Skip to content

v1.5.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 14:01
· 14 commits to main since this release
3d4c9c9

Two things you will notice, and a great deal of work on the paths you should never have to think about.

What's new

A browser inside the application. Steam pages you need to reach — trade offers, market listings, account settings — open here instead of in your ordinary browser, with tabs and an address bar that belong to the application rather than to the page. A session opened for one account cannot be reused by another.

A routing choice per window. Each browser window can use the account's proxy for everything, use Steam-only through that same proxy, or go Direct, and the choice is shown rather than assumed. Require proxies is a vault-wide rule for people who want the stronger version: a configured proxy is the only way out, the Direct button does not exist, and the update check is refused. It is enforced in the main process, not by hiding a control.

Desktop notifications for confirmations. Off by default, and the setting says what a toast can contain before you turn it on. Clicking one opens that account's confirmations directly — including when the vault has locked and reloaded the window in between, which is the case a notification is least useful if it loses.

A Windows installer for arm64. The build configuration has always declared it and every release so far built x64 only, so Windows-on-ARM machines have had nothing but the x64 build under emulation.

Behind those, most of this release is failure safety: what happens when Steam is asked to do something irreversible and the answer never arrives. An operation Steam may already have carried out is now reported as a dead end rather than as a failure you can retry, and the application remembers that across closing the screen and across a restart. Locking the vault ends every Steam session, browser session, cached token and half-finished sign-in it was holding, rather than most of them. The full list is in CHANGELOG.md.

Which file to download

File For
open-desktop-authenticator-1.5.0-x64-setup.exe Most Windows PCs. 64-bit Intel or AMD.
open-desktop-authenticator-1.5.0-arm64-setup.exe Windows on ARM, such as a Snapdragon laptop.
open-desktop-authenticator-1.5.0-setup.exe Both of the above in one installer. Twice the size; take it only if you do not know which you need.
open-desktop-authenticator-1.5.0-portable.exe Windows, no installation. Keeps its vault beside the executable. 64-bit Intel or AMD only. It does not update itself — come back here for a new version.
open-desktop-authenticator-1.5.0-x86_64.AppImage Linux, no installation.
open-desktop-authenticator-1.5.0-amd64.deb Debian and Ubuntu.

Microsoft Store 1.5.0 is available now. Install it from the Store. Microsoft re-signs that x64 package, so it does not carry the warning shown for the direct downloads and Store updates arrive through Windows. On Windows 11 Arm, the Store's x64 package runs under emulation; use the native arm64 installer above if you want the native build.

No macOS build is published. macOS is built on every release so the target keeps working, but signing it needs Apple Developer enrollment as an organisation, which we have not completed. We will not ship an unsigned macOS build: unsigned, Gatekeeper refuses it on every machine except the one that built it.

Verifying what you downloaded

The Windows and Linux downloads on this page are not code-signed, and none is planned. We applied to the SignPath Foundation for a free certificate during this cycle and were declined. Windows will warn on first run. That warning is expected, and it is exactly why the checks below exist.

There is no way around the warning that does not involve trusting us more, so instead here is how to trust us less.

1. Check the file you downloaded is the file we published.

Linux:

sha256sum --check --ignore-missing SHA256SUMS.txt

macOS:

shasum -a 256 --check --ignore-missing SHA256SUMS.txt

Windows PowerShell — compare the result against the line for your file in SHA256SUMS.txt:

Get-FileHash .\open-desktop-authenticator-1.5.0-x64-setup.exe -Algorithm SHA256

--ignore-missing checks the files you actually have and skips the rest, so downloading one installer does not fail on the five you did not take. Read the output: every file you downloaded must say OK.

2. Check the checksum list is ours. Hashes prove a file was not altered on its way to you. They cannot prove the list is ours — whoever can replace a binary on a release page can usually replace the hash file beside it. This closes that:

cosign verify-blob SHA256SUMS.txt \
  --signature SHA256SUMS.txt.sig \
  --certificate SHA256SUMS.txt.pem \
  --certificate-identity https://github.com/opendesktopauthenticator/open-desktop-authenticator/.github/workflows/release.yml@refs/tags/v1.5.0 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

The signature is keyless. There is no private key a maintainer holds, escrows, loses or has stolen; the certificate is minted for this one workflow run and expires ten minutes later.

3. Check the binary came from this repository. Every file on this page carries a build provenance attestation, and the workflow refuses to publish anything it does not cover:

gh attestation verify open-desktop-authenticator-1.5.0-x64-setup.exe \
  --repo opendesktopauthenticator/open-desktop-authenticator

That names the workflow, the tag and the commit these bytes were built from. A site that copies this application cannot produce one.

What this does not prove. The attestation says where these bytes came from; it does not say they match the source, because nothing recomputes them. Builds are not yet reproducible — you cannot compile this tag yourself and get byte-for-byte identical output. When that changes it will be said here.

sbom.spdx.json lists what is inside the application, in SPDX format.


Open Desktop Authenticator is developed, owned, and published by MASTERPANEL LLC. Its official product website is opendesktopauthenticator.com. MASTERPANEL LLC also operates Master Panel; the products have no shared accounts, data, or integration. ODA is not affiliated with, endorsed by, or sponsored by Valve Corporation. Steam and Steam Guard are trademarks of Valve Corporation.