Documentation
How the application works, page by page. If something here is wrong or missing, tell us — documentation faults are treated as faults.
Getting started
- Importing from SDA
- Bringing existing maFile accounts across, including encrypted ones.
- Creating a vault
- On first run you choose a passphrase. It protects every secret the application holds and it cannot be recovered — there is no reset, because a reset would be a back door. Write it down before you continue past that screen.
- Adding an authenticator
- For an account that does not have Steam Guard on a device yet. You sign in, Steam emails a code, and the application attaches an authenticator and shows your revocation code. Write that code down. The application will keep warning you until you confirm you have.
Everyday use
- Codes
- Each account shows its current code and how much of the thirty-second window is left. Copy places it on the clipboard and clears it again shortly after, so it does not sit there for the next thing that reads your clipboard.
- Confirmations
- Trades and market listings awaiting approval, with what Steam said about each: what is being traded, with whom, and when it was raised. Approve or cancel individually.
- Automatic confirmation
- Optional, per account, and limited to market listings and trades. Anything else — most importantly an account recovery request — is held back and reported in Activity rather than approved. This limit is in the code, not in a setting.
- Activity
- What automatic confirmation did while you were not watching, and anything it refused. The place to look if something feels wrong.
Keeping access
- Revocation codes
- The code that detaches an authenticator from Steam. Revealing one requires your passphrase again even when the vault is unlocked. Store it somewhere that is not this computer.
- Backups
- The vault keeps the previous version of itself beside the current one. If the vault file is damaged, the unlock screen offers to load that backup. Restoring returns the vault to how it was when the backup was written: accounts added since will be gone, and accounts removed since will come back.
- Recovery files
- Written automatically when an account is enrolled, and deliberately kept when an account is removed — recovering from that removal is the reason they exist. They are encrypted with the vault passphrase in force at the time they were written.
Troubleshooting
- Steam rejects the codes
- Almost always the clock. Codes are generated from the current time, so a machine more than about half a minute out produces codes Steam will not accept. The application checks its clock against Steam's and warns you when it could not.
- An imported account cannot confirm trades
- Its maFile had no identity secret. Login codes work; confirmations cannot. The account has to be re-enrolled to fix it.
- Sign-in wants approval on another device
- Steam is asking for confirmation on the device that already holds the authenticator. If that device is gone, the revocation code is the way through.