Confirmations
Steam Guard mobile confirmations. A sell listing is not live until confirmed, so this is part of the sell path rather than a separate concern.
These routes live under /mobileconf, not /market, and authenticate with an HMAC of the
account's identity_secret rather than the sessionid CSRF field.
List pending confirmations
/mobileconf/getlistReturns the account's outstanding Steam Guard confirmations, including the one a new sell listing is waiting on. Match a confirmation to its listing by the asset ID in its details.
Signed with tag=conf. The signature covers the tag, so a key generated for one tag is not
valid for another.
Query Parameters
stringClient kind. Confirmations are an authenticator flow, so this is android.
androidreactResponses
Get confirmation details
/mobileconf/details/{confirmationid}Returns an HTML fragment describing one pending confirmation. Clients parse it to tie a confirmation to the listing or trade that created it.
Signed with tag=details{confirmationid}, not a fixed string.
Path Parameters
Query Parameters
stringClient kind. Confirmations are an authenticator flow, so this is android.
androidreactResponses
Accept or reject a confirmation
/mobileconf/ajaxopAccepts or rejects one pending confirmation. Accepting the confirmation attached to a new
sell listing is what actually publishes it; until then POST /market/sellitem/ has only
staged the listing.
Signed with tag=allow or tag=cancel, matching op.
Query Parameters
stringClient kind. Confirmations are an authenticator flow, so this is android.
androidreact
