"alea iacta est" — The die is cast.
A verifiable random selection tool that uses drand's distributed randomness beacon to make choices. Because deciding what to have for lunch deserves the same cryptographic rigor as a national lottery.
Sometimes you need to pick between pizza and sushi. You could flip a coin like a normal person, or you could query a decentralized network of nodes running threshold BLS signatures on a chained randomness scheme to produce publicly verifiable, unbiasable entropy — and use that to pick your lunch.
This is that second thing.
Every selection is tied to a specific drand round, meaning anyone can independently verify the result wasn't tampered with. No trust required. Just math.
Download — a single binary that runs on Linux, macOS, Windows, FreeBSD, OpenBSD and NetBSD, on x86-64 and ARM64:
curl -L https://github.com/hermo/alea/releases/latest/download/alea.ape -o alea
chmod +x alea
sudo mv alea /usr/local/bin/Homebrew (macOS and Linux):
brew install hermo/tap/aleaBuild from source:
make
sudo make installRequires libcurl and OpenSSL libcrypto headers:
- macOS:
brew install openssl(libcurl is already there) - Debian/Ubuntu:
apt install libcurl4-openssl-dev libssl-dev
Build the portable APE binary yourself:
curl -L https://cosmo.zip/pub/cosmocc/cosmocc-4.0.2.zip -o /tmp/cosmocc.zip
unzip /tmp/cosmocc.zip -d ~/cosmocc
make ape COSMOCC=~/cosmocc/bin/cosmoccProduces alea.ape — runs everywhere without modification.
Or build it in a container instead, with no local cosmocc install required
(uses podman by default; pass CONTAINER_ENGINE=docker to use Docker
instead):
make ape-containeralea pizza sushi tacos ramen🎲 tacos
round: 6100001
time: 2026-05-10T16:38:00Z
verify:
alea --round 6100001 pizza sushi tacos ramen
alea --round 6100001 pizza sushi tacos ramenSame round + same options = same result. Always. Anyone can check.
Use --count N to pick N unique winners in ranked order. No duplicates —
each winner is removed from the pool before the next is drawn:
alea --count 3 Alice Bob Charlie Dave EveMaximum 8 winners per draw (8 × 32-bit chunks from the 256-bit drand value).
alea --file restaurants.txt
alea --file menu.csv --delimiter ","
alea --count 3 --file participants.txtUse - to read from stdin:
git log --format="%an" | sort -u | alea --file -When using --file, the output includes a SHA-256 hash of the input so
you can prove the options weren't modified after the fact.
Pre-calculate the drand round for a specific time. Useful for raffles where you want to announce the parameters in advance:
alea --at '2026-07-22T12:00:00+03:00' --count 3 --file participants.txtShare the round number, pick count, and file hash beforehand. When the time comes, run the command and everyone can verify the result.
winner=$(alea --quiet pizza sushi tacos)alea --json pizza sushi tacos
alea --tsv pizza sushi tacos | grep '^winner' | cut -f2Don't have alea installed? Each shell mode gives you a self-contained
verification command that only needs curl:
alea --sh pizza sushi tacos # bash/zsh
alea --fish pizza sushi tacos # fish
alea --ps pizza sushi tacos # PowerShell
alea --all pizza sushi tacos # all of the abovePass --quiet to get only the raw oneliner, ready to pipe:
alea --sh --quiet pizza sushi tacos | bash- Fetch a randomness round from drand's public HTTP API
- Take the first 8 hex characters of the randomness (32 bits)
- Compute
index = value % option_count - That's your winner
For multiple winners, each pick uses the next 8 hex characters as its seed, and the chosen option is removed from the pool before the next draw.
The drand network produces a new random value every 30 seconds. Each round is publicly verifiable and cannot be predicted or biased by any single party.
--round <N> Use a specific drand round (for verification)
--at <TIMESTAMP> Calculate round for a future time (ISO 8601)
-f, --file <path> Read options from a file
-d, --delimiter <str> Split file by delimiter (default: newline)
-n, --count <N> Pick N unique winners (default: 1, max: 8)
-q, --quiet Print only the result, no headers or labels
--all Show all verification methods
--json Machine-readable JSON output
--tsv Tab-separated key/value output
--sh Output bash/zsh verification oneliner
--fish Output fish verification oneliner
--ps Output PowerShell verification oneliner
-V, --version Show version
-h, --help Show this help
No dependencies to rot. libcurl's ABI has been stable since 2006. This binary will build unchanged in 30 years.
The portable download is built with Cosmopolitan libc and bundles BearSSL for TLS — no runtime dependencies of any kind. One binary, every platform.
GPL-2.0