MetaWin Originals verifier
Paste a revealed MetaWin server seed, client seed and nonce. This page recomputes the selected Original with MetaWin’s Tequity fairness math — HMAC-SHA256 of clientSeed:nonce:cursor, then uint32 words with low-bit rejection. After the page loads, nothing is sent to a server.
What this page implements
HMAC + uint32 stream
MetaWin Originals (Tequity RGS) key HMAC-SHA256 with the revealed server seed and sign clientSeed:nonce:cursor. Each 32-byte digest is eight big-endian uint32 words. That is not Stake’s 4-byte float or BitStarz’s 8-byte float.
Low-bit rejection
A draw of 0 … limit−1 keeps the low ceil(log2(limit)) bits of a word and throws the word away when that value is ≥ limit. Dice uses limit 10001 (14 bits). Mines steps from 25 down to 2.
Not on this page
Prime Dice, Navigator, Slide, Cases, Packs, Pump, Pepe’s River Run, Coin Flip, Darts, Dragon Tower, Snakes and Bars stay off until their extra tables can be labelled without guessing. Those titles are MetaWin-exclusive skins on top of extra config.
Not the unified calculator
Stake, Shuffle and BC.Game stay on /verify. This URL is MetaWin-only so you can check the numbers before any tab is added there.
Does any of my data leave this page?
No. After the page loads, hashing runs through the browser Web Crypto API. Seeds are not posted anywhere — including not to MetaWin or Tequity.
Where do I copy the seeds?
Open a MetaWin Original, then Fairness. Client seed and nonce are on the Seeds tab. Rotate the pair to reveal the old server seed, then paste that revealed value here. The hashed server seed is optional and only used to confirm the commitment.
Why is Crash different from the live lobby graph?
MetaWin Crash / Rekt and Navigator are shared multiplayer rounds. This tool still uses the per-bet Tequity seed math (0.99 × 2³² / (h+1)). Use it on a revealed seed pair from Fairness, not on the public round hash alone.