How to open a Steam .maFile safely
There is no special program needed to look inside one. A maFile is a small text file, and a text editor opens it — showing either readable fields or, if it was encrypted, a block of base64 you will need the passphrase and manifest to make sense of. The care required is not technical — it is about what you do with the file afterwards.
Never use an online file viewer or converter on a real
maFile. Some generic online file viewers ask you to upload the file
to read it. Uploading an unencrypted maFile exposes the authenticator secret
itself. An encrypted one should not be uploaded either: it is sensitive
backup material, and it may become readable if its matching
manifest.json and passphrase are exposed later. There is no
legitimate reason for a website to see either.
Any plain-text editor can display a maFile — Notepad, VS Code, anything. An unencrypted one contains JSON; an encrypted one shows base64 ciphertext. There is nothing to install and nothing to convert. Work on a copy, not the original.
The danger is not opening it. It is where the contents go afterwards: never into a website, a Discord bot, a pastebin, an AI chat, or a support form.
1. Where is the maFiles folder?#
SDA is a portable program, so its maFiles folder sits
beside the SDA executable — wherever you extracted it.
It has no fixed location inside Steam's installation. Check the folder
containing the SDA program or search for *.maFile and
manifest.json. Copies can exist in several places; keep track
of which backup belongs to the current authenticator.
Enable file-name extensions in File Explorer. A filename ending in
.maFile.exe is an executable, not an authenticator data file.
2. Why should I copy it first?#
Close SDA first and copy the whole maFiles folder into a
private local folder that is not automatically shared or synced. Include
manifest.json so encrypted files remain usable. Inspect a copy
without saving changes; accidental edits can corrupt the only surviving backup.
3. What opens a .maFile?#
Anything that reads plain text. What matters more is what you deliberately do not use — and double-clicking counts as not choosing, because Windows will pick something for you.
- A trusted local text editor. Use Open with and pick it yourself. An unencrypted maFile shows JSON — curly braces and quoted field names; an encrypted SDA file contains base64 ciphertext. Avoid cloud editors or extensions that send document contents to remote services.
- Not an online JSON viewer, formatter or "maFile decoder". Never upload either type. Pasting an unencrypted maFile into a web page exposes its secrets; uploading an encrypted one exposes sensitive backup material that may become readable if its matching manifest and passphrase are later obtained — whatever the page promises about not storing anything.
- Not an AI chat, a Discord bot or a pastebin. An unencrypted file exposes live secrets immediately; an encrypted one is still sensitive backup material. You cannot rely on retrieving or deleting every copy after it has been shared.
- No converter is needed just to inspect it. A maFile is already text. Decryption is a separate operation requiring the right passphrase and matching metadata.
4. Is mine encrypted or readable?#
- Readable field names
-
shared_secret,identity_secret,account_nameand friends. This is an unencrypted maFile, and treat any credentials in it as sensitive even if the file is old. Here is what each field does. - A block of base64 text, possibly split across lines
-
This is consistent with SDA encryption, but appearance alone does not
prove the file is valid. You will need the passphrase and the
manifest.jsonthat was beside it — this is the page for that. - Neither, or the file will not open
- It may be corrupt, empty, from a different tool or simply the wrong file. File size alone is not a reliable test. Keep the original and look for a matching backup before attempting changes.
Opening a copy in a text editor does not run anything — but the
contents are still live secrets. Editors keep recent-file history
and documents folders are often synced to cloud storage, so where you put
that copy matters. Do not paste the
contents into a website, a Discord bot, a pastebin, an AI chat, or a support
form — including ours. Pasting an unencrypted maFile
hands over its secrets; an encrypted one is still sensitive backup material
and should not be uploaded either. If the
shared_secret is readable in what you paste, whoever receives
it can generate your Steam Guard codes while that secret remains the account's
current authenticator — there is no scheduled expiry in the file.
The shared_secret on its own does not hand over the password.
But a maFile carrying a still-usable session or refresh token may allow
account actions immediately, and even without one, the second factor stops
being an obstacle. A compromised shared_secret cannot be fixed
by changing your password — it takes removing or replacing the
authenticator.
5. Is it safe to load it into an authenticator?#
"Opening" a maFile in an authenticator is a much larger act than reading it. You are handing a program the authority to act as your authenticator indefinitely — these secrets do not expire on their own, and stop working only when the authenticator is removed or replaced. To Steam the requests it signs carry the same cryptography yours would.
So the question is not whether the software can read the format. It is whether you are willing to give the people who wrote it that authority. Before loading a maFile into anything, including ODA, check that you can name who publishes it, verify the download is what they published, and read what it does with the secret afterwards. Counterfeit authenticators exist specifically to be handed maFiles, and they look like the real thing.