Dice roller

Type an expression such as 2d6+3, or pick a die below.

Expression

Notation
  • 2d6: two six-sided dice, added up. d20 = 1d20.
  • 2d6+1d4+3, d20-2: several terms, added or subtracted.
  • 4d6kh3: keep the highest 3; 2d20kl1: keep the lowest one.
  • d%: 1 to 100. 4dF: Fudge dice, each −1, 0 or +1.
Custom dice

Transparency

Dice are rolled in your browser, by the scripts listed below. Nothing leaves this page.

Enforced by your browser
This page's Content Security Policy allows a single destination, the site's audience measurement (connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'), so even a bug could not send what you type or draw anywhere. You can read the policy at the top of the page source.
Audience measurement
Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
  • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
    SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
  • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
What is stored
No cookie, and nothing in the address. Rolls and their history are never stored: they disappear when you reload or close the page. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives what you type or draw.
Code that runs here
  • app.js: the dice roller, written for R-no Toolbox. Not minified, no third-party library. 13.1 kB
    SHA-256 af339c31d9a8bf96d446c1debe967ee42df3ae0181e5b4076508ddd20fd05c8f
  • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 6.0 kB
    SHA-256 d811c97abf8ac0e37cf0e6c8842a14fc0253a036912dfa2d7333dbecfaac2acb
  • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
    SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
Where the randomness comes from
Your browser's cryptographic random generator, crypto.getRandomValues (Web Crypto API). Draws that would favour some values are rejected rather than folded with a modulo, so every outcome is equally likely. Each die is drawn on its own: every face has exactly the same chance. When some dice are kept (kh, kl), all of them are rolled first, then the best or worst are kept; on a tie, the first rolled is kept.
Check it yourself
Download a script and compare its fingerprint with the one above:
curl -s https://r-no.fr/random/dice/app.js | shasum -a 256
What a result proves
Nothing, to anyone else. A screenshot or a copied result does not show how many times the draw was repeated before this one, nor whether the page was modified. It is fine for deciding among yourselves; for a draw that others must be able to check (a contest, for instance), a verifiable draw tool is planned.
Limits
At most 100 dice per term, 1,000 faces per die, 10 terms, and 100 custom faces. No exploding dice, rerolls or success counting. The average is only shown when no dice are discarded. The history keeps the last 20 rolls, in this page only.