Encrypted maFiles: the password, and the manifest
You have a .maFile, something is asking for a password, and
nothing you type works. Start by checking which password it needs, and whether
you kept the matching encryption information with the file.
An encrypted maFile wants the passphrase you set in SDA —
not your Steam password, and not your email password. It also needs the
manifest.json that was sitting beside it, because the salt and
initialisation vector live in that file rather than in the maFile.
A lone encrypted .maFile is an incomplete backup unless you
also preserved its matching salt and IV elsewhere.
Copy the whole maFiles folder.
Which password does an encrypted maFile want?#
The encryption passphrase set inside SDA, on the machine that made the file. Not your Steam password, not your Windows password, not the email password. When SDA's encryption was switched on it asked for a passphrase of its own — that is the one. If somebody else set the machine up, it may be theirs rather than yours.
Why won't my encrypted maFile open on another machine?#
SDA does not keep everything needed for decryption inside the maFile itself.
manifest.json, in the same folder, maps each filename to
the salt used to derive the encryption key from your passphrase and the
initialisation vector used by AES-CBC. The practical rule:
Decryption needs the matching salt and IV as well as the
passphrase. SDA stores those values in manifest.json.
Copy the whole maFiles folder together, preserving filenames.
manifest.json. Copies of those parameters can also
work, but the reliable backup is the whole maFiles folder.
This is a common way people lock themselves out
while believing they made a backup: the .maFile went to
the USB stick, the manifest stayed behind, and the machine was wiped.
If that is where you are, work through these in order before assuming it is lost:
-
Look for the original folder, not the file
Old drive, old user profile, an SDA folder in a previous Windows installation, a full-disk image. You need the
manifest.jsonthat lived beside this maFile. -
Check every other backup you made
Cloud sync, an old external disk, a zip of the whole SDA directory. A complete backup of the
maFilesfolder from the same SDA installation should include the matching manifest; a backup containing only the individual.maFilewill not. -
If the matching encryption data is gone, use account recovery
Ordinary importers cannot decrypt without the matching salt and IV. They could survive in another backup even if the original manifest is gone. Do not upload the files to a website promising recovery. Move to account recovery instead — that path still works without the file.
Why does it only say the passphrase is wrong?#
SDA derives a key from your passphrase with PBKDF2 and encrypts with AES-256-CBC — a mode with no authentication tag. That matters: an authenticated cipher would at least detect reliably that something was wrong, though not which thing. Without one you get a padding error, or occasionally plausible-looking rubbish, and those look identical whether the real problem is
- a wrong passphrase,
- the wrong salt or IV — usually a mismatched
manifest.json, - or a corrupted file.
ODA's importer checks whether the decrypted result parses as a maFile and checks manifest fields. That can catch missing or malformed data, but a generic decryption error alone does not prove which input is wrong. Valid JSON is also not cryptographic proof that a file was never modified.
Other things that look like a passphrase problem#
How do I tell whether a maFile is encrypted at all?#
Open a copy in a text editor. Readable field names like
shared_secret mean it is not encrypted and nothing is being asked
of you. Base64 text, possibly split across lines, is consistent with SDA
encryption but does not by itself prove the file is intact.
The full walkthrough is here.
I have the manifest but it still will not open#
Match the entry's filename to the original maFile name, and
check that encryption_salt and encryption_iv came
from the same backup. The SteamID alone is insufficient: SDA can generate
new salt and IV values when it rewrites or re-encrypts an account. Restore
a complete matching snapshot rather than mixing files from different dates.
Can I decrypt it without SDA?#
Yes, but not by any tool that merely "supports AES". It has to implement SDA's exact scheme — the same PBKDF2 parameters, a 32-byte key, CBC mode, PKCS#7 padding, and the manifest mapping that tells it which salt and IV belong to which account. Ours does. That specificity is also the reason to be careful which tool you hand it to.
What if I have lost the passphrase completely?#
There is no password-reset service for SDA encryption. Recovery depends on finding the passphrase, another usable copy, or guessing the correct passphrase; a strong unknown passphrase makes guessing impractical. Check your password manager, old records, keyboard layout and remembered variants locally. The Steam account can still have other recovery routes:
- Look for an unencrypted copy. SDA's encryption was off by default, so an older backup of the folder may be plain JSON. Open one in a text editor — readable field names mean unencrypted.
- A still-working copy of this authenticator. Preserve it and make a fresh protected backup before changing anything. Steam Mobile can show its recovery code; a desktop file may contain one. A recovery code removes an authenticator when used in recovery; it does not add a replacement automatically and removal carries a 15-day restriction.
- Neither? The lost-access page covers an available SMS transfer, a saved recovery code, and Steam Support when those options are unavailable.