Skip to main content

Affiliate disclosure:Some links on this site route through tracked affiliate partnerships. ClearCasinos may earn a commission if a reader signs up, at no cost to the reader. Rankings stay independent and follow our published affiliate disclosure.

Nataly Aleksieva
By Nataly Aleksieva — Casino Reviewer · LinkedIn
Table of Contents▼

Provably Fair Explained: What It Proves and What It Doesn't

Provably Fair Explained: What It Proves and What It Doesn't

Every crypto casino puts "provably fair" somewhere on the home page. Almost none of them explain what the phrase covers, and the gap between what players assume it means and what it actually guarantees is wide enough to lose money in.

The short version: provably fair proves the casino did not change the outcome of your bet after you placed it. That is a real, cryptographically solid guarantee. It says nothing about the house edge, nothing about the slots in the main lobby, and nothing about whether the operator will actually send your withdrawal.

Key takeaways

  • Provably fair proves the result was fixed before your bet, not that the odds favour you.
  • It covers in-house Originals – dice, crash, mines, plinko – not the third-party slot lobby.
  • The house edge stays exactly where the casino set it. Cloudbet's verified Originals run at 1%.
  • A hashed server seed shown before you play is the whole mechanism. No commitment, no proof.
  • It is not a licence, not proof of solvency, and not a guarantee you get paid.

What the cryptography actually does

Picture the problem it solves. You bet on a dice roll. The casino generates the number. Without any verification layer, you have no way to know whether the casino generated that number honestly or waited to see your bet and then picked a losing one.

Provably fair closes that specific hole with a commitment scheme. The casino locks in the result before you bet, publishes proof that it locked something in, and lets you check afterwards that it never swapped the answer.

Three ingredients make it work:

  • Server seed – a secret random string the casino generates. You see only a hash of it up front.
  • Client seed – a string you control. You can type your own or let the browser generate one.
  • Nonce – a counter that increments with every bet, so the same seed pair produces a different result each round.

The outcome comes from running those three through a cryptographic hash function. Stake and most of the market use HMAC-SHA256. Implementations vary – Cloudbet's system runs on SHA3-256 and SHAKE256 with a public verification calculator. The function does not matter much. The commitment does. Stake builds those games in-house rather than licensing them in, which is the part of its operation we could verify most easily when we ran a full legitimacy check on the brand.

Here is the part that carries all the weight: the casino shows you the hashed server seed before your first bet. A hash is one-way. It reveals nothing about the seed, but it is a fingerprint the casino cannot fake later. When you rotate your seed, the casino reveals the original string, you hash it yourself, and you compare it to the fingerprint you were given. If they match, the seed was fixed before you ever placed a bet.

Key Takeaway

The proof lives in the timing. A server seed hash published before you play is a commitment. A "verification" tool that only appears after the round is theatre.

How to actually verify a bet

Most players never do it once. It takes about two minutes.

  1. Find the fairness settings before you play – usually under your profile or a "Fairness" tab in the game itself.
  2. Copy the hashed server seed. Save it somewhere outside the casino.
  3. Set your own client seed. Type something arbitrary rather than accepting the default. It is the step that stops the casino pre-computing results against a seed it chose for you.
  4. Play your rounds. Note the nonce on the bet you want to check.
  5. Rotate the seed. Rotating retires the old server seed and forces the casino to reveal it.
  6. Hash the revealed seed with any SHA-256 tool and compare it to the fingerprint from step 2. Then replay the bet – server seed, your client seed, that nonce – through a third-party verifier and confirm you get the same result.
Pro Tip

Run the final check on an open-source verifier hosted somewhere other than the casino. A calculator built by the operator you are auditing proves whatever the operator wants it to prove.

What it does not prove

Four gaps, in the order they cost players money.

It does not change the house edge. A provably fair game can be verifiably stacked against you, and every one of them is. Cloudbet's Originals run at a flat 99% RTP, which is a 1% house edge – lean by casino standards, and still an edge. The cryptography confirms the game ran at the odds the casino published. It does not make those odds good. If you want the mechanics behind that number, we cover how RTP and volatility play out over a real session separately.

It does not cover the slot lobby. Here is the one that surprises people. At every operator we review, the provably fair label applies to the in-house Originals set – crash, dice, mines, plinko, limbo, hilo – and not to the thousands of third-party slots that make up the bulk of the site. Rainbet runs 10 provably fair Originals next to a full third-party lobby. Roobet runs 10 alongside 6,000+ slots. BC.Game is the outlier on volume with 75+ in-house titles, and even there the Pragmatic and Hacksaw games in the lobby are not verifiable.

Those third-party slots are not unregulated – they run certified RNGs audited by labs like GLI, iTech Labs, or eCOGRA. Different model entirely: you trust an auditor's certificate instead of checking the maths yourself. Cloudbet is the one meaningful exception we have found, having added 21 third-party provably fair titles alongside its 13 in-house ones.

Heads Up

If a casino advertises "provably fair" on its home page and you spend your session on Sweet Bonanza, you played nothing verifiable. The badge describes a corner of the game library, not the site.

It does not replace a licence. Verification proves the dice were honest. It says nothing about segregated player funds, dispute resolution, or who you complain to when things go wrong. A provably fair casino with no credible regulator behind it is a site with honest games and no recourse – and the difference between regulators is bigger than most players assume, which is why we break down what each licence actually buys you.

It does not mean you get paid. The largest category of complaints against crypto casinos has nothing to do with rigged games. It is withheld withdrawals, KYC holds on large wins, and bonus terms that void the balance. Rainbet's welcome-code winnings, for instance, cap out at $50 no matter what you turn that bonus into – verifiably fair rounds, contractually capped payout. If a payout stalls, the fairness tab will not help you; the escalation path when a casino refuses to pay runs through support, then the licensing body, then ADR.

Red flags in a provably fair implementation

Not every system that carries the label deserves it. Five things we check when scoring the crypto casinos we rate:

  • No hashed server seed before play – without an up-front commitment there is nothing to verify against.
  • A locked client seed – if you cannot set your own, the casino controls both inputs.
  • No seed rotation – the old server seed never gets revealed, so the commitment never gets tested.
  • A closed verifier – the algorithm should be published so anyone can rebuild the check independently.
  • The badge on a slots-only site – a casino with no in-house games has nothing provably fair to offer.

Bottom line: treat provably fair as a narrow, genuine guarantee about game outcomes, and judge the operator on licensing, payout record, and bonus terms the same way you would judge any other casino. It is a good signal. It is not a shortcut past the rest of the due diligence.

FAQ

What does provably fair mean?

Provably fair means you can cryptographically verify that a casino did not alter the result of your bet after you placed it. The casino commits to a hashed server seed before play, reveals the original seed afterwards, and you confirm the two match and that the result replays correctly.

Does provably fair mean better odds?

No. The house edge is unchanged. A provably fair game verifies that the casino ran the odds it advertised – those odds still favour the casino. Cloudbet's Originals sit at 99% RTP, which is a 1% house edge on every verified round.

Are slots provably fair?

Almost never. Provably fair applies to in-house Originals like crash, dice, mines, and plinko. Third-party slots from Pragmatic Play, Hacksaw, NetEnt and others use certified RNGs audited by testing labs instead, which you cannot verify yourself.

What is a server seed and client seed?

The server seed is a secret random string the casino generates and shows you only as a hash before you play. The client seed is a string you set yourself. Combining both, plus a nonce that counts your bets, produces each result – so neither side controls the outcome alone.

Can a provably fair casino still cheat you?

Not on the game outcome, if the system is implemented properly and you verify. It can still refuse a withdrawal, void a bonus on a technicality, hold funds during KYC, or fold entirely. Fairness verification covers the maths, not the business.

Do I have to verify every bet?

No. Spot-checking is enough. The deterrent works because verification is possible at all – a casino that manipulated results would be caught by any single player who checked. Verify a handful of rounds after each seed rotation.

Is provably fair better than an eCOGRA or GLI certificate?

They solve different problems. Provably fair lets you check individual results with no trusted third party. A lab certificate covers the whole game library, including slots, but asks you to trust the auditor. The strongest setup combines both – verifiable Originals plus certified third-party games under a real licence.