3v4l.org

run code in 500+ PHP versions simultaneously
<?php $serverSeed = 'paste server seed here'; // 32 characters, e.g. 086127124b1bd0b3d8027aef9b89c6b9 $serverSalt = 'paste server salt here'; // 16 characters, e.g. 03859d44cfc338ee $publicHash = 'paste public hash here'; // 64 characters, published BEFORE you played $clientSeed = 'paste client seed here'; // your own seed, e.g. 123 $nonce = 0; // bet number for this seed pair, e.g. 6 $maxRoll = 100000; // "maxRoll" from the response $expectedRoll = 0; // "roll" from the response, e.g. 95808 // --------------- nothing to edit below this line --------------- // Check 1: the site published $publicHash before you played. If it equals the hash // of the seed + salt revealed afterwards, the seed cannot have been swapped later. $hashOk = hash_equals($publicHash, hash_hmac('sha256', $serverSeed, $serverSalt)); // Check 2: the roll comes only from the server seed, your seed and the bet number, // so anyone can recompute it and must get exactly the same number. $roll = (hexdec(substr(hash_hmac('sha512', $serverSeed, "$clientSeed-$nonce"), 0, 15)) % $maxRoll) + 1; printf("server seed matches the hash published before the bet: %s\n", $hashOk ? 'YES' : 'NO'); printf("roll recomputed from your data: %d (possible range 1..%d)\n", $roll, $maxRoll); printf("same roll as the site reported (%d): %s\n", $expectedRoll, $roll === $expectedRoll ? 'YES' : 'NO');
Output for 8.2.0 - 8.2.34, 8.3.0 - 8.3.35, 8.4.1 - 8.4.26, 8.5.0 - 8.5.11
server seed matches the hash published before the bet: NO roll recomputed from your data: 51317 (possible range 1..100000) same roll as the site reported (0): NO

preferences:
27.49 ms | 1136 KiB | 6 Q