Game rules
Two players, one coin. Pick a side, another player takes the other, and the winner takes the pot. The house never plays: it takes a fee from the pot and nothing else. These are the rules enforced by the JustPoker game engine; where the table and this page could ever disagree, the engine's published tests are the reference.
Coinflip is a game between two players. One creates a flip: a stake and a side, heads or tails. Another joins it with the same stake and takes the other side. The coin decides, and the player whose side comes up is paid the pot — both stakes — less a 5% fee.
The house is never your opponent: it does not create or join flips and has nothing riding on the result. It takes the fee from every pot, whoever wins, so heads and tails, creator and joiner all get the same deal: on average every stake returns 95% of itself.
Each flip is decided by a server seed committed when the flip is created and a public randomness beacon round that is fixed only when someone joins, so nobody, us included, can know the result before both stakes are in. You can check any finished flip on our Provably Fair page.
Choose heads or tails and a stake from $1 to $1,000. The stake is taken from your balance at once and held for the flip, which appears in the lobby with your username, your side, the stake, its server seed hash and the time left before it expires.
Any other player can join for exactly your stake and takes the other side. You cannot join your own flip. The join fixes the beacon round that will decide the flip, and from then on neither player can back out.
The drand beacon publishes that round 3–6 seconds after the join. The coin spins until it does, with the round number on screen the whole time.
The flip's server seed and the beacon round decide the face. The player whose side comes up is paid the pot, both stakes, less the 5% fee. The server seed is revealed so that anyone can check the result.
Until someone joins you can cancel your flip for a full refund. A flip that nobody joins within 30 minutes is cancelled and refunded automatically.
A finished flip stays in the lobby for 10 seconds, then moves to the results list (the last 30) and to both players' hand history.
Set the stake with the chips, ½ and 2×, choose a side with the Heads / Tails toggle, and press Create flip. Join and Cancel are on each flip in the lobby.
Stakes are whole cents. The joiner always stakes exactly what the creator did, so both halves of the pot are equal.
Chips of $1, $5, $10, $25, $100, $500, or type an amount.
The lobby holds up to 200 open flips at once, and one internet connection up to 12 across all the accounts that use it.
An unjoined flip is then refunded in full.
Of the pot, taken from the winner's payout.
Every stake is checked before it is taken
The pot is both stakes. When the flip is decided the house takes 5% of the pot and the winner is paid the rest. Nothing else is taken: the loser's stake is the winner's prize.
The fee is rounded down to the cent, so it is never more than 5%; the fraction of a cent goes to the winner. Two stakes of $12.34 make a pot of $24.68; 5% of it is $1.234, so the fee is $1.23 and the winner is paid $23.45.
Each player wins half of all flips, so on average a stake returns 95% of itself: you put in a stake, and half the time you are paid twice that stake less the fee. That holds for heads and tails, for the creator and the joiner, and for every stake. The fee is recorded with each flip when it is created, so a change to it applies only to new flips.
These are averages: any one flip either doubles your stake less the fee or loses it. Please read our responsible gambling information and set limits before you play.
| Stakes | Pot | Fee (5%) | Winner is paid |
|---|---|---|---|
| $1.00 each | $2.00 | $0.10 | $1.90 |
| $10.00 each | $20.00 | $1.00 | $19.00 |
| $12.34 each | $24.68 | $1.23 | $23.45 |
| $1,000.00 each | $2,000.00 | $100.00 | $1,900.00 |
Fee = 5% of the pot, rounded down to the cent. The winner is paid the pot less the fee.
A stake is refunded in full whenever a flip ends without a result. Once someone has joined, the flip produces one, unless its beacon round never arrives (below).
A flip's result needs two inputs that nobody holds together before the join: a server seed we commit to when the flip is created, and a beacon round that does not exist until seconds after the join.
coinflip:number:round:randomness — the flip's number, the round and that round's randomness.:0, keyed with the server seed. Its first 6 bytes (12 hex digits) are a 48-bit number; with two outcomes every such number is accepted, and its remainder after dividing by 2 is the face: 0 is heads, 1 is tails. The creator wins when the face is their side.Open any flip in your hand history and choose Verify, or read the full scheme on the Provably Fair page.
The first published test vector, on a real drand quicknet round. Every step can be checked with any SHA-256 and HMAC tool.
3f9a1c8e6b2d4f7a9c0e1b3d5f7a9c2e4b6d8f0a1c3e5b7d9f1a3c5e7b9d0f2a0fdef169ef108e2826cdb4d895a10ea3021edde33fb7dcc417bb007f97b1f857b22aad4794f7451896f7a371aa46106fd84d919f3f569acd5b2fddf1d1440af3coinflip:1:1000000:b22aad4794f7451896f7a371aa46106fd84d919f3f569acd5b2fddf1d1440af370b9780c8d9ce45d53afb0b741c1cc468bc77e743fef965bca7e5aec4b2beae470b9780c8d9c, are 123,941,885,349,276: below 248 = 281,474,976,710,656, so accepted.Any correct implementation must reproduce these faces exactly. Flip 1 uses a real drand round; the others use the development beacon.
| Flip | Server seed | Round | Creator | Face | Winner |
|---|---|---|---|---|---|
| 1 | 3f9a1c8e…9d0f2a | 1,000,000drand | Heads | Heads | Creator |
| 2 | b0d47831…e6cbad | 32,689,921dev | Tails | Heads | Joiner |
| 123 | 22fc8b59…3dab54 | 32,690,000dev | Heads | Heads | Creator |
| 4,096 | 9e708aa6…86fd00 | 33,000,000dev | Tails | Heads | Joiner |
| 1,000,000 | c8720d06…4523f5 | 40,000,000dev | Heads | Tails | Joiner |
The verifier's Coinflip mode checks the commitment, the beacon round's signature and timing, and recomputes the face and the payout. Paste the values above to try it.
Node.js and its own crypto module, nothing of ours.
const { createHash, createHmac } = require("node:crypto");
const serverSeed = "3f9a1c8e6b2d4f7a9c0e1b3d5f7a9c2e4b6d8f0a1c3e5b7d9f1a3c5e7b9d0f2a";
const randomness = "b22aad4794f7451896f7a371aa46106fd84d919f3f569acd5b2fddf1d1440af3"; // drand quicknet round 1000000
const message = `coinflip:1:1000000:${randomness}`;
console.log(createHash("sha256").update(serverSeed).digest("hex")); // the commitment
const block = createHmac("sha256", serverSeed).update(message + ":0").digest();
const u = BigInt("0x" + block.subarray(0, 6).toString("hex"));
console.log(u % 2n === 0n ? "heads" : "tails"); // headsThe randomness that decides a game comes from drand, a public randomness beacon run by the League of Entropy, a group of independent universities, companies and foundations. Its quicknet chain publishes a new value every 3 seconds. Each value is a threshold BLS signature produced jointly by the network's nodes: it is unique, nobody can compute it before enough nodes have signed, and anyone can check it against the chain's public key.
A game's beacon round is fixed at the moment someone joins the flip: our server takes the latest round published at that moment and adds 2. That round is published 3–6 seconds later. Until then it does not exist anywhere, so nobody — no player and not us — can know the result while anyone can still take part. The round number is shown the moment entries close, before its value exists.
Our server fetches the round from drand's public relays and checks its signature against the quicknet public key before using it; the relays only carry it. A round's randomness is the SHA-256 of its signature, and you can look up any round yourself, for example round 1,000,000, the one the worked example below uses.
The beacon round is counted from our server's clock, so our server also checks that clock against drand: while the games are in use it regularly fetches drand's newest round and checks its signature like any other. If drand has already published a round that, by our clock, is still more than a second away, our clock is behind real time, and joins and deposits stay closed until it is right again.
What remains to trust is that enough of the beacon's independent nodes do not conspire with us. Test servers use a predictable development beacon instead, always labelled “Development beacon (predictable; local testing only)”; it is never used on the live site.
You cannot join your own flip, and you may hold one account only. Two accounts of one person playing each other gain nothing — on average the pair just pays the fee — and multi-accounting is prohibited by our Terms.
No. In Coinflip you play other players. We never create, join or deposit, and we take nothing but the fee from the pot, whoever wins.
And even if an account were ours — or someone inside our company who knows every server seed — it could not know the result: the beacon round that decides it is fixed only when entries close and published seconds later. Knowing the server seed is useless without it. That is why our staff need no rule against playing.
Because a bot would be the house playing against you. It would play with our money, so Coinflip would stop being a game between players: the house would become your opponent, with a different return and a reason to want you to lose. We keep the house out of it entirely.
If nobody takes your flip, nothing is lost: cancel it whenever you like, or it is refunded in full after 30 minutes.
Coinflip has a chat room of its own. Signed-in players can post messages of up to 200 characters; messages are deleted after 30 days.
Chat and the lobby are public
Stakes from $1.00 to $1,000.00, a 5% fee on the pot. Your balance, limits and reality checks apply at Coinflip exactly as they do everywhere on JustPoker.
18+ only. Gambling can be harmful; play within limits you set in advance. Help is available through the organisations listed on our responsible gambling page.