Open Desktop Authenticator

How Steam trade confirmations work on desktop

Reviewed by MASTERPANEL LLC 5 min read Sources and testing: Trade-offer flow checked against Valve's offer guidance; request tags and session requirements against node-steamcommunity's public implementation Editorial method

Steam can ask for a separate confirmation when you send items or list them for sale. Desktop authenticators can handle those requests using the authenticator's secrets and a signed-in Steam session. Here is how to review them, what to check when nothing appears, and what access you give the software.

Short answer

A desktop tool approves confirmations by holding your identity_secret and signing each request with it, exactly as the phone does. It needs a live Steam session as well as the secret — the secret alone cannot sign in.

That is why an authenticator file is worth protecting like the account itself, and why nothing here should ever be pasted into a website.

What actually approves a Steam trade confirmation?#

A confirmation approves a pending action; it does not necessarily complete a trade immediately. For example, an outgoing offer can need confirmation before it is sent, and then still needs the other person's acceptance. Valve's trade-offer guide describes confirmation through the mobile app, or by email without it. See also Trade and Market Confirmations. Follow the status Steam shows for the actual transaction.

When Steam requires a mobile confirmation, three things have to come together before that request is valid:

  1. The identity secret from your authenticator. It is used as the HMAC key: the request sends a derived signature, not the raw secret.
  2. An authenticated Steam session — a live login for the account, not just the secret.
  3. A signature derived from the time and action tag. The message being signed is the current Steam-corrected time followed by a short tag naming the action — one tag for fetching the list, a different one for allowing, another for cancelling. The action request also includes the selected confirmation's ID and nonce. Those values are separate from the time-and-tag signature; it is not a signature over every trade detail.

Valve documents the confirmation feature but not this wire format. The tag behaviour above matches the long-standing open implementation in DoctorMcKay's node-steamcommunity, a protocol reference for this project. Our own confirmation implementation follows that request format.

Do not treat this mechanism as a guarantee that a captured request cannot be reused. Steam controls timestamp acceptance and replay checks, and list keys are reusable in the public library. Protect the session and the device as well as the secrets. A working authenticator can remove standard holds after 7 days, but it does not remove account restrictions. CS2 trades use Trade Protection instead of trade holds.

How can a desktop program approve them?#

By holding the identity secret and signing in as you. It imports the secret from a maFile, or receives it when the authenticator is first created, then produces the same signatures the phone does. These unofficial clients implement Steam's confirmation protocol. Valid cryptography and a valid session are required, but do not guarantee acceptance: Steam can also reject requests or restrict an account.

That is the honest framing of "approve confirmations on PC": not a convenience feature, but moving trade authority from a device you carry to a machine that is often left running.

It is worth being exact about what somebody gains by stealing that file, because both the panic and the shrug are wrong:

Why would anyone want confirmations on a PC?#

Is it safe to let software approve my trades?#

Not "can it approve confirmations" — they all can, or they would not be offering. Ask what it will approve without asking you, and what happens to the secret while the machine is unattended.

Open Desktop Authenticator's answers, so you can compare them against anything else: automatic approval is off unless you switch it on, per account, and switching on automatic trades — the setting that can move items out of an account with nobody watching — requires typing a confirmation phrase rather than clicking a toggle. Locking the vault stops new approval requests; it cannot recall a request already sent to Steam. The vault locks after the configured idle period and on suspend. Secrets are encrypted in the vault, but are available to the application while unlocked; malware on the PC can undermine that protection.

A tool that cannot answer those two questions clearly is asking you to hand over trade authority on trust alone.

How to review confirmations in ODA#

  1. Unlock the vault and choose the right account.

    The account needs its current shared and identity secrets, obtained by import, enrolment or transfer.

  2. Open Confirmations and sign in if prompted.

    A login code can work offline while confirmations still require a new Steam session. Use Refresh to fetch the current list.

  3. Match each entry to the action you intended.

    Check the account, items, recipient or offer, and any displayed price against Steam. If the summary is insufficient, inspect the original offer or listing in Steam before pressing Approve.

  4. Approve only entries you recognise.

    Approve all affects every ordinary entry shown, not a selection. Security-sensitive confirmations must be handled individually. Deny an unexpected request and review your Steam account security.

No confirmation appears, or approval fails#