Randomness other
contracts can trust
The dice game is one consumer of this. It is a general-purpose commit-reveal oracle: permissionless to build on, permissionless to provide for, and every reveal is checked by keccak256 on-chain before it is delivered.
Try it without writing anything
One transaction, straight to the oracle — no game, no stake, no consumer contract. You get the 32-byte word, its sequence number, and the reveal that proves it.
Because the sender is an ordinary account rather than a contract, the delivery
callback is a no-op and the word is read back from the Revealed event —
identical bytes, just collected differently.
How it works
Neither the provider nor the requester can choose the outcome. Both are locked in before either sees anything.
Provider pre-commits
The provider registers the head of a hash chain on-chain before your request exists. Every future reveal is already fixed — it just isn't public yet.
You add entropy
Your request carries your own 32-byte contribution. The word is keccak256(reveal, yours, provider, seq, you) — the provider can't grind it, and neither can you.
Verified delivery
The reveal is checked on-chain by walking keccak256 back to the commitment, then delivered to your entropyCallback. Unrevealed? Anyone can trigger your refund.
Ways in
Four, depending on what you're building.
Solidity consumer
Inherit IDicedConsumer, override entropyCallback, call requestV2. About 30 lines — the dice game is itself just a consumer.
Already on Pyth Entropy
Change one address. requestV2, getFeeV2, getProviderInfoV2, getRequestV2, refundRequest and the callback selector all match.
Agents, over HTTP
No wallet, no gas, no Solidity. Sign one $0.05 USDG permit and POST — the reply carries the word plus the sequence number and reveal transaction.
Run a provider
Registration is permissionless. Commit a hash chain, set your own fee, keep your own fees. Consumers choose whom to request from, so no single operator can stall it.
Addresses
Read the code you're trusting before you send it anything.
The oracle contracts are source-verified on Blockscout. The testnet oracle runs the same source as mainnet with its own keeper, so you can exercise the whole request-and-reveal path before spending real ETH. The dice game contract is not verified.
Honest about trust
Commit-reveal has one residual assumption: a provider can't change an outcome, but it could withhold one. Your recourse is an automatic, permissionless refund — and because provider registration is open, a consumer can route around one entirely. The same operator runs the dice game and a provider, which is worth knowing rather than glossing over.