Open Desktop Authenticator

Report a problem

Bugs, documentation errors, and suspected clone sites. You do not need an account to report something. You receive a private report link: save the whole link, including its key, to follow up.

Never include a secret in a report#

Do not paste a .maFile, a shared secret, an identity secret, a revocation code, a password or an API key into this form or into any message to us. Nobody here will ever ask for one. A report that needs to describe a secret can describe its shape without its value. For a vulnerability, use the private security channels below rather than this general report form.

No account is created either way. Save your full private report link to check back; leaving an address means we can ask a follow-up question, which is often the difference between a fixed bug and a closed one.

Reports containing what looks like a shared secret, an identity secret, a revocation code or a private key are refused and not stored. That is deliberate: the check is in the code, not just in the sentence above.

What to include#

What happens to a report#

  1. You get a link, holding a reference in the form ODA-7K2M-B9QW and the key that opens it. Keep the whole link — the reference on its own will not open the report, and there is no account to recover it from.
  2. Our triage policy: anything describing lost access, lost items, or a secret behaving unexpectedly is looked at ahead of everything else.
  3. Our aim is to answer each report, including a reason if we cannot make the requested change. General reports have no guaranteed response time. Steam account recovery and item disputes must go through Steam Support.

Reporting a clone site#

Fake authenticator downloads are the reason this project exists, and a report takes a minute. Send the URL and where you found it — a search result, an advertisement, a video description, a Discord message. We collect them, warn about the patterns on the scam clones page, and report the worst to the registrars and hosts involved.

You do not need to be sure. A site that turns out to be legitimate costs us five minutes; one that turns out not to be may save somebody their inventory.

Security reports

Do not open a public issue for a security problem. There are two published private routes:

What we commit to, in writing: acknowledgement within 72 hours, an initial assessment within 7 days, and a fix or a dated plan within 30 days for a confirmed high or critical. Those are the commitments of a single maintainer, and if one is going to be missed we will say so before the deadline rather than after. The full policy is in SECURITY.md.

Please give us a reasonable window to release a fix before publishing details. We will not use that window to argue you into silence, and we will credit you unless you would rather we did not.

Published and reviewed by MASTERPANEL LLC. Last checked . Editorial method.