Importing maFiles from Steam Desktop Authenticator
Your accounts are yours. Import reads the same .maFile format SDA
writes, shows you what it found, and stores nothing until you say so.
Before you start
Do not delete your SDA installation. Keep it until you have confirmed the imported accounts generate the same codes. Importing copies; it does not move. There is no step here that alters your existing files.
1. Find your maFiles
They live in the maFiles folder inside your SDA installation
directory, one .maFile per account, named after the SteamID —
plus a manifest.json.
2. Select them
Choose Import maFiles and select the account files. If your maFiles are
encrypted you also need manifest.json: it holds the salt and
initialisation vector, and without it an encrypted maFile cannot be decrypted at
all. If you select an encrypted file and forget the manifest, the application
looks for one beside the files you picked and adds it for you.
3. Unlock, if they are encrypted
You will be asked for the passphrase you set in SDA — not your Steam password, and not the passphrase for this application's vault. It is used to decrypt the files in memory and is not stored.
4. Review what was found
Nothing has been written yet at this point. The report lists each account it could read and flags anything that matters:
- Accounts already in your vault, so you do not import a duplicate.
-
A maFile with no
identity_secret— it will generate login codes but cannot confirm trades, and it is better to know now. - A maFile with no revocation code, which means detaching that authenticator later will need Steam Support.
- A proxy setting found inside the file, which you can adopt or discard.
- Files that could not be read at all, and why.
Tick what you want. Everything else is discarded when you close the screen.
5. Confirm the codes match
Put the two applications side by side and check that an imported account shows the same five characters as SDA does. Same secret, same clock, same code. That is your proof the import worked before you rely on it.
Leaving again
Export writes an account back out as a standard .maFile, readable
by SDA. There is no lock-in, and that is deliberate: a tool that made your
secrets hard to take elsewhere would be behaving like the thing it is meant to
replace.