Skip to content
LogoLogo

Confirmations

Steam Guard mobile confirmations. A sell listing is not live until confirmed, so this is part of the sell path rather than a separate concern.

These routes live under /mobileconf, not /market, and authenticate with an HMAC of the account's identity_secret rather than the sessionid CSRF field.

List pending confirmations

GET/mobileconf/getlist

Returns the account's outstanding Steam Guard confirmations, including the one a new sell listing is waiting on. Match a confirmation to its listing by the asset ID in its details.

Signed with tag=conf. The signature covers the tag, so a key generated for one tag is not valid for another.

Query Parameters

pRequired
string

Device identifier, derived from the SteamID by the mobile authenticator.

aRequired
string

SteamID64 of the account.

kRequired
string

Base64 HMAC-SHA1 over the tag and timestamp, keyed by identity_secret.

tRequired
integer <int64>

Unix seconds. Must match the timestamp the key was generated for.

mRequired
string

Client kind. Confirmations are an authenticator flow, so this is android.

Values
androidreact
tagRequired
string
Values
conf

Responses

Get confirmation details

GET/mobileconf/details/{confirmationid}

Returns an HTML fragment describing one pending confirmation. Clients parse it to tie a confirmation to the listing or trade that created it.

Signed with tag=details{confirmationid}, not a fixed string.

Path Parameters

confirmationidRequired
string

Query Parameters

pRequired
string

Device identifier, derived from the SteamID by the mobile authenticator.

aRequired
string

SteamID64 of the account.

kRequired
string

Base64 HMAC-SHA1 over the tag and timestamp, keyed by identity_secret.

tRequired
integer <int64>

Unix seconds. Must match the timestamp the key was generated for.

mRequired
string

Client kind. Confirmations are an authenticator flow, so this is android.

Values
androidreact
tagRequired
string
Exampledetails12345678901234567890

Responses

Accept or reject a confirmation

GET/mobileconf/ajaxop

Accepts or rejects one pending confirmation. Accepting the confirmation attached to a new sell listing is what actually publishes it; until then POST /market/sellitem/ has only staged the listing.

Signed with tag=allow or tag=cancel, matching op.

Query Parameters

opRequired
string

allow accepts, cancel rejects.

Values
allowcancel
cidRequired
string

Confirmation ID from /mobileconf/getlist.

ckRequired
string

Confirmation nonce from /mobileconf/getlist.

pRequired
string

Device identifier, derived from the SteamID by the mobile authenticator.

aRequired
string

SteamID64 of the account.

kRequired
string

Base64 HMAC-SHA1 over the tag and timestamp, keyed by identity_secret.

tRequired
integer <int64>

Unix seconds. Must match the timestamp the key was generated for.

mRequired
string

Client kind. Confirmations are an authenticator flow, so this is android.

Values
androidreact
tagRequired
string
Values
allowcancel

Responses