Open Desktop Authenticator

Encrypted maFiles: the password, and the manifest

Reviewed by MASTERPANEL LLC 5 min read Sources and testing: Encryption, salt and IV handling checked against SDA's FileEncryptor source; manifest entries and file mapping against SDA's Manifest source Editorial method

You have a .maFile, something is asking for a password, and nothing you type works. Start by checking which password it needs, and whether you kept the matching encryption information with the file.

Short answer

An encrypted maFile wants the passphrase you set in SDA — not your Steam password, and not your email password. It also needs the manifest.json that was sitting beside it, because the salt and initialisation vector live in that file rather than in the maFile.

A lone encrypted .maFile is an incomplete backup unless you also preserved its matching salt and IV elsewhere. Copy the whole maFiles folder.

Which password does an encrypted maFile want?#

The encryption passphrase set inside SDA, on the machine that made the file. Not your Steam password, not your Windows password, not the email password. When SDA's encryption was switched on it asked for a passphrase of its own — that is the one. If somebody else set the machine up, it may be theirs rather than yours.

Why won't my encrypted maFile open on another machine?#

SDA does not keep everything needed for decryption inside the maFile itself. manifest.json, in the same folder, maps each filename to the salt used to derive the encryption key from your passphrase and the initialisation vector used by AES-CBC. The practical rule:

Decryption needs the matching salt and IV as well as the passphrase. SDA stores those values in manifest.json. Copy the whole maFiles folder together, preserving filenames.

76561…maFile ciphertext authenticator data manifest.json salt + IV how to open it + passphrase = readable all three needed Copy only the .maFile and you keep the locked box without the parameters needed to unlock it.
An encrypted SDA maFile needs the correct passphrase and matching salt and IV, normally stored in manifest.json. Copies of those parameters can also work, but the reliable backup is the whole maFiles folder.

This is a common way people lock themselves out while believing they made a backup: the .maFile went to the USB stick, the manifest stayed behind, and the machine was wiped.

If that is where you are, work through these in order before assuming it is lost:

  1. Look for the original folder, not the file

    Old drive, old user profile, an SDA folder in a previous Windows installation, a full-disk image. You need the manifest.json that lived beside this maFile.

  2. Check every other backup you made

    Cloud sync, an old external disk, a zip of the whole SDA directory. A complete backup of the maFiles folder from the same SDA installation should include the matching manifest; a backup containing only the individual .maFile will not.

  3. If the matching encryption data is gone, use account recovery

    Ordinary importers cannot decrypt without the matching salt and IV. They could survive in another backup even if the original manifest is gone. Do not upload the files to a website promising recovery. Move to account recovery instead — that path still works without the file.

Why does it only say the passphrase is wrong?#

SDA derives a key from your passphrase with PBKDF2 and encrypts with AES-256-CBC — a mode with no authentication tag. That matters: an authenticated cipher would at least detect reliably that something was wrong, though not which thing. Without one you get a padding error, or occasionally plausible-looking rubbish, and those look identical whether the real problem is

ODA's importer checks whether the decrypted result parses as a maFile and checks manifest fields. That can catch missing or malformed data, but a generic decryption error alone does not prove which input is wrong. Valid JSON is also not cryptographic proof that a file was never modified.

Other things that look like a passphrase problem#

How do I tell whether a maFile is encrypted at all?#

Open a copy in a text editor. Readable field names like shared_secret mean it is not encrypted and nothing is being asked of you. Base64 text, possibly split across lines, is consistent with SDA encryption but does not by itself prove the file is intact. The full walkthrough is here.

I have the manifest but it still will not open#

Match the entry's filename to the original maFile name, and check that encryption_salt and encryption_iv came from the same backup. The SteamID alone is insufficient: SDA can generate new salt and IV values when it rewrites or re-encrypts an account. Restore a complete matching snapshot rather than mixing files from different dates.

Can I decrypt it without SDA?#

Yes, but not by any tool that merely "supports AES". It has to implement SDA's exact scheme — the same PBKDF2 parameters, a 32-byte key, CBC mode, PKCS#7 padding, and the manifest mapping that tells it which salt and IV belong to which account. Ours does. That specificity is also the reason to be careful which tool you hand it to.

What if I have lost the passphrase completely?#

There is no password-reset service for SDA encryption. Recovery depends on finding the passphrase, another usable copy, or guessing the correct passphrase; a strong unknown passphrase makes guessing impractical. Check your password manager, old records, keyboard layout and remembered variants locally. The Steam account can still have other recovery routes:

  1. Look for an unencrypted copy. SDA's encryption was off by default, so an older backup of the folder may be plain JSON. Open one in a text editor — readable field names mean unencrypted.
  2. A still-working copy of this authenticator. Preserve it and make a fresh protected backup before changing anything. Steam Mobile can show its recovery code; a desktop file may contain one. A recovery code removes an authenticator when used in recovery; it does not add a replacement automatically and removal carries a 15-day restriction.
  3. Neither? The lost-access page covers an available SMS transfer, a saved recovery code, and Steam Support when those options are unavailable.