Skip to content
LogoLogo

Authentication

Steam uses browser session state rather than one uniform API credential.

Public reads

Search, suggestions, filter facets, price overview, and most listing data respond without an authenticated account. Availability still depends on locale, rate controls, and Steam policy.

Session-authenticated reads

Account-specific routes require the same cookie state as an authenticated steamcommunity.com browser session. Relevant cookies commonly include steamLoginSecure and locale/currency cookies.

Cookie: steamLoginSecure=<redacted>; sessionid=<redacted>

GET /market/userbillinginfo, GET /market/mylistings, price history, and Market mutations should be treated as authenticated.

Mutations and CSRF

Mutating form requests include a sessionid field in addition to authenticated cookies. Steam uses this value as a CSRF token.

Content-Type: application/x-www-form-urlencoded
 
sessionid=<redacted>&buy_orderid=6885979650

Never publish cookies, access tokens, billing data, or session IDs.