if a flip really matters to you.

Nothing to check yet? Flip a coin online with friends — one shared room, one synced toss, and a proof like this one behind every result.