Flip a Coin: Heads or Tails
Tap the coin: heads or tails, decided by your browser's cryptographic randomness.
Runs entirely in your browser
Loading the tool…
Tap the coin to flip it
Each flip is decided by your browser's cryptographic random source, the one used for passwords: heads and tails are exactly as likely, and nothing about the last flip changes the next.
Tap the coin and it spins and lands on heads or tails. Settle who goes first, who pays, which film to watch, or anything else two ways round. Press Space on a keyboard to flip again; flip 10 or 100 coins at once to see how chance evens out, with the count of each side and the longest run in a row.
Each result is decided by your browser's cryptographic random source, the same one it uses to make passwords, before the coin starts to move: the spin only shows where it landed. Heads and tails are exactly as likely, and no flip remembers the one before, so five heads in a row tell you nothing about the sixth.
How to use it
- Tap the coin, or press Flip.
- Read heads or tails as it lands.
- Flip 10 or 100 at once to see the tally.
Questions
Is this coin flip really fair?
Yes. Each flip takes one random bit from your browser's cryptographic source, the generator used for passwords and encryption keys, so heads and tails each come up exactly half the time in the long run. A real coin is slightly less fair: it lands on the side it started on a little more than half the time.
What are the odds of getting heads five times in a row?
One in 32, about 3%. Each flip is still 50/50, whatever came before: the coin has no memory. Flip 100 and a run of six or seven of one side is normal.
Is anything sent anywhere?
No. The flips happen in this tab and the page keeps working offline.
Your data stays on your device
Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.
This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.