Skip to main content

Provably Fair

How sealed odds work and how to verify any pull

T
Written by Theodore at Lastpack

Provably fair means you don't have to take our word for it: you can check every pull yourself.

​

Before you open a pack, we lock in the odds and a secret key, and publish a fingerprint of that key so it can't be changed afterwards. When you open, your device adds its own random input that we can't see in advance. Your card is decided by combining the two. Once the key is revealed, anyone can re-run the math and land on the same card.

​

What happens when you open a pack

  1. We seal the envelope. Before you open, we commit to a secret answer key (its fingerprint is on your fairness page) and to the pack's odds: every rarity tier's exact share and a fingerprint of every card in it. This is the "sealed manifest".
    ​

  2. Your device checks the seal, then signs. The app or browser checks the sealed odds really match their fingerprint, and only then creates its own random signature. We cannot see it beforehand, so we cannot pick an envelope to suit it. Your device keeps a receipt of what it saw.
    ​

  3. Two rolls decide the card. The first roll picks a rarity tier using the sealed tier odds. The second picks the card inside that tier. If a card is out of stock the draw rolls again, and every roll is recorded.
    ​

  4. After the pull we open the envelope. The answer key is revealed, and anyone can re-run both rolls.

​

What you can check (Verify on any of your pulls)

  • The answer key matches the fingerprint published before your pull.
    ​

  • The odds used are exactly the sealed odds, and they match the receipt your device kept before the pull.
    ​

  • Each roll replays, lands inside the sealed odds, and proves its card is part of the sealed card list, without that list being published.
    ​

  • Each card's rarity tier follows the published rule for this pack's price.
    ​

  • The last roll is the card you got.

​

Under the checks, Walk through the math shows every step with your pull's real numbers, and Run it yourself gives a short Python or Node script with your pull's values already filled in. Paste it into a terminal: it redoes every check without our website and prints ALL CHECKS PASS.

​

If your device did not keep a receipt (another device, cleared browser data), the check says so and compares against the envelope we recorded: compare its fingerprint with your fairness page.

​

Older pulls (classic check)

Pulls opened before 6 October 2026, and some since (like Grail opens and pulls from older app versions), use the classic check. Your pull's Verify screen shows which check it uses. Every pull, old or new, can still be verified.

​

How it works. Before you open, we seal a secret key and publish its fingerprint on your fairness page. Your device adds its own random input, and your pull number is added too. Mixing these with the secret gives a number within the pack's total odds; each card takes up a share of that range equal to its odds, and wherever the number lands is your card. After the pull the key is revealed, so anyone can re-run it.

​

What you can check. The revealed key matches the fingerprint published before your pull, the odds shown are the ones for the exact pack you opened as they stood at the time, and the math lands on the card you got. Run it yourself on the Verify screen gives ready-to-run Python or Node code with your pull filled in.

Did this answer your question?