public randomness beacon: one commit-reveal round per unix minute; trust-minimised, not trustless round: every unix minute t has a round; the beacon value is r_t seed: s_t = HMAC-SHA256(HKDF-SHA256(server_secret, info "cx-rand-v1"), uint64be(t)); kept secret until minute t commit: c_t = sha256(s_t) is published one round ahead as c_next, pinning s_t before it is revealed mix: mix_t = sha256(h0||h1||...) over the distinct contribution hashes received in minute t-1, sorted ascending by raw bytes (sha256 of the empty string when none) value: r_t = sha256(s_t || mix_t) statement: rand1 t= r= s= mix= n= c_next= k=1, signed Ed25519 (see /.well-known/cx-key, /verify) drbg: keystream = HMAC-SHA256(r_t, purpose||0x00||salt||uint32be(ctr)) for ctr=0,1,...; purpose in {pick,u,coin}; read as a byte stream pick: /pick?n=&of=&salt= : partial Fisher-Yates over [0,of): for i in 0..n-1 swap i with i+uniform(of-i); returns the first n indices uniform: uniform(bound) draws 4-byte big-endian words, rejects words >= floor(2^32/bound)*bound, returns word mod bound; /u?max= is uniform(max) coin: /coin?salt= is heads when uniform(2)==1 else tails contribute: POST /v1/rand/mix {"h":"<64 hex>"} adds entropy to the next round (token or X-PoW, 10/min per network) anchor: each completed UTC day's rounds hash sha256(r_t0||r_t1||...) is stamped into the notary (GET /ts) trust: the operator cannot bias a round after its commitment is out, but could grind s_t before committing: trust-minimised, not trustless next: GET /rand latest | GET /verify statements | GET /.well-known/cx-key key