Open Desktop Authenticator

How to open a Steam .maFile safely

Reviewed by MASTERPANEL LLC 5 min read Sources and testing: File identification and opening branches checked against SDA's published source and maFile layout Editorial method

There is no special program needed to look inside one. A maFile is a small text file, and a text editor opens it — showing either readable fields or, if it was encrypted, a block of base64 you will need the passphrase and manifest to make sense of. The care required is not technical — it is about what you do with the file afterwards.

Never use an online file viewer or converter on a real maFile. Some generic online file viewers ask you to upload the file to read it. Uploading an unencrypted maFile exposes the authenticator secret itself. An encrypted one should not be uploaded either: it is sensitive backup material, and it may become readable if its matching manifest.json and passphrase are exposed later. There is no legitimate reason for a website to see either.

Short answer

Any plain-text editor can display a maFile — Notepad, VS Code, anything. An unencrypted one contains JSON; an encrypted one shows base64 ciphertext. There is nothing to install and nothing to convert. Work on a copy, not the original.

The danger is not opening it. It is where the contents go afterwards: never into a website, a Discord bot, a pastebin, an AI chat, or a support form.

1. Where is the maFiles folder?#

SDA is a portable program, so its maFiles folder sits beside the SDA executable — wherever you extracted it. It has no fixed location inside Steam's installation. Check the folder containing the SDA program or search for *.maFile and manifest.json. Copies can exist in several places; keep track of which backup belongs to the current authenticator.

Enable file-name extensions in File Explorer. A filename ending in .maFile.exe is an executable, not an authenticator data file.

2. Why should I copy it first?#

Close SDA first and copy the whole maFiles folder into a private local folder that is not automatically shared or synced. Include manifest.json so encrypted files remain usable. Inspect a copy without saving changes; accidental edits can corrupt the only surviving backup.

3. What opens a .maFile?#

Anything that reads plain text. What matters more is what you deliberately do not use — and double-clicking counts as not choosing, because Windows will pick something for you.

4. Is mine encrypted or readable?#

Readable field names
shared_secret, identity_secret, account_name and friends. This is an unencrypted maFile, and treat any credentials in it as sensitive even if the file is old. Here is what each field does.
A block of base64 text, possibly split across lines
This is consistent with SDA encryption, but appearance alone does not prove the file is valid. You will need the passphrase and the manifest.json that was beside it — this is the page for that.
Neither, or the file will not open
It may be corrupt, empty, from a different tool or simply the wrong file. File size alone is not a reliable test. Keep the original and look for a matching backup before attempting changes.

Opening a copy in a text editor does not run anything — but the contents are still live secrets. Editors keep recent-file history and documents folders are often synced to cloud storage, so where you put that copy matters. Do not paste the contents into a website, a Discord bot, a pastebin, an AI chat, or a support form — including ours. Pasting an unencrypted maFile hands over its secrets; an encrypted one is still sensitive backup material and should not be uploaded either. If the shared_secret is readable in what you paste, whoever receives it can generate your Steam Guard codes while that secret remains the account's current authenticator — there is no scheduled expiry in the file. The shared_secret on its own does not hand over the password. But a maFile carrying a still-usable session or refresh token may allow account actions immediately, and even without one, the second factor stops being an obstacle. A compromised shared_secret cannot be fixed by changing your password — it takes removing or replacing the authenticator.

5. Is it safe to load it into an authenticator?#

"Opening" a maFile in an authenticator is a much larger act than reading it. You are handing a program the authority to act as your authenticator indefinitely — these secrets do not expire on their own, and stop working only when the authenticator is removed or replaced. To Steam the requests it signs carry the same cryptography yours would.

So the question is not whether the software can read the format. It is whether you are willing to give the people who wrote it that authority. Before loading a maFile into anything, including ODA, check that you can name who publishes it, verify the download is what they published, and read what it does with the secret afterwards. Counterfeit authenticators exist specifically to be handed maFiles, and they look like the real thing.