Open Desktop Authenticator

Who builds this

Open Desktop Authenticator is published by MASTERPANEL LLC. On most products this page would be filler. On something that holds your Steam Guard secrets it is evidence, so here it is plainly.

Why this page exists

The counterfeit authenticators described on the scam clones page have one thing in common: nobody is behind them. No company, no name, no other work to point at, nothing that could be embarrassed by the software turning out to steal accounts. That anonymity is not incidental — it is the business model.

We are not asking you to trust us because we are named. We are pointing out that a name is one of the few things you can check about a piece of software before you run it, alongside the checksum and the signature and the source itself. Use all of them.

What else we build

Why a Steam trading company wrote an authenticator

Because we watch this go wrong. Running a skins platform and an account marketplace means dealing, routinely, with people whose accounts have just been emptied — and a large share of them were emptied the same way: they searched for a desktop authenticator, downloaded the first plausible result, and handed a modified build their .maFile.

It also happened to one of us, before any of this existed. That account is written up in full, because it is the most honest answer to why we bothered.

That is a solvable problem. Not by telling people to be careful, which has never worked, but by making a version of the tool where the dangerous parts are visible, the build is reproducible, and the site tells you how to check what you downloaded. Whether they use ours or somebody else's matters less than whether they verify it.

The obvious question

Two of the projects above are commercial and Steam-adjacent. It is fair to ask whether a company that profits from Steam trading should be trusted with a Steam authenticator, and the honest answer is that you should not have to decide that on vibes.

This is precisely why the application is built the way it is. It has no server of ours to talk to, no account system, and no telemetry — there is nowhere for a secret to go even if we wanted one. It cannot update itself, so a future version cannot be pushed to you quietly. And every line of it is public, so the claim in this paragraph is checkable rather than merely stated. That is a better answer than a promise.

Getting in touch

Bugs, documentation errors and suspected clone sites go through the reporting form. Security reports go to the same place and are handled privately — see the security page for what we ask and what we commit to.

Last reviewed .