v1.0.0
The first version of Open Desktop Authenticator that exists as an installable file rather than as source. A maintained successor to Steam Desktop Authenticator, built and maintained by MASTERPANEL LLC.
Where to get it
On Windows, use the Microsoft Store. Microsoft re-signs every package it distributes, so SmartScreen never warns, updates arrive on their own, and there is nothing for you to verify by hand.
The files below are for everything else — Linux, Windows images without the Store, the portable build, and anyone who would rather check the bytes than be told they are fine.
They carry no code-signing certificate, so Windows warns on first run. That warning is about a missing certificate, not about the file being wrong, and the steps below are how you tell those two apart.
What it does
- An encrypted vault for as many accounts as you have, unlocked with a passphrase you choose
- Imports the maFiles you already have from Steam Desktop Authenticator
- Steam Guard codes
- Trade and market confirmations: see what is pending, accept it or deny it
- Optional auto-confirm, per account and per confirmation type, off until you turn it on
- Optional per-account network routing
No servers. No sync. No accounts with us. No telemetry of any kind. Your machine talks to Valve directly and to nothing of ours.
Verify what you downloaded
Take SHA256SUMS.txt from this release page — not from a mirror, and not from wherever you got the installer.
Linux
sha256sum --check --ignore-missing SHA256SUMS.txt
macOS — a stock Mac ships shasum, not sha256sum:
shasum -a 256 --check --ignore-missing SHA256SUMS.txt
--ignore-missing is not optional here. The list covers every file in the
release and you almost certainly took one of them, so without it sha256sum
reports FAILED open or read for each file you do not have and exits non-zero
— which looks exactly like the tampering you were checking for. It also skips
the .appx line, which refers to a file removed from this release (see the note
at the end).
Windows PowerShell
Get-FileHash .\<file> -Algorithm SHA256
PowerShell prints upper case and the list is lower case. That is the same value written two ways, not a mismatch.
Build provenance — proof these exact bytes came from this repository's public workflow, at this commit:
gh attestation verify <file> --owner opendesktopauthenticator
Platforms
Windows 10 version 1809 (build 17763) or later, Windows 11, and Linux. macOS is deferred rather than planned: signing it requires Apple Developer enrollment as an organization, and we will not ship an unsigned macOS build.
Honest limits
This is maintainer testing, not an independent audit. The application has been run end to end against live Steam accounts — import from SDA, enrollment, code generation, confirmations, backup, restore and recovery — and the defects that surfaced were fixed and covered by tests. That is not the same as review by someone with no stake in the answer.
Microsoft Store certification is not a substitute either. It checks policy compliance and that the application runs. It does not examine the vault's cryptography, and nobody should read it as if it had.
Never download an authenticator from a website — including ours. The Store listing above and this releases page are the only two places a genuine build comes from. opendesktopauthenticator.com hosts no installer and never will; every button on it links to one of these two.
Full changelog: CHANGELOG.md
Note, added 25 August 2026
An .appx was removed from this release after publication.
Open.Desktop.Authenticator.1.0.0.appx was published here by mistake. The Store
package is deliberately unsigned — Microsoft re-signs it when it ingests the
submission — so the file could not be installed by anyone who downloaded it, and
it was not covered by the build provenance attestation. Both of the checks
described above therefore failed on it: gh attestation verify returned 404, and
its name in SHA256SUMS.txt never matched the name GitHub served it under.
A file on this page that cannot be verified is the exact thing this project tells
you to be suspicious of, so it has been taken down. Nothing else changed. If you
installed from the Microsoft Store, or downloaded any other file here, you are
unaffected.
SHA256SUMS.txt has deliberately not been regenerated. It still lists that
appx. Quietly editing a published list of hashes is indistinguishable from
tampering with one, and asking you to trust a checksum file that changed after
publication would undo the point of having it. The remaining entries are
unchanged and still correct; the appx line simply refers to a file that is no
longer here.
The pipeline no longer collects the Store package into the release, and a step
now refuses to publish anything the attestation does not cover
(907468f).