Report a problem
Bugs, documentation errors, and suspected clone sites. You do not need an account to report something. You receive a private report link: save the whole link, including its key, to follow up.
Never include a secret in a report#
Do not paste a .maFile, a shared secret, an identity secret, a
revocation code, a password or an API key into this form or into any message
to us. Nobody here will ever ask for one. A report that needs to describe a
secret can describe its shape without its value.
For a vulnerability, use the private security
channels below rather than this general report form.
Reports containing what looks like a shared secret, an identity secret, a revocation code or a private key are refused and not stored. That is deliberate: the check is in the code, not just in the sentence above.
What to include#
- What you did, what you expected, and what happened instead.
- The application version and your operating system.
- Whether it happens every time or occasionally.
- For a suspected clone site: the URL, and where you encountered it.
What happens to a report#
-
You get a link, holding a reference in the form
ODA-7K2M-B9QWand the key that opens it. Keep the whole link — the reference on its own will not open the report, and there is no account to recover it from. - Our triage policy: anything describing lost access, lost items, or a secret behaving unexpectedly is looked at ahead of everything else.
- Our aim is to answer each report, including a reason if we cannot make the requested change. General reports have no guaranteed response time. Steam account recovery and item disputes must go through Steam Support.
Reporting a clone site#
Fake authenticator downloads are the reason this project exists, and a report takes a minute. Send the URL and where you found it — a search result, an advertisement, a video description, a Discord message. We collect them, warn about the patterns on the scam clones page, and report the worst to the registrars and hosts involved.
You do not need to be sure. A site that turns out to be legitimate costs us five minutes; one that turns out not to be may save somebody their inventory.
Security reports
Do not open a public issue for a security problem. There are two published private routes:
- GitHub private vulnerability reporting — preferred. It keeps the discussion in a private advisory rather than a public issue and requires a GitHub account. If it is unavailable, use the email route.
- By email, if you would rather not use GitHub. The address is published in our security.txt, which is the standard place to look for security contact information. The same address is also in the repository's SECURITY.md.
What we commit to, in writing: acknowledgement within 72 hours, an initial assessment within 7 days, and a fix or a dated plan within 30 days for a confirmed high or critical. Those are the commitments of a single maintainer, and if one is going to be missed we will say so before the deadline rather than after. The full policy is in SECURITY.md.
Please give us a reasonable window to release a fix before publishing details. We will not use that window to argue you into silence, and we will credit you unless you would rather we did not.