SHA-256 In Provably Fair Games: What The Hash Proves And What It Does Not
Provably fair games lean on one tool, the SHA-256 hash. It is what lets a site commit to a result before you bet without telling you what it is. Here is how it works in practice on Cryptoflip, and where its guarantees stop.
A hash is a fingerprint
SHA-256 turns any input into a fixed 64-character string. The same input always gives the same output, a tiny change to the input gives a completely different output, and there is no practical way to work backwards from the output to the input.
Commit before, reveal after
Before a round, the site generates a secret server seed and shows you only its SHA-256 hash. After the round it reveals the seed. Hash it yourself: if it matches the hash you were shown, the seed was fixed before you bet and was not changed.
How Original turns a hash into a side
Original hashes the server seed, client seed, nonce and both account IDs with SHA-256. The first eight characters of the result are read as a number and scaled between 0 and 1, and below 0.5 is blue.
How the Wheel uses HMAC-SHA256
The Wheel uses HMAC-SHA256, a keyed version of the same hash, with the server seed as the key and the client seed and nonce as the message. The first eight characters become the roll that places the pointer on the wheel.
Why the client seed matters
The server seed is the site's input. The client seed and nonce mean the result also depends on something the server did not choose alone, so the site could not have picked a seed that happens to produce a run of results it liked.
What it proves
A matching hash proves the result came from inputs fixed before the round, and that anyone running the same calculation gets the same outcome. It rules out the site changing a result after seeing your bet.
What it does not prove
It does not tell you the odds are good. The house edge is part of the game design, stated separately: 5% of the pot on Original and 10% on the Wheel. Verification proves the game was run as described; it does not make a bet a good one.
Checking it yourself
Any SHA-256 tool will hash a revealed server seed so you can compare it with the hash you were shown. The verifier on the Provably Fair page goes further and recomputes the whole result in your browser without calling the site's API.
SHA-256 is what turns "trust us" into "check it". Open any settled Original game or Wheel spin and run it through the verifier to see the calculation end to end.
Ready to play? Try Original or the Wheel on Cryptoflip.