Dice Roller

Roll d4 to d100 or custom dice with counts and modifiers, plus a coin flip — crypto rejection sampling keeps every 1–N roll provably fair.

Rolls happen locally with the Web Crypto API — no server ever sees your dice, and the history vanishes on reload.

Die type
Roll history (last 10)

    No rolls yet — the last ten will appear here in dice notation.

    Coin flip
    —Heads: 0Tails: 0

    How It Works

    Pick a die, a number of dice (1–20) and optionally a modifier, then roll. Each face is drawn independently from the Web Crypto API's entropy pool and mapped to 1–sides with rejection sampling, so the distribution is exactly uniform — and every roll, coin flip included, is a separate secure draw.

    Dice notation NdM±K
    Tabletop shorthand: N dice, each with M faces (s), plus a flat modifier K applied to the sum. So "2d6+1" is two six-sided dice plus one, "1d20+5" a single d20 attack roll, and "1d100" the percentile die used for open checks. The history column echoes this exact notation — for example "3d6: 4,5,2 = 11" — so you can re-read a session from the list alone.
    Why rejection sampling, not modulo
    A common shortcut takes a 32-bit random number modulo 6, but 2³² is not a multiple of 6 — the leftover values slightly favour the low faces (1 and 2 get one extra hit per cycle, about 0.00000003% bias for d6, larger for odd die sizes). This roller instead computes the largest multiple of the die size that fits in 32 bits and re-draws anything above it, discarding the biased region entirely. The result is provably uniform for d4 through custom d200.
    Digital dice vs physical ones
    Real dice have manufacturing bias, uneven wear and toss mechanics — a casino die is truer than a novelty one, and no physical die is perfectly fair either. What digital rolls guarantee is perfect independence: a d20 has no memory, so "three lows in a row means a high is due" is the gambler's fallacy, not a strategy. Streaks that feel suspicious are exactly what true randomness looks like.

    Frequently Asked Questions

    Are the results random enough for a real game?

    Yes — more than enough. Each roll is drawn from your operating system's entropy pool via crypto.getRandomValues, and the mapping to die faces uses rejection sampling, so every face has exactly the same probability. No seed is stored, no session pattern exists to exploit; the next roll is independent of all previous ones.

    Can I roll 1000 dice at once?

    No, the count is capped at 20 per roll — and that is deliberate. A thousand die faces would be an unreadable wall of numbers, which defeats the purpose of a results grid, and any real tabletop need (damage, healing, loot) fits comfortably in a few rolls. Roll repeatedly and add the totals, or use the copy button.

    How does the d100 work without two dice?

    A physical d100 is impractical, so shops sell percentile dice: one d10 reading 1–9/0 as tens and one reading 0–9. Our d100 chip draws 1–100 directly with rejection sampling, which is exactly equivalent in distribution. If you want to see the classic pair, choose d10 twice and read them as tens and units yourself.

    Does the modifier apply to each die or the total?

    To the total, like every tabletop convention: 3d6+2 means the three faces are summed first and then 2 is added. The formula line, the result grid and the history entries all follow that reading, so “4d6+5” in history means the four dice plus 5 over their sum.

    Is anything uploaded to a server?

    No. Rolls are generated locally with the Web Crypto API, the history lives only in the page and vanishes on reload, and the coin counters are plain numbers in memory. The roller works with the internet switched off.