Releases: opendesktopauthenticator/open-desktop-authenticator
Release list
v1.5.1 - Signed Windows downloads
Signed Windows downloads
Windows direct downloads in this release are Authenticode-signed by MASTERPANEL LLC and timestamped using Azure Artifact Signing. The packaged application, elevation helpers and embedded uninstallers are signed as well. Windows can identify the publisher and detect changes to signed files; signing does not guarantee that SmartScreen will stop warning.
What changed
- Shorter installer permission-prompt name: Open Desktop Authenticator.
- Clearer publisher labels identifying MASTERPANEL LLC, and About text explaining that Master Panel is a separate product with no shared accounts or data.
- Gated signing, final-signature verification and development-tool security updates.
No authenticator protocol, vault-format or production dependency changes are included. Application identity and vault locations are unchanged. Existing v1.5.0 assets have not been replaced and its Windows executables remain unsigned.
Choose your download
- Most Intel/AMD Windows PCs:
open-desktop-authenticator-1.5.1-x64-setup.exe. - Windows on ARM:
open-desktop-authenticator-1.5.1-arm64-setup.exe. - Combined x64/ARM64 installer:
open-desktop-authenticator-1.5.1-setup.exe. - Portable x64, manual updates:
open-desktop-authenticator-1.5.1-portable.exe. - Linux x64:
.AppImageor-amd64.deb. Linux files are not platform code-signed; use the checksums and provenance below.
The Microsoft Store is a separate distribution channel; this GitHub release does not update its package. No macOS download is included.
Verification
On Windows, open Properties → Digital Signatures → Details. The signature should be valid and identify MASTERPANEL LLC. In PowerShell:
Get-AuthenticodeSignature .\open-desktop-authenticator-1.5.1-x64-setup.exe | Format-List Status,SignerCertificate,TimeStamperCertificate
Get-FileHash .\open-desktop-authenticator-1.5.1-x64-setup.exe -Algorithm SHA256Compare the file hash with its entry in SHA256SUMS.txt. On Linux, after downloading that list and the files you need:
sha256sum --check --ignore-missing SHA256SUMS.txtThe checksum list is separately signed with Sigstore. Download SHA256SUMS.txt, SHA256SUMS.txt.sig and SHA256SUMS.txt.pem, then verify using cosign v2:
cosign verify-blob SHA256SUMS.txt --signature SHA256SUMS.txt.sig --certificate SHA256SUMS.txt.pem --certificate-identity https://github.com/opendesktopauthenticator/open-desktop-authenticator/.github/workflows/release.yml@refs/tags/v1.5.1 --certificate-oidc-issuer https://token.actions.githubusercontent.comVerify an executable's GitHub build provenance, substituting another downloaded binary when appropriate:
gh attestation verify open-desktop-authenticator-1.5.1-x64-setup.exe --repo opendesktopauthenticator/open-desktop-authenticatorsbom.spdx.json lists the shipping dependency tree. More context: verification guide, source changelog.
Testing and limits
The v1.5.1 release workflow passed Windows and Linux automated tests, final Windows signature verification, the portable-runtime check, packaging, checksum-signature verification and build-provenance generation. The preceding signed Windows smoke build was also installed and tested by the maintainer, with Windows showing the verified publisher. This is not an independent security audit. Native ARM64 execution and Linux manual runtime checks are not claimed here; the founder test plan records the existing broader manual-test gaps.
Back up your vault and recovery information before an upgrade. Use the installer for your architecture, and keep portable vault data when replacing the portable executable.
v1.5.0
Two things you will notice, and a great deal of work on the paths you should never have to think about.
What's new
A browser inside the application. Steam pages you need to reach — trade offers, market listings, account settings — open here instead of in your ordinary browser, with tabs and an address bar that belong to the application rather than to the page. A session opened for one account cannot be reused by another.
A routing choice per window. Each browser window can use the account's proxy for everything, use Steam-only through that same proxy, or go Direct, and the choice is shown rather than assumed. Require proxies is a vault-wide rule for people who want the stronger version: a configured proxy is the only way out, the Direct button does not exist, and the update check is refused. It is enforced in the main process, not by hiding a control.
Desktop notifications for confirmations. Off by default, and the setting says what a toast can contain before you turn it on. Clicking one opens that account's confirmations directly — including when the vault has locked and reloaded the window in between, which is the case a notification is least useful if it loses.
A Windows installer for arm64. The build configuration has always declared it and every release so far built x64 only, so Windows-on-ARM machines have had nothing but the x64 build under emulation.
Behind those, most of this release is failure safety: what happens when Steam is asked to do something irreversible and the answer never arrives. An operation Steam may already have carried out is now reported as a dead end rather than as a failure you can retry, and the application remembers that across closing the screen and across a restart. Locking the vault ends every Steam session, browser session, cached token and half-finished sign-in it was holding, rather than most of them. The full list is in CHANGELOG.md.
Which file to download
| File | For |
|---|---|
open-desktop-authenticator-1.5.0-x64-setup.exe |
Most Windows PCs. 64-bit Intel or AMD. |
open-desktop-authenticator-1.5.0-arm64-setup.exe |
Windows on ARM, such as a Snapdragon laptop. |
open-desktop-authenticator-1.5.0-setup.exe |
Both of the above in one installer. Twice the size; take it only if you do not know which you need. |
open-desktop-authenticator-1.5.0-portable.exe |
Windows, no installation. Keeps its vault beside the executable. 64-bit Intel or AMD only. It does not update itself — come back here for a new version. |
open-desktop-authenticator-1.5.0-x86_64.AppImage |
Linux, no installation. |
open-desktop-authenticator-1.5.0-amd64.deb |
Debian and Ubuntu. |
Microsoft Store 1.5.0 is available now. Install it from the Store. Microsoft re-signs that x64 package, so it does not carry the warning shown for the direct downloads and Store updates arrive through Windows. On Windows 11 Arm, the Store's x64 package runs under emulation; use the native arm64 installer above if you want the native build.
No macOS build is published. macOS is built on every release so the target keeps working, but signing it needs Apple Developer enrollment as an organisation, which we have not completed. We will not ship an unsigned macOS build: unsigned, Gatekeeper refuses it on every machine except the one that built it.
Verifying what you downloaded
The Windows and Linux downloads on this page are not code-signed, and none is planned. We applied to the SignPath Foundation for a free certificate during this cycle and were declined. Windows will warn on first run. That warning is expected, and it is exactly why the checks below exist.
There is no way around the warning that does not involve trusting us more, so instead here is how to trust us less.
1. Check the file you downloaded is the file we published.
Linux:
sha256sum --check --ignore-missing SHA256SUMS.txtmacOS:
shasum -a 256 --check --ignore-missing SHA256SUMS.txtWindows PowerShell — compare the result against the line for your file in SHA256SUMS.txt:
Get-FileHash .\open-desktop-authenticator-1.5.0-x64-setup.exe -Algorithm SHA256--ignore-missing checks the files you actually have and skips the rest, so downloading one installer does not fail on the five you did not take. Read the output: every file you downloaded must say OK.
2. Check the checksum list is ours. Hashes prove a file was not altered on its way to you. They cannot prove the list is ours — whoever can replace a binary on a release page can usually replace the hash file beside it. This closes that:
cosign verify-blob SHA256SUMS.txt \
--signature SHA256SUMS.txt.sig \
--certificate SHA256SUMS.txt.pem \
--certificate-identity https://github.com/opendesktopauthenticator/open-desktop-authenticator/.github/workflows/release.yml@refs/tags/v1.5.0 \
--certificate-oidc-issuer https://token.actions.githubusercontent.comThe signature is keyless. There is no private key a maintainer holds, escrows, loses or has stolen; the certificate is minted for this one workflow run and expires ten minutes later.
3. Check the binary came from this repository. Every file on this page carries a build provenance attestation, and the workflow refuses to publish anything it does not cover:
gh attestation verify open-desktop-authenticator-1.5.0-x64-setup.exe \
--repo opendesktopauthenticator/open-desktop-authenticatorThat names the workflow, the tag and the commit these bytes were built from. A site that copies this application cannot produce one.
What this does not prove. The attestation says where these bytes came from; it does not say they match the source, because nothing recomputes them. Builds are not yet reproducible — you cannot compile this tag yourself and get byte-for-byte identical output. When that changes it will be said here.
sbom.spdx.json lists what is inside the application, in SPDX format.
Open Desktop Authenticator is developed, owned, and published by MASTERPANEL LLC. Its official product website is opendesktopauthenticator.com. MASTERPANEL LLC also operates Master Panel; the products have no shared accounts, data, or integration. ODA is not affiliated with, endorsed by, or sponsored by Valve Corporation. Steam and Steam Guard are trademarks of Valve Corporation.
v1.0.0
The first version of Open Desktop Authenticator that exists as an installable file rather than as source. A maintained successor to Steam Desktop Authenticator, built and maintained by MASTERPANEL LLC.
Where to get it
On Windows, use the Microsoft Store. Microsoft re-signs every package it distributes, so SmartScreen never warns, updates arrive on their own, and there is nothing for you to verify by hand.
The files below are for everything else — Linux, Windows images without the Store, the portable build, and anyone who would rather check the bytes than be told they are fine.
They carry no code-signing certificate, so Windows warns on first run. That warning is about a missing certificate, not about the file being wrong, and the steps below are how you tell those two apart.
What it does
- An encrypted vault for as many accounts as you have, unlocked with a passphrase you choose
- Imports the maFiles you already have from Steam Desktop Authenticator
- Steam Guard codes
- Trade and market confirmations: see what is pending, accept it or deny it
- Optional auto-confirm, per account and per confirmation type, off until you turn it on
- Optional per-account network routing
No servers. No sync. No accounts with us. No telemetry of any kind. Your machine talks to Valve directly and to nothing of ours.
Verify what you downloaded
Take SHA256SUMS.txt from this release page — not from a mirror, and not from wherever you got the installer.
Linux
sha256sum --check --ignore-missing SHA256SUMS.txt
macOS — a stock Mac ships shasum, not sha256sum:
shasum -a 256 --check --ignore-missing SHA256SUMS.txt
--ignore-missing is not optional here. The list covers every file in the
release and you almost certainly took one of them, so without it sha256sum
reports FAILED open or read for each file you do not have and exits non-zero
— which looks exactly like the tampering you were checking for. It also skips
the .appx line, which refers to a file removed from this release (see the note
at the end).
Windows PowerShell
Get-FileHash .\<file> -Algorithm SHA256
PowerShell prints upper case and the list is lower case. That is the same value written two ways, not a mismatch.
Build provenance — proof these exact bytes came from this repository's public workflow, at this commit:
gh attestation verify <file> --owner opendesktopauthenticator
Platforms
Windows 10 version 1809 (build 17763) or later, Windows 11, and Linux. macOS is deferred rather than planned: signing it requires Apple Developer enrollment as an organization, and we will not ship an unsigned macOS build.
Honest limits
This is maintainer testing, not an independent audit. The application has been run end to end against live Steam accounts — import from SDA, enrollment, code generation, confirmations, backup, restore and recovery — and the defects that surfaced were fixed and covered by tests. That is not the same as review by someone with no stake in the answer.
Microsoft Store certification is not a substitute either. It checks policy compliance and that the application runs. It does not examine the vault's cryptography, and nobody should read it as if it had.
Never download an authenticator from a website — including ours. The Store listing above and this releases page are the only two places a genuine build comes from. opendesktopauthenticator.com hosts no installer and never will; every button on it links to one of these two.
Full changelog: CHANGELOG.md
Note, added 25 August 2026
An .appx was removed from this release after publication.
Open.Desktop.Authenticator.1.0.0.appx was published here by mistake. The Store
package is deliberately unsigned — Microsoft re-signs it when it ingests the
submission — so the file could not be installed by anyone who downloaded it, and
it was not covered by the build provenance attestation. Both of the checks
described above therefore failed on it: gh attestation verify returned 404, and
its name in SHA256SUMS.txt never matched the name GitHub served it under.
A file on this page that cannot be verified is the exact thing this project tells
you to be suspicious of, so it has been taken down. Nothing else changed. If you
installed from the Microsoft Store, or downloaded any other file here, you are
unaffected.
SHA256SUMS.txt has deliberately not been regenerated. It still lists that
appx. Quietly editing a published list of hashes is indistinguishable from
tampering with one, and asking you to trust a checksum file that changed after
publication would undo the point of having it. The remaining entries are
unchanged and still correct; the appx line simply refers to a file that is no
longer here.
The pipeline no longer collects the Store package into the release, and a step
now refuses to publish anything the attestation does not cover
(907468f).