ToolsEdits
    Mesh Ludo

    How Mesh Ludo works

    Under the hood of Mesh Ludo: deterministic game engine, authoritative host, crypto dice, SHA-256 state hashes, AES-GCM encrypted WebRTC DataChannels and QR signaling.

    Host ↔ players

    The room creator is the authoritative host. Each player has one WebRTC connection to the host: Host A → B, Host A → C, Host A → D. There is no game server.

    QR signaling

    WebRTC needs an offer and an answer to connect. Instead of a signaling server, the offer and answer are compressed into QR codes that phones scan from each other.

    Actions, not screens

    Players send action requests (roll dice, move token). The host validates the turn, sequence number and rules, applies the action with the shared deterministic engine, and broadcasts the accepted action. Every phone replays it with the same engine.

    Anti-cheat dice

    A player can only ask to roll. The host draws the value with crypto.getRandomValues() — never Math.random() — so nobody can claim a six.

    State hashes and recovery

    After every action each phone computes a SHA-256 hash of the canonical game state. A mismatch triggers STATE_SYNC from the host. A disconnected player keeps their slot and resyncs when they scan a rejoin invite.

    Encryption

    Each connection uses fresh ECDH P-256 keys exchanged inside the QR codes, deriving an AES-256-GCM session key. Private keys never leave the device.

    If the host leaves

    Players can only talk to the host, so the game pauses. The next host is chosen deterministically (lowest player ID). That phone continues from its last verified state and the others rejoin by scanning its new invite.