Lost your Steam authenticator?
A dead phone, a wiped machine, a deleted folder. This page is the order to try things in, from the option that takes a minute to the one that takes days. Work down it — do not skip to the bottom.
Everything on this page happens on Steam's own site or in Steam's own app. Searching for a tool that promises to recover a Steam authenticator will find you something that steals accounts. There is no such tool and there cannot be one.
1. Is there a copy of the secret anywhere?
More recoverable than people assume. Any of these is a working authenticator:
- A
.maFilein an old SDA folder, or in a backup of one. -
The same folder on a machine you still have — an old laptop, a drive you kept.
Encrypted ones also need
manifest.json. - Steam still signed in on another device, which can often re-add Steam Guard.
If you find one, import it somewhere you control and confirm it produces codes Steam accepts before you rely on it.
2. Do you have the revocation code?
It looks like R12345 and was shown when the authenticator was first
added. With it, you can remove the authenticator yourself from Steam's help
pages, then set a new one up. This is the fast path: minutes, not days.
Removing the authenticator puts a hold on trading and the Market for a period. That is Steam's rule, not something a tool can shorten — anything advertising otherwise is a scam.
3. No revocation code
Then it is Steam Support, through a help request to remove the authenticator. Expect to prove ownership: purchase history, payment details, the original email address, when the account was created. It takes days rather than minutes, and it generally works if the account is genuinely yours.
Nobody else can do this for you. A service offering to recover a Steam account is either lying or planning to sell it.
Making sure this does not happen again
- Write the revocation code on paper. Not in the same place as the maFile, and not only on the machine that holds it.
- Keep an offline copy of the secret somewhere encrypted that is not the computer you use every day.
- Test the backup once. An untested backup is a belief, not a backup.
This is the reasoning behind two decisions in our own application: a recovery file is written the moment an account is enrolled rather than when someone remembers to ask, and it is deliberately kept when an account is removed — because that is exactly the moment people discover they needed it.