Almost every CS2 case opening, crash and roulette site calls itself provably fair. The phrase sounds like a safety rating, and many players read it as one. It is narrower than that. Provably fair is a cryptographic receipt for the random number behind each result. Knowing exactly what it proves, and what it does not, is the difference between trusting a site for the right reasons and the wrong ones.
How provably fair works
Three ingredients produce every result:
- Server seed: a random secret chosen by the site. Before you play, the site shows you only its SHA-256 hash. A hash works like a sealed envelope: it fixes the seed without revealing it.
- Client seed: a value you control. Most sites generate one for you, and you can replace it with anything you like.
- Nonce: a counter that starts at 0 or 1 and goes up by one with every bet on the same seed pair.
The site combines the three, usually with an HMAC-SHA256 function, and turns the output into a number: a roll between 0 and 1, a ticket number for a case, or a crash multiplier. Because the server seed was locked in before you chose your client seed, the site cannot steer the result. Because you cannot see the server seed until later, you cannot predict it either.
When you rotate to a new seed pair, the site reveals the old server seed. Now you can check the envelope: hash the revealed seed and confirm it matches what you were shown at the start.
How to verify a roll yourself
- Before playing, open the fairness settings and copy the hashed server seed.
- Set your own client seed. Any random string works.
- Play, and note the nonce of any result you want to check.
- Rotate your seed pair. The site reveals the previous server seed.
- Hash the revealed server seed with SHA-256 and compare it with the hash you copied in step 1.
- Recalculate the result with the formula the site publishes and compare it with what you got.
Most sites have a built-in verifier, but checking with an independent tool is the point. This short Node.js script does both checks for the common HMAC-SHA256 setup:
const crypto = require('crypto');
const serverSeed = 'the-server-seed-revealed-after-rotation';
const hashedServerSeed = 'the-hash-you-saw-before-playing';
const clientSeed = 'your-client-seed';
const nonce = 42; // the bet number you want to check
// 1. The revealed seed must hash to the value shown before you played.
const hash = crypto.createHash('sha256').update(serverSeed).digest('hex');
console.log('Seed matches commitment:', hash === hashedServerSeed);
// 2. Recreate the roll. Many sites use HMAC-SHA256 like this, but always
// follow the exact formula your site publishes.
const hmac = crypto
.createHmac('sha256', serverSeed)
.update(clientSeed + ':' + nonce)
.digest('hex');
const roll = parseInt(hmac.slice(0, 8), 16) / 2 ** 32; // between 0 and 1
console.log('Roll:', roll);Each site turns the hash into a result slightly differently, for example how many characters it reads or how it maps the roll to case tickets. If a site does not publish its exact formula, you cannot verify anything, and that is a red flag on its own.
How crash games prove fairness
Crash works a little differently because every player sees the same multiplier. Many crash games generate a long chain of hashes before the first round and then play it backwards, so each round's hash can be checked against the next one. A public salt fixed in advance, often the hash of a future blockchain block, stops the operator from picking a chain that suits it. Once a round ends, you can hash its value and confirm it links to the previous round. Our crash sites guide covers the other checks worth making before playing.
Case odds and value: the part provably fair skips
On a case opening site the roll picks a ticket, and an odds table maps tickets to items. Provably fair proves the ticket. It does not tell you whether the case is worth opening. For that you need the expected value:
Expected value = sum of (item drop chance × item market value)
If a case costs 5 dollars and its contents are worth 4.10 dollars on average, the case returns 82% and the site keeps 18% of every opening over time. Two things inflate that picture:
- Site prices vs market prices. Items are often valued above what they sell for on the Steam Market or third-party markets. Check a few big items yourself. Our Steam Market fees guide explains why Steam prices also overstate what you can cash out.
- Hidden or rounded odds. If the per-item drop chances are not shown, or do not add up to 100%, you cannot work out the value at all.
What provably fair does not prove
- The size of the house edge or the return to player.
- That item values or the odds table match what is shown on the case page.
- That withdrawals are processed quickly, or at all.
- That the site is licensed, legal where you live, or will keep the same terms.
- That bonus and promo terms are fair. Those are covered in our bonus terms guide.
A site can be perfectly provably fair and still be a bad place to put money. Treat the fairness page as one item on the checklist, not the whole checklist.
A quick checklist before you play
- The site publishes its exact formula and lets you set your own client seed.
- You can rotate seeds and see past server seeds and nonces.
- Per-item drop chances are shown and add up to 100%.
- The return to player is stated, or you can work it out from the odds.
- Recent users report withdrawals completing in a reasonable time.
- Terms, ownership and restricted countries are easy to find.
Our site trust scorecard turns these checks into a score, and the case opening sites guide applies them to specific sites.