Official domains
This is the complete list. If an address is not on it, it is not an official publishing address — however similar the name, however convincing the page, and however high it ranks. We do not designate third-party mirrors or forks as official. The MIT licence allows others to redistribute or modify the source; that does not make their builds ours.
Where we publish#
| Address | What it is | Downloads? |
|---|---|---|
| opendesktopauthenticator.com | This site. Documentation and links only — it has never hosted an installer and never will. | No |
| github.com/opendesktopauthenticator/open-desktop-authenticator | The project repository: source, public build workflow and releases. Use its Releases page for direct downloads. | Yes |
| apps.microsoft.com — Open Desktop Authenticator | The Microsoft Store listing for product ID 9NMM2XJ6HZ1D, published by MASTERPANEL LLC. Microsoft signs the Store AppX package. | Yes |
| masterspanel.com | The company that publishes this. Names the product and links back here, which is the other half of the check. | No |
The two official application-download channels are the Microsoft Store listing and the repository's GitHub releases page. The download page explains which to take, and how to check what you got.
What this page is for#
The attack this project exists to answer is a search result that looks official. A counterfeit Steam Desktop Authenticator can display working codes while copying account secrets. Similar names and search rankings are not proof of origin — what a counterfeit build actually does covers the pattern.
A list like this only helps if it is the same list everywhere, which is why the release process compares the GitHub organisation name against this page rather than against somebody’s memory. If this page, the repository and a download disagree, stop and investigate. Do not choose whichever source looks most reassuring. Follow the signature and provenance checks; a website can be compromised too.
If you find something claiming to be us#
Report it through the reporting form — suspected clone sites are one of the things it is for, and a report costs you a minute and may save somebody their inventory. Do not send us vulnerability details there; the security page has the private channels for that.
GitHub and Microsoft can serve the actual file through their own delivery domains after you follow these official links. A delivery redirect alone is not proof of a fake; a lookalike page offering its own build needs independent verification. If you ran an untrusted authenticator and gave it Steam credentials or maFiles, treat those secrets as potentially compromised and work through the recovery steps rather than hoping. Open Desktop Authenticator cannot undo that, and neither can we.