> For the complete documentation index, see [llms.txt](https://yubico.gitbook.io/yubikey5/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://yubico.gitbook.io/yubikey5/tutorials/steam-otp.md).

# Steam OTP

The following instructions allow you to add Steam to your Yubikey's TOTP list via Yubikey Authenticator.

## <mark style="color:red;">❊ What is Steam?</mark>

Steam is a video game digital distribution service and storefront by Valve. It was launched as a software client in September 2003 as a way for Valve to provide automatic updates for their games, and expanded to distributing and offering third-party game publishers' titles in late 2005.

One of the main security features of Steam is known as <mark style="color:red;">**Steam Guard**</mark>. This service allows you to add extra protection to your account and relies on installing a mobile program called <mark style="color:red;">**Steam Guard Mobile Authenticator**</mark>.

## <mark style="color:red;">❊ Steam Guard Mobile Authenticator</mark>

<mark style="color:red;">**Steam Guard**</mark> is the Two-Factor authentication system you can enable to protect your Steam account. It works exactly as any 2FA protection, except that the One-Time Passwords are generated by the [Steam Guard Mobile Authenticator](https://help.steampowered.com/faqs/view/7EFD-3CAE-64D3-1C31) only (or received by e-mail).

As Steam does not provide a standard way to use an alternative OTP app like 2FAuth, Authy, or Google Authenticator, the workaround is to get the OTP secret thanks to a third-party app. Once recovered, you will be able to use 2FAuth in place of the Steam Mobile Authenticator.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2Fwhk9K67xFEPwHrW3wMeD%2Fsteam_2.png?alt=media&amp;token=fec93b83-e9d7-4a49-99f9-c0ae7006618e" alt=""><figcaption></figcaption></figure>

## <mark style="color:red;">❊ Steam Secret Key</mark>

The <mark style="color:red;">**steam secret key**</mark> is the key you are given that is used by the mobile authenticator in order to generate a OTP every 30 seconds. Steam does not provide an easy way to view your steam secret; and they frankly don't want you having it. However, once you obtain your steam secret; you can use that secret to add your Steam account to any authenticator, including the Yubikey.

## <mark style="color:red;">❊ Obtaining Steam Secret Key</mark>

{% hint style="danger" %}
Your steam secret key should be kept secret. Under no circumstances should you EVER give out your Steam Secret Key to anyone, for any reason.

If someone obtains your steam secret; they can then generate OTP codes and allow themself to access your steam account.
{% endhint %}

Since Steam does not want you having your secret key, we need to utilize a program called <mark style="color:red;">**Steam Desktop Authenticator (SDA)**</mark>. This is a free open-source application that has been around for years and is trusted. Using this application will allow you to obtain the secret key needed.

{% hint style="danger" %} <mark style="color:red;">**DANGER:**</mark>\
Recently there have been fake versions of SDA floating around that will steal your Steam account. Never download SDA from any place other than the official github repo!

The direct download above has been taken right from the repo.&#x20;
{% endhint %}

### <mark style="color:red;">Download From Github</mark>

<table><thead><tr><th></th><th></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="https://github.com/Jessecar96/SteamDesktopAuthenticator/releases">Official Website</a></td><td>Download the latest version of SDA from the official Github page.</td><td></td></tr></tbody></table>

### <mark style="color:red;">Direct Download</mark>

You may also get the direct download below.

{% file src="/files/9dMgUdG65cG75owyrJ8Y" %}

Once you have downloaded SDA from the links above, extract the zip somewhere on your computer.

Before continuing, you must first disable the Steam Guard feature of your steam account before attempting to use SDA. If you already have Steam Guard enabled, and attempt to use SDA; you will be presented with the following error:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FXNnskS3GhgsWEFYnvwuO%2Fsteam_8.png?alt=media&amp;token=9c541c2c-db9e-4f14-b0db-2692f9044c87" alt=""><figcaption></figcaption></figure>

Once everything is done, launch <mark style="color:red;">**`Steam Desktop Authenticator.exe`**</mark>

The application may install a few libraries that are required for the program to run:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FppPEl3IDJ2l6rVaMlIjq%2Fsteam_4.png?alt=media&amp;token=08baff7a-7e1a-462d-a546-f32343b36854" alt=""><figcaption></figcaption></figure>

After the application launches, you'll be presented with the following options:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FMtMKgrPodd7Pzf2dE6nH%2Fsteam_5.png?alt=media&amp;token=15cca723-5cbe-4b61-a7ad-151f661d5616" alt=""><figcaption></figcaption></figure>

Read the options, and select which scenario fits you best. Some of you may have already used this program before.&#x20;

For most people, you'll want to select <mark style="color:red;">**This is my first time and I just want to sign into my Steam Account(s).**</mark>

You will be presented with the main interface:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYaqkMyfEAvaQ6bjRm36%2Fsteam_6.png?alt=media&amp;token=fac38266-ca42-4ca1-9164-86a837110b19" alt=""><figcaption></figcaption></figure>

You will need to select ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FOhQIRbjeQ2DBufn05NLE%2Fsteam_9.png?alt=media\&token=1a4262dc-40a5-4d14-a208-889aeb9d682f)

Which will ask you for your Steam login credentials:

{% hint style="danger" %}
Ensure you downloaded SDA from the links above. Do not enter your login information until you are sure you have the correct application. As stated before, there are fake versions running around. The official link and the direct download above are the only officials.
{% endhint %}

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FOsDYHK5r8k8ZEoiXhWns%2Fsteam_7.png?alt=media&amp;token=53d11673-6121-4629-8fdc-7d68bb9b77af" alt=""><figcaption></figcaption></figure>

Continue with the setup by signing in. It may ask you to verify adding the Steam Guard service to your account by sending you an email that you must click on.

{% hint style="info" %}
My steam account currently has Steam Guard enabled and I have it configured with my authenticators, so I can't show each step otherwise I'd have to unlink Steam Guard and then update all my OTP programs again.&#x20;

It is easy to follow, so you should have no issues.
{% endhint %}

After adding your steam account to SDA, you should start generating OTP codes:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FIhTMu11ZwcxcBhC5mynE%2Fsteam_10.png?alt=media&amp;token=1265fa4c-db38-4932-8dec-ece09b51c4bb" alt=""><figcaption></figcaption></figure>

Go back to the folder where you placed SDA. Then click on the <mark style="color:red;">**`maFiles`**</mark> folder. You should see a <mark style="color:red;">**`.maFile`**</mark> file which is the named with your Steam64 ID.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2F3768KNdkWz6ifrXGR9oB%2Fsteam_11.png?alt=media&amp;token=0dff0577-5f80-4b49-b3c6-b217d8b34708" alt=""><figcaption></figcaption></figure>

Open the .maFile in a text editor.

{% hint style="info" %}
For this example, I have "beautified" mine so that it's easier to read.

\
If the code is too difficult to read with everything being on one line or word-wrapped, you can use an [**online JSON Beautifier available here**](https://codebeautify.org/jsonviewer).

Paste your code inside the beautifier and then press "Beautify".

This tool will format your JSON file in a more human readable format.
{% endhint %}

{% code lineNumbers="true" %}

```json
{
    "shared_secret": "H26A/2BAH2L5kL2G56EpDkAk/ag=",
    "serial_number": "11145234561356781234",
    "revocation_code": "RAAA0A",
    "uri": "otpauth://totp/Steam:YourSteamUsername?secret=BAFR25G2EHFEGHFA346F572AVGQ256F6&issuer=Steam",
    "server_time": 1000000000,
    "account_name": "YourSteamUsername",
    "token_gid": "1a123456789ae123",
    "identity_secret": "AEF3DQxz14zfG26A4gh4H25e6fs=",
    "secret_1": "2d42d4g52G35A2FA2F123AguUj5=",
    "status": 1,
    "device_id": "android:47769b96-1111-aaaa-9999-234e23a5eb24",
    "fully_enrolled": true,
    "Session": {
        // hidden
    }
}
```

{% endcode %}

In your <mark style="color:red;">**`maFile`**</mark>, locate the `shared_secret`:

```json
"shared_secret": "H26A/2BAH2L5kL2G56EpDkAk/ag="
```

Write the <mark style="color:red;">**`shared_secret`**</mark> down or store it in a password manager like Bitwarden or KeePassXC.  We need the shared secret to give us the ability to use our Yubikey to sign into Steam.

Next, we need to convert the shared secret to get your actual secret key, you have to take the text in the shared\_secret above and run it through a few tools.

{% hint style="info" %}
The instructions below require you to go to a few websites and convert the shared\_secret from <mark style="color:red;">**base64**</mark> to <mark style="color:red;">**hex**</mark> to <mark style="color:red;">**base32**</mark>.

If you do not want to do these steps, there's a pre-made tool that is already configured to do the conversion for you.

Use the tool below and paste your shared\_secret in the top right box. Your actual steam secret will be provided in the bottom right box.<br>

[**View Online Tool Here**](https://gchq.github.io/CyberChef/#recipe=From_Base64\('A-Za-z0-9%2B/%3D',false,false\)To_Hex\('None',0\)From_Hex\('Auto'\)To_Base32\('A-Z2-7%3D'\))

\
For more information on this method, view the section :\
[**Converting Base64 Shared Secret**](#converting-base64-shared-secret)
{% endhint %}

If you do not want to use the online tool provided above, follow these instructions:

Copy the shared secret in the maFile, then go to [**Base64 to Hex converter website here**](https://base64.guru/converter/decode/hex).

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FC8kIvqOxf0R5qZhKux2J%2Fsteam_12.png?alt=media&amp;token=d12183c7-0d9f-4b38-ab18-6d6fa59bf4c2" alt=""><figcaption></figcaption></figure>

Paste your steam shared\_secret in the top box labeled **Base64**. Press the **Convert Base64 to Hex** button and your Hex should be provided in the **Hex** box at the bottom.

For my example, it converted <mark style="color:blue;">**H26A/2BAH2L5kL2G56EpDkAk/ag=**</mark> to the hex <mark style="color:blue;">**1f6e80ff60401f62f990bd86e7a1290e4024fda8**</mark>

Next, convert the **Hex** string to **Base32**. You can do this by visiting the [**Hex to Base32 converter website here**](https://cryptii.com/pipes/hex-to-base32).

Paste your **Hex** value into the far left box, and then the far right box should automatically give you a **Base32** value.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FkK70Kjse3ILekcBtH5ti%2Fsteam_13.png?alt=media&amp;token=831c184f-f2bd-4678-951c-2104b0c8f4d1" alt=""><figcaption></figcaption></figure>

To summarize:

* Copy the <mark style="color:yellow;">**`Base64`**</mark><mark style="color:red;">**`shared_secret`**</mark> given in the <mark style="color:red;">**maFile**</mark>.
* Convert the <mark style="color:yellow;">**`Base64`**</mark> <mark style="color:red;">**`shared_secret`**</mark> to <mark style="color:blue;">**`Hex`**</mark>.
* Convert the <mark style="color:blue;">**`Hex`**</mark> to <mark style="color:green;">**`Base32`**</mark>.

The Base32 string is your actual secret that you will use with your authenticators. In our example, we're given the value <mark style="color:red;">**`D5XIB73AIAPWF6MQXWDOPIJJBZACJ7NI`**</mark>

This number should be saved also in a private place. The original shared\_secret that you saved is no longer needed unless you lose your actual secret one day and need to convert it again.

We've done quite a bit, but we're almost done.

## <mark style="color:red;">❊ Adding Steam to Yubikey</mark>

{% hint style="warning" %}
If you do not have the [**Yubikey Authenticator**](https://www.yubico.com/products/yubico-authenticator/) and [**Yubico Manager**](https://www.yubico.com/support/download/yubikey-manager/) installed; you will need to do so now.\
\
If you don't have a Yubikey at all, you can add your Steam account to programs such as KeePassXC and Bitwarden by following steps similar to below.
{% endhint %}

Now that we have our Steam secret key, add it to a Yubikey.

You cannot add Steam to your Yubikey from the <mark style="color:red;">**Yubikey Authenticator**</mark> app. The reason for this is because <mark style="color:green;">**Steam OTP**</mark> codes are <mark style="color:green;">**5 digits**</mark>.&#x20;

<mark style="color:red;">**Yubico Authenticator**</mark> only gives the option to add <mark style="color:yellow;">**6 and 8 digit codes**</mark>.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FDEelpnJEGiA26FCtAkTe%2Fsteam_1.png?alt=media&amp;token=1476bf02-c863-4e93-b5f4-3beba6e41a6b" alt=""><figcaption></figcaption></figure>

We need to utilize the command-line and manually add Steam to our Yubikey.

Launch **Powershell**, **Command Prompt**, or **Terminal**.

Change directories to your <mark style="color:red;">**Yubikey Manager**</mark> program path with the following command:

```powershell
cd "C:\Program Files\Yubico\YubiKey Manager"
```

Add your Steam account by typing:

```powershell
ykman oath accounts add STEAMNAME -i Steam
```

Change <mark style="color:red;">**`STEAMNAME`**</mark> to your steam account name. Don't edit anything else.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FBLKCjOLlkDVzSQVaYJr6%2Fsteam_15.png?alt=media&amp;token=58032da0-c108-4155-a6c3-f634ec39f4ef" alt=""><figcaption></figcaption></figure>

You will be prompted to enter your <mark style="color:red;">**`Steam Secret Key`**</mark>. Which is what we converted earlier from our <mark style="color:red;">**shared\_secret**</mark>.

My Steam secret is D5XIB73AIAPWF6MQXWDOPIJJBZACJ7NI. Yours will be different.

It might prompt for a password. If so, enter the <mark style="color:red;">**OATH password**</mark> you configured in the Yubikey Authenticator program.

Steam will be added to your Yubico Authenticator app.

Now launch <mark style="color:red;">**Yubico Authenticator**</mark>.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2Ffqlktzv68KM2wgR9fIKr%2Fsteam_19.png?alt=media&amp;token=f9bf9b35-31ac-4f06-8645-8fe04d1c01b2" alt=""><figcaption></figcaption></figure>

If you have a password enabled for Yubico Authenticator, enter it:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FKzkgZYIPvq40MJNBVJUt%2Fsteam_18.png?alt=media&amp;token=512ae94c-5ddc-41ec-8556-3fcef53aa51e" alt=""><figcaption></figcaption></figure>

You should now see Steam in your authenticator list:

<div><figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2Fr5c4e2ILaiSHFAevZOpj%2Fsteam_16.png?alt=media&amp;token=1069d20d-14e1-49c8-bcdf-424480623796" alt=""><figcaption></figcaption></figure> <figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FBVVx73anjlakoTohsa02%2Fsteam_17.png?alt=media&amp;token=36b0dbfe-5480-438f-8af3-58bdd02eaada" alt=""><figcaption></figcaption></figure></div>

Every time you sign into Steam, you can launch the Yubico Authenticator and retrieve your 5 digit OTP code.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FJjni3nJEVAWyDyOJDvqc%2Fsteam_20.png?alt=media&amp;token=dea7c5b3-c98c-4369-adcf-d75a2f6b18a0" alt=""><figcaption></figcaption></figure>

## <mark style="color:red;">❊ Converting Base64 Shared Secret</mark>

In the instructions above, we ask you to go to several websites. There's an easier alternative way which makes it a whole lot more simple thanks to the program Cyber Chef.

Cyber Chef is a online utility which allows you to convert many different strings. I have prepared a URL which automatically sets up the application to where you only need to paste in your shared secret.

[**Click here to access the converter**](https://gchq.github.io/CyberChef/#recipe=From_Base64\('A-Za-z0-9%2B/%3D',false,false\)To_Hex\('None',0\)From_Hex\('Auto'\)To_Base32\('A-Z2-7%3D'\))

In the tool, Ignore everything on the left; it has been set up for you.

You only need to paste your <mark style="color:red;">**shared\_secret**</mark> in the **top right box**, and your actual steam secret will be output in the bottom right box:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FjlcYei4BMVlKja7ukOx4%2Fsteam_21.png?alt=media&amp;token=cf7e5b29-aebb-4df4-8e71-f0d9b09e723c" alt=""><figcaption></figcaption></figure>

The program does all of the conversions.

Then copy the secret key in the bottom right box, and use that with the instructions in the [**Adding Steam to Yubikey section**](#adding-steam-to-yubikey).

The website is trustworthy and does not record information you provide. However, there is the option to download the actual program, extract it to your computer, and open the provided HTML file and you can do everything locally.

<table data-header-hidden><thead><tr><th></th><th></th><th data-hidden></th></tr></thead><tbody><tr><td><strong>CyberChef (Github)</strong></td><td><a href="https://github.com/gchq/CyberChef/releases"><strong>Download Here</strong></a></td><td></td></tr></tbody></table>
