Guide
How to Verify Provably Fair Pack Openings (Step by Step)
A step-by-step guide to checking a "provably fair" rip yourself, using the server seed, client seed and nonce, and what to do if it doesn't match.
Published
“Provably fair” is one of the most common badges on pack opening sites and one of the least checked. The idea is simple: the platform commits to its randomness before you rip, so it can’t quietly change the outcome after seeing what you bet. This guide shows you how to confirm that yourself in about five minutes.
The three ingredients
Every provably-fair system we’ve tested uses the same three inputs:
- Server seed. A random value the platform generates. Before you rip, you’re shown only its hash (usually SHA-256). That hash is the commitment.
- Client seed. A value you control. Change it to anything you like, so the platform can’t pre-pick a server seed that works against a seed it chose for you.
- Nonce. A counter that goes up by one with every rip under the same seed pair, so each rip gets a different result.
The roll is typically HMAC_SHA256(serverSeed, clientSeed + ":" + nonce). That output is converted into a number, which is mapped onto the pack’s odds table.
Step 1: Record the commitment before you rip
Open the fairness or seed settings and copy the hashed server seed. Set your own client seed: a random word works. Write down both, then rip. Note the nonce and exactly what you pulled.
Step 2: Rotate the seed pair
Rotate or “reveal” the seed. The platform should now show the unhashed server seed you were using. If it won’t reveal the old seed, stop here: the rip can’t be verified.
Step 3: Check the hash
Hash the revealed server seed with SHA-256, using any offline tool or a few lines of code, and compare it with the commitment you saved in step 1. They must match exactly. If they don’t, the platform changed its seed after committing.
// Node.js
import { createHash } from 'node:crypto';
createHash('sha256').update(revealedServerSeed).digest('hex') === savedHash;
Step 4: Recompute the roll
Using the platform’s published algorithm, recompute the roll for your nonce and map it onto the pack’s odds table. The item it lands on should be the item you received.
import { createHmac } from 'node:crypto';
const hex = createHmac('sha256', revealedServerSeed).update(`${clientSeed}:${nonce}`).digest('hex');
// Many sites take the first 8 hex chars → 0..1 float → odds-table bucket
const roll = parseInt(hex.slice(0, 8), 16) / 0x100000000;
Algorithms differ in the details, so always use the exact method from the platform’s own fairness page.
Which pack opening sites claim to be provably fair?
These platforms in our directory claim a provably-fair system. A claim isn’t verification; use the steps above to check a result yourself. Each listing notes how well the system is documented.
- Boxed.gg (Pokémon, MTG, One Piece, Sports)
- Cases.gg (Pokémon, One Piece, MTG, Yu-Gi-Oh!, Sports, Luxury, Sneakers)
- ClutchPacks (Pokémon, One Piece, Sports)
- Collector Crypt (Pokémon, One Piece, Sports, Luxury)
- HypeDrop (Pokémon, One Piece, MTG, Lorcana, Sports, Luxury, Sneakers)
- Jemlit (Pokémon, One Piece, Yu-Gi-Oh!, Luxury, Sneakers)
- Krush.gg (Pokémon)
- LastPack (Pokémon, One Piece)
- LuxDrop (Pokémon, Luxury, Sneakers)
- OpenThatPack (Pokémon, MTG, One Piece)
- PackDraw (Pokémon, Sports, Luxury, Sneakers)
- Packs.com (Pokémon, MTG, One Piece)
- Phygitals (Pokémon, One Piece, Yu-Gi-Oh!, Sports)
- PICKEM Ripping Packs (Pokémon, Sports)
- Pullbox (MTG, Pokémon, Lorcana, One Piece)
- RillaBox (Luxury, Sneakers)
- Rip.fun (Pokémon, One Piece)
- ripz.gg (Pokémon, One Piece, Lorcana)
- Trove (Sports, Pokémon, One Piece)
Red flags
- The platform won’t reveal previous server seeds.
- No published algorithm, or one too vague to reproduce.
- You can’t set your own client seed.
- The odds table the roll maps onto isn’t published, or changes without notice.
Any one of these means “provably fair” is just a label. We record every platform’s result in our rankings and explain the test on our methodology page.