Open Desktop Authenticator

Steam authenticator alternatives to SDA, compared

Three realistic options, and the honest case for each — including the one where the answer is not us. We would rather you chose correctly than chose ours.

Steam Mobile — the default, and the right answer for most people

Valve's own app. It is maintained by the people who run the service, it cannot be counterfeited on a search results page, and losing your phone is a recoverable problem rather than a catastrophe.

Choose it if: you are not confirming listings in bulk, you are not sure what a maFile is, or you would rather not be responsible for storing a secret. This is not a consolation prize — it is the safest option available and most people should stop here.

Against it: confirming thirty market listings means thirty taps. Codes have to be read and retyped. The secret lives on a device that can break.

Steam Desktop Authenticator — the incumbent

The tool most traders have used for years, and the reason this category exists. It works, it is widely understood, and there is a large body of community knowledge about it.

Choose it if: you already use it, it works for you, and you got it from its own repository.

Against it: its name is what the counterfeit sites rank for, so every new user has to run a gauntlet to get a genuine copy. The clone problem is real and specific, and it is a problem of the ecosystem around the tool rather than of the tool itself.

Open Desktop Authenticator — this project

An independent implementation built around one idea: you should not have to trust us. Public source, reproducible builds, published checksums, no self-updating, and a documented security model that includes what it cannot protect you from.

Choose it if: you want a desktop authenticator and you want to be able to check what it does — or have somebody else check.

Against it, plainly: it is new. It has no public release yet, no years of community scrutiny behind it, and no track record. Those are real disadvantages and no amount of open source substitutes for them. If that matters more to you than auditability, one of the options above is the better choice today.

The comparison that actually matters

Not the feature list — the failure modes. Ask of any authenticator, including ours:

  1. Can I verify that what I ran is what was published?
  2. Where does the secret live, and who else can read it?
  3. What happens when I lose the device? Answer that before you need it.
  4. Can it update itself? If yes, whoever controls the update controls the secret.
  5. What can it approve without asking me?

A tool that answers those five well is a tool worth using, whoever wrote it.

Related

Last reviewed .