How Steam trade confirmations work on desktop
Steam can ask for a separate confirmation when you send items or list them for sale. Desktop authenticators can handle those requests using the authenticator's secrets and a signed-in Steam session. Here is how to review them, what to check when nothing appears, and what access you give the software.
A desktop tool approves confirmations by holding your
identity_secret and signing each request with it, exactly as
the phone does. It needs a live Steam session as well as the
secret — the secret alone cannot sign in.
That is why an authenticator file is worth protecting like the account itself, and why nothing here should ever be pasted into a website.
What actually approves a Steam trade confirmation?#
A confirmation approves a pending action; it does not necessarily complete a trade immediately. For example, an outgoing offer can need confirmation before it is sent, and then still needs the other person's acceptance. Valve's trade-offer guide describes confirmation through the mobile app, or by email without it. See also Trade and Market Confirmations. Follow the status Steam shows for the actual transaction.
When Steam requires a mobile confirmation, three things have to come together before that request is valid:
- The identity secret from your authenticator. It is used as the HMAC key: the request sends a derived signature, not the raw secret.
- An authenticated Steam session — a live login for the account, not just the secret.
- A signature derived from the time and action tag. The message being signed is the current Steam-corrected time followed by a short tag naming the action — one tag for fetching the list, a different one for allowing, another for cancelling. The action request also includes the selected confirmation's ID and nonce. Those values are separate from the time-and-tag signature; it is not a signature over every trade detail.
Valve documents the confirmation feature but not this wire format. The tag behaviour above matches the long-standing open implementation in DoctorMcKay's node-steamcommunity, a protocol reference for this project. Our own confirmation implementation follows that request format.
Do not treat this mechanism as a guarantee that a captured request cannot be reused. Steam controls timestamp acceptance and replay checks, and list keys are reusable in the public library. Protect the session and the device as well as the secrets. A working authenticator can remove standard holds after 7 days, but it does not remove account restrictions. CS2 trades use Trade Protection instead of trade holds.
How can a desktop program approve them?#
By holding the identity secret and signing in as you. It imports the secret from a maFile, or receives it when the authenticator is first created, then produces the same signatures the phone does. These unofficial clients implement Steam's confirmation protocol. Valid cryptography and a valid session are required, but do not guarantee acceptance: Steam can also reject requests or restrict an account.
That is the honest framing of "approve confirmations on PC": not a convenience feature, but moving trade authority from a device you carry to a machine that is often left running.
It is worth being exact about what somebody gains by stealing that file, because both the panic and the shrug are wrong:
- The identity secret cannot sign in to Steam. On its own it signs confirmations and nothing else.
- The shared secret is not your password. It supplies the second factor, so it closes half the gap rather than all of it.
- A usable session or refresh token changes that. A file carrying one may let a thief obtain account access without re-entering the password, depending on its scope, validity and Steam's checks.
- The secrets have no scheduled expiry in the file. Changing the password does not rotate them. A copied secret remains a risk while Steam recognises it as the account's current authenticator.
Why would anyone want confirmations on a PC?#
- A larger review surface. A desktop can make a long list easier to inspect alongside the original offers and listings. Batch controls vary by app and version; batching alone is not exclusive to a desktop.
- Several accounts at once. The Steam app does hold multiple accounts, but it shows one at a time; a desktop screen can show them side by side.
- No usable phone. A broken handset does not have to stop trading. There is more on that here.
Is it safe to let software approve my trades?#
Not "can it approve confirmations" — they all can, or they would not be offering. Ask what it will approve without asking you, and what happens to the secret while the machine is unattended.
Open Desktop Authenticator's answers, so you can compare them against anything else: automatic approval is off unless you switch it on, per account, and switching on automatic trades — the setting that can move items out of an account with nobody watching — requires typing a confirmation phrase rather than clicking a toggle. Locking the vault stops new approval requests; it cannot recall a request already sent to Steam. The vault locks after the configured idle period and on suspend. Secrets are encrypted in the vault, but are available to the application while unlocked; malware on the PC can undermine that protection.
A tool that cannot answer those two questions clearly is asking you to hand over trade authority on trust alone.
How to review confirmations in ODA#
- Unlock the vault and choose the right account.
The account needs its current shared and identity secrets, obtained by import, enrolment or transfer.
- Open Confirmations and sign in if prompted.
A login code can work offline while confirmations still require a new Steam session. Use Refresh to fetch the current list.
- Match each entry to the action you intended.
Check the account, items, recipient or offer, and any displayed price against Steam. If the summary is insufficient, inspect the original offer or listing in Steam before pressing Approve.
- Approve only entries you recognise.
Approve all affects every ordinary entry shown, not a selection. Security-sensitive confirmations must be handled individually. Deny an unexpected request and review your Steam account security.
No confirmation appears, or approval fails#
- Check Steam's transaction status. It may not be awaiting confirmation, may already be processed, or may belong to another account. An empty list does not prove a sale or trade succeeded.
- Sign-in requested: renew the session. Re-importing the secret is not a substitute for signing in.
- Connection or proxy error: restore the connection and refresh. Treat an incomplete-list warning as incomplete information.
- Timeout after approval: check Steam's trade or Market history before retrying; the action may already have succeeded.