Open Desktop Authenticator

Documentation

The product manual and the Steam Guard reference library, grouped by the task you are trying to complete. If something here is wrong or missing, tell us — documentation faults are treated as faults.

Getting started#

Importing from SDA
Bringing existing maFile accounts across, including encrypted ones.
Creating a vault
On first run you choose a passphrase. It protects every secret the vault stores, and ODA cannot reset it. Use a strong, unique passphrase and keep a secure record separately from your vault backup.
Adding an authenticator
Choose Add authenticator for an account without a mobile authenticator. Sign in and complete Steam's sign-in challenge. Activation then uses a separate code delivered by Steam; follow the screen's email or phone-number hint. Record the revocation code outside this computer and confirm the backup when asked. If an authenticator already exists, use Move authenticator instead of removing it first. If an operation's outcome is uncertain, follow its recovery instructions before attempting it again.

Everyday use#

Codes
Each account shows its current code and how much of the thirty-second window is left. Copy places it on the clipboard; ODA attempts to clear its own entry after 30 seconds by default, configurable in Settings. This does not clear clipboard history, cloud sync or copies already read by other apps.
Confirmations
Trades and market listings awaiting approval, with what Steam said about each: what is being traded, with whom, and when it was raised. Approve or cancel individually. Verify the recipient and items yourself before approving; a familiar account name is not proof that the request is yours.
Automatic confirmation
Optional, per account, and limited to market listings and trades. Anything else — most importantly an account recovery request — is held back and reported in Activity rather than approved. This limit is in the code, not in a setting. Automatic approval can still authorise an unwanted trade or sale. Leave it off if you need to review each request.
Activity
What automatic confirmation did while you were not watching, and anything it refused. The place to look if something feels wrong.

Keeping access#

Revocation codes
The code that detaches an authenticator from Steam. Revealing one requires your passphrase again even when the vault is unlocked. Store it somewhere that is not this computer.
Backups
The vault keeps the previous version of itself beside the current one. If the vault file is damaged, the unlock screen offers to load that backup. Restoring returns local records to how they were when the backup was written. It does not undo a Steam-side transfer or deactivation. The adjacent backup is also lost if the disk fails or the whole data folder is deleted: keep a separate encrypted copy and retain the passphrase that opens it.
Recovery files
Written automatically for imported, enrolled and transferred authenticators, and kept when a vault entry is removed. Address any backup warning shown by the application. A file needs the vault passphrase in force when it was written; changing today's passphrase does not unlock an older copy with the new one. A file cannot revive secrets Steam has replaced or deactivated.

Troubleshooting#

Steam rejects the codes
Check the clock first. Codes depend on time, and clock drift can make them invalid. ODA attempts to obtain Steam's time offset and shows time-sync failures; do not infer Steam's acceptance tolerance from the 30-second code period. The full walkthrough, including the fixes on Windows and phone, is here.
An imported account cannot confirm trades
Its maFile may have an identity_secret whose value is present but unusable; current imports flag this with a warning. Login codes may still work when the shared_secret is usable, but confirmations cannot. First check sign-in, connectivity and the account's configured proxy. If the secret is unusable, re-import a known-good copy; if none exists, use Steam's recovery or transfer routes before considering removal and re-enrollment.
Sign-in wants approval on another device
Steam is asking for confirmation on the device that already holds the authenticator. Use its current code if the sign-in screen offers that route. If the device is gone, Steam's recovery flow may use your recovery code, linked phone number or proof of ownership.

maFile reference#

What a maFile contains
The secrets, recovery code and session material inside the file, and why each matters.
Opening a maFile safely
How to inspect a copy locally without uploading live authenticator material.
Encrypted maFiles and manifest.json
Why an SDA passphrase and the matching manifest are both required.
Importing from SDA
The product workflow for selecting, checking, importing and later exporting accounts.

Move or recover an authenticator#

Lost access completely
The recovery routes in the order worth trying, all on Steam's own systems.
Find or use the recovery code
What the R-code does and where to record it before a device is lost.
Move to a new phone
Valve's phone-to-phone transfer and the restriction that follows it.
Move from a phone to a PC
What a Steam transfer changes and why the old copy must be treated as replaced.
Trade holds and restrictions
Each trigger and duration, separated so different restrictions are not confused.
Codes that Steam refuses
Start with time synchronisation, then work through the less common causes.

Choose and use an authenticator#

Steam Guard without a smartphone
The difference between needing a mobile device and keeping a phone number for recovery.
Trade confirmations on desktop
How confirmation signing works and which secret and session it requires.
Mobile app or desktop
The security, recovery and convenience trade-offs between device types.
Authenticator options compared
Valve's app, SDA and this project, including the case against choosing ours.
Product FAQ
Short answers about cost, platform support, privacy, imports and losing a passphrase.

Published and reviewed by MASTERPANEL LLC. Last checked . Editorial method.