Open Desktop Authenticator

Report a problem

Bugs, documentation errors, and suspected clone sites. You do not need an account to report something, and you will get a reference you can use to follow it up.

Never include a secret in a report

Do not paste a .maFile, a shared secret, an identity secret, a revocation code, a password or an API key into this form or into any message to us. Nobody here will ever ask for one. A report that needs to describe a secret can describe its shape without its value.

No account is created either way. You get a reference you can use to check back; leaving an address just means we can ask a follow-up question, which is often the difference between a fixed bug and a closed one.

Reports containing what looks like a shared secret, an identity secret, a revocation code or a private key are refused and not stored. That is deliberate: the check is in the code, not just in the sentence above.

What to include

What happens to a report

  1. You get a reference in the form ODA-7K2M-B9QW. It is the only way to find the report again, so keep it — there is no account to recover it from.
  2. It is read. Reports are triaged rather than queued: anything describing lost access, lost items, or a secret behaving unexpectedly is looked at ahead of everything else.
  3. It gets an answer. Including "we are not going to change this", with a reason. A tracker where reports quietly expire is a tracker nobody reports to twice.

Reporting a clone site

Fake authenticator downloads are the reason this project exists, and a report takes a minute. Send the URL and where you found it — a search result, an advertisement, a video description, a Discord message. We collect them, warn about the patterns on the scam clones page, and report the worst to the registrars and hosts involved.

You do not need to be sure. A site that turns out to be legitimate costs us five minutes; one that turns out not to be may save somebody their inventory.

Security reports

Do not open a public issue for a security problem. There are two private routes, both live now:

What we commit to, in writing: acknowledgement within 72 hours, an initial assessment within 7 days, and a fix or a dated plan within 30 days for a confirmed high or critical. Those are the commitments of a single maintainer, and if one is going to be missed we will say so before the deadline rather than after. The full policy is in SECURITY.md.

Please give us a reasonable window to release a fix before publishing details. We will not use that window to argue you into silence, and we will credit you unless you would rather we did not.

Last reviewed .