Documentation
The product manual and the Steam Guard reference library, grouped by the task you are trying to complete. If something here is wrong or missing, tell us — documentation faults are treated as faults.
Getting started#
- Importing from SDA
- Bringing existing maFile accounts across, including encrypted ones.
- Creating a vault
- On first run you choose a passphrase. It protects every secret the vault stores, and ODA cannot reset it. Use a strong, unique passphrase and keep a secure record separately from your vault backup.
- Adding an authenticator
- Choose Add authenticator for an account without a mobile authenticator. Sign in and complete Steam's sign-in challenge. Activation then uses a separate code delivered by Steam; follow the screen's email or phone-number hint. Record the revocation code outside this computer and confirm the backup when asked. If an authenticator already exists, use Move authenticator instead of removing it first. If an operation's outcome is uncertain, follow its recovery instructions before attempting it again.
Everyday use#
- Codes
- Each account shows its current code and how much of the thirty-second window is left. Copy places it on the clipboard; ODA attempts to clear its own entry after 30 seconds by default, configurable in Settings. This does not clear clipboard history, cloud sync or copies already read by other apps.
- Confirmations
- Trades and market listings awaiting approval, with what Steam said about each: what is being traded, with whom, and when it was raised. Approve or cancel individually. Verify the recipient and items yourself before approving; a familiar account name is not proof that the request is yours.
- Automatic confirmation
- Optional, per account, and limited to market listings and trades. Anything else — most importantly an account recovery request — is held back and reported in Activity rather than approved. This limit is in the code, not in a setting. Automatic approval can still authorise an unwanted trade or sale. Leave it off if you need to review each request.
- Activity
- What automatic confirmation did while you were not watching, and anything it refused. The place to look if something feels wrong.
Keeping access#
- Revocation codes
- The code that detaches an authenticator from Steam. Revealing one requires your passphrase again even when the vault is unlocked. Store it somewhere that is not this computer.
- Backups
- The vault keeps the previous version of itself beside the current one. If the vault file is damaged, the unlock screen offers to load that backup. Restoring returns local records to how they were when the backup was written. It does not undo a Steam-side transfer or deactivation. The adjacent backup is also lost if the disk fails or the whole data folder is deleted: keep a separate encrypted copy and retain the passphrase that opens it.
- Recovery files
- Written automatically for imported, enrolled and transferred authenticators, and kept when a vault entry is removed. Address any backup warning shown by the application. A file needs the vault passphrase in force when it was written; changing today's passphrase does not unlock an older copy with the new one. A file cannot revive secrets Steam has replaced or deactivated.
Troubleshooting#
- Steam rejects the codes
- Check the clock first. Codes depend on time, and clock drift can make them invalid. ODA attempts to obtain Steam's time offset and shows time-sync failures; do not infer Steam's acceptance tolerance from the 30-second code period. The full walkthrough, including the fixes on Windows and phone, is here.
- An imported account cannot confirm trades
-
Its maFile may have an
identity_secretwhose value is present but unusable; current imports flag this with a warning. Login codes may still work when theshared_secretis usable, but confirmations cannot. First check sign-in, connectivity and the account's configured proxy. If the secret is unusable, re-import a known-good copy; if none exists, use Steam's recovery or transfer routes before considering removal and re-enrollment. - Sign-in wants approval on another device
- Steam is asking for confirmation on the device that already holds the authenticator. Use its current code if the sign-in screen offers that route. If the device is gone, Steam's recovery flow may use your recovery code, linked phone number or proof of ownership.
maFile reference#
- What a maFile contains
- The secrets, recovery code and session material inside the file, and why each matters.
- Opening a maFile safely
- How to inspect a copy locally without uploading live authenticator material.
- Encrypted maFiles and manifest.json
- Why an SDA passphrase and the matching manifest are both required.
- Importing from SDA
- The product workflow for selecting, checking, importing and later exporting accounts.
Move or recover an authenticator#
- Lost access completely
- The recovery routes in the order worth trying, all on Steam's own systems.
- Find or use the recovery code
- What the R-code does and where to record it before a device is lost.
- Move to a new phone
- Valve's phone-to-phone transfer and the restriction that follows it.
- Move from a phone to a PC
- What a Steam transfer changes and why the old copy must be treated as replaced.
- Trade holds and restrictions
- Each trigger and duration, separated so different restrictions are not confused.
- Codes that Steam refuses
- Start with time synchronisation, then work through the less common causes.
Choose and use an authenticator#
- Steam Guard without a smartphone
- The difference between needing a mobile device and keeping a phone number for recovery.
- Trade confirmations on desktop
- How confirmation signing works and which secret and session it requires.
- Mobile app or desktop
- The security, recovery and convenience trade-offs between device types.
- Authenticator options compared
- Valve's app, SDA and this project, including the case against choosing ours.
- Product FAQ
- Short answers about cost, platform support, privacy, imports and losing a passphrase.