Open Desktop Authenticator

The work this is built on

There is a reason an independent Steam authenticator can exist at all, and it is not us. Valve publishes no specification for Steam Guard. The algorithm behind the five-character code, the signing behind a mobile confirmation, the shape of the login exchange — none of it is documented by the people who built it. It is public because someone worked it out and gave it away.

DoctorMcKay has maintained the open-source Steam libraries that most of this ecosystem runs on, for years, under the MIT licence — which is to say he did the hard part and then asked for nothing.

Donate to him →

What we actually use

Stated precisely, because vague gratitude is worth less than an accurate account of the debt:

Why this matters more than a credits line

Everything on this site argues the same point: that you should not have to trust a stranger with the keys to your Steam account, because you can check the thing instead. That argument only works if there is something to check — an alternative that is open, inspectable and not the only game in town.

Without that reverse-engineering published openly, there is no ecosystem. There is Valve's app, and there is whatever an anonymous download page hands you, and nothing in between. The clone sites we spend this whole domain warning people about exist precisely because the demand is real and the legitimate options are few. Every open, checkable option makes that gap smaller, and all of them rest on the same foundation.

He is not paid for this. There is no company behind those repositories. The libraries are MIT-licensed, which means anyone — including us, including people selling things — can take the work and owe nothing back. That is generous to the point of being a bad deal for him, and it is the reason the deal exists for everyone else.

Donate to him directly

All three go to him. Nothing routes through us, and we take nothing — the moment anyone sits between a donor and a maintainer this stops being credit and starts being collection.

In his own words: “If my work helped you or saved you time, please consider donating. Donations of any size are greatly appreciated.” His page is at dev.doctormckay.com/donate, and his repositories are at github.com/DoctorMcKay.

To be completely clear about what this page is

Open Desktop Authenticator is an independent project. It is not affiliated with, endorsed by, or connected to DoctorMcKay, who has no involvement in it and has not reviewed it. We link to him because we depend on his work, not because he vouches for ours. Verify the addresses on his own donation page before sending anything — including the links above, and including because we said so.

If you would rather support this project

Consider him first; the dependency runs one way. If you still want to, the donations page explains what it pays for.

Last reviewed .