unforgiv3n Oct 31, 2020 @ 3:37am
Anybody knows what is Steam API key exactly? (safe or dangerous?)
So basically, I gambled on a CSGO gambling site yesterday and they ask people to create Steam API keys before depositing so the trade can be safer, so they can track it better and what not, I didn't understand much. Regardless, they said, the key makes your trades and account safer.

But, an hour later I search on youtube about this and see people get scammed and their accounts hacked through their API keys.

So my question is, does this API key make your account safe or vulnerable? What's the use of it? Can't really understand much. (I revoked it btw)
< >
Showing 1-15 of 23 comments
ReBoot Oct 31, 2020 @ 3:57am 
If anybody but you has that key, it's very dangerous. That's basically like a key to your home.
unforgiv3n Oct 31, 2020 @ 4:19am 
Originally posted by ReBoot:
If anybody but you has that key, it's very dangerous. That's basically like a key to your home.

Well nobody has it, I just entered it on a legit non scamming csgo gambling site so the trades can be faster and safer. Nobody else has it. I revoked it though. I don't think I have a key now.
ReBoot Oct 31, 2020 @ 4:24am 
Originally posted by unforgiv3n:
Originally posted by ReBoot:
If anybody but you has that key, it's very dangerous. That's basically like a key to your home.

Well nobody has it, I just entered it on a legit non scamming csgo gambling site so the trades can be faster and safer. Nobody else has it. I revoked it though. I don't think I have a key now.
You have no way to verify whether the site is trustworthy or not. But yeah, it's still like a key: if you trust someone, you may just as well give them the key. Just make sure your trust isn't wasted.

I personally wouldn't trust any gambling site because with unregulated gambling, they can screw you over as much as they want. There have been several incidents in the past where popular streamers were affiiliated with gambling, of course not disclosing that, and the odds were seriously tilted in favor of those streamers so the gambling site looked better than it was towards everybody else.
Last edited by ReBoot; Oct 31, 2020 @ 4:29am
unforgiv3n Oct 31, 2020 @ 4:28am 
Originally posted by ReBoot:
Originally posted by unforgiv3n:

Well nobody has it, I just entered it on a legit non scamming csgo gambling site so the trades can be faster and safer. Nobody else has it. I revoked it though. I don't think I have a key now.
You have no way to verify whether the site is trustworthy or not. But yeah, it's still like a key: if you trust someone, you may just as well give them the key. Just make sure your trust isn't wasted.

It's a 100% trusted site, it's been legit for years. But even if it's not, I revoked it and I need to know if a revoke is enough or no. I don't think my account has a key anymore, I want to be sure though.
ReBoot Oct 31, 2020 @ 4:30am 
Originally posted by unforgiv3n:
Originally posted by ReBoot:
You have no way to verify whether the site is trustworthy or not. But yeah, it's still like a key: if you trust someone, you may just as well give them the key. Just make sure your trust isn't wasted.

It's a 100% trusted site, it's been legit for years. But even if it's not, I revoked it and I need to know if a revoke is enough or no. I don't think my account has a key anymore, I want to be sure though.
The moment a key is revoked, it's gone, that's the whole point of revoking something. That particular combination of characters becomes a worthless random string of gibberish.
unforgiv3n Oct 31, 2020 @ 4:45am 
Originally posted by ReBoot:
Originally posted by unforgiv3n:

It's a 100% trusted site, it's been legit for years. But even if it's not, I revoked it and I need to know if a revoke is enough or no. I don't think my account has a key anymore, I want to be sure though.
The moment a key is revoked, it's gone, that's the whole point of revoking something. That particular combination of characters becomes a worthless random string of gibberish.

Some people said I need to change my password and disable/enable my steam mobile authenticator again. I wonder if that's even necessary or a revoke is enough.
J4MESOX4D Oct 31, 2020 @ 5:01am 
Originally posted by unforgiv3n:
Originally posted by ReBoot:
If anybody but you has that key, it's very dangerous. That's basically like a key to your home.

Well nobody has it, I just entered it on a legit non scamming csgo gambling site so the trades can be faster and safer. Nobody else has it. I revoked it though. I don't think I have a key now.
There is no legit sites of this nature and an API key can be created at any time. If you credential set has been captured along with the auth code, hijackers have control of your account and can do as they wish at any time.

The amount of users I've seen who have sworn blind a site is 'legit' on for them to come back crying that they got scammed is so big, I'd say it's near the thousands and that's just from these forums. You wont know until it's too late.

It's even possible for a site to detect if a user is instigating a trade which allows them to create an instant API key once this action is in motion. So you may think your account is clean only for the botters to make a split-second move.

If I were you, I'd deauthorize all other devices and walk away. For all the money you think you'll save, you may lose a lot more in getting scammed just like everyone else.
ReBoot Oct 31, 2020 @ 5:14am 
Originally posted by unforgiv3n:
Originally posted by ReBoot:
The moment a key is revoked, it's gone, that's the whole point of revoking something. That particular combination of characters becomes a worthless random string of gibberish.

Some people said I need to change my password and disable/enable my steam mobile authenticator again. I wonder if that's even necessary or a revoke is enough.
Did you give that gambling site your password? If no, then no need to change it. Did you give them a Steam guard token? If no, no need to deauthorizing devices or disabling the mobile auth.
Last edited by ReBoot; Oct 31, 2020 @ 5:14am
reg1s7 Oct 31, 2020 @ 5:29am 
Originally posted by unforgiv3n:
Some people said I need to change my password and disable/enable my steam mobile authenticator again. I wonder if that's even necessary or a revoke is enough.
You do not need to disable mobile authenticator.
About the password, it depends on whether you ever put it on fake login page or not. I suggest to change it, just in case.
unforgiv3n Oct 31, 2020 @ 5:53am 
Originally posted by J4MESOX4D:
Originally posted by unforgiv3n:

Well nobody has it, I just entered it on a legit non scamming csgo gambling site so the trades can be faster and safer. Nobody else has it. I revoked it though. I don't think I have a key now.
There is no legit sites of this nature and an API key can be created at any time. If you credential set has been captured along with the auth code, hijackers have control of your account and can do as they wish at any time.

The amount of users I've seen who have sworn blind a site is 'legit' on for them to come back crying that they got scammed is so big, I'd say it's near the thousands and that's just from these forums. You wont know until it's too late.

It's even possible for a site to detect if a user is instigating a trade which allows them to create an instant API key once this action is in motion. So you may think your account is clean only for the botters to make a split-second move.

If I were you, I'd deauthorize all other devices and walk away. For all the money you think you'll save, you may lose a lot more in getting scammed just like everyone else.

I am completely aware that there are scamming sites.

But this one is one of the most famous ones and it is really legit. Millions of people are using it and profiting from it.

I don't worry about my username or password. All I wanted to know is about the API key, what it can do, who has access to it and if a revoke is enough for protection.

I guess I got all my answers, so thank you and everyone else. Peace.
Nx Machina Oct 31, 2020 @ 7:03am 
Originally posted by unforgiv3n:
I am completely aware that there are scamming sites.

But this one is one of the most famous ones and it is really legit. Millions of people are using it and profiting from it.

Post the website link to the site you claim is legit. Steam will not block or remove it if it is legit.
ReBoot Oct 31, 2020 @ 7:05am 
Originally posted by Kusa:
Originally posted by unforgiv3n:
I am completely aware that there are scamming sites.

But this one is one of the most famous ones and it is really legit. Millions of people are using it and profiting from it.

Post the website link to the site you claim is legit. Steam will not block or remove it if it is legit.
Drop it all right. The OP got what they wanted and, more importantly, the OP revoked their key. Conclusion: all what's going on from now on is about being right rather than a constructive discussion.
J4MESOX4D Oct 31, 2020 @ 7:08am 
Originally posted by unforgiv3n:
Originally posted by J4MESOX4D:
There is no legit sites of this nature and an API key can be created at any time. If you credential set has been captured along with the auth code, hijackers have control of your account and can do as they wish at any time.

The amount of users I've seen who have sworn blind a site is 'legit' on for them to come back crying that they got scammed is so big, I'd say it's near the thousands and that's just from these forums. You wont know until it's too late.

It's even possible for a site to detect if a user is instigating a trade which allows them to create an instant API key once this action is in motion. So you may think your account is clean only for the botters to make a split-second move.

If I were you, I'd deauthorize all other devices and walk away. For all the money you think you'll save, you may lose a lot more in getting scammed just like everyone else.
But this one is one of the most famous ones and it is really legit. Millions of people are using it and profiting from it.
There are no 'legit' ones because gambling licences are not issued for this purpose and Valve has desist orders against many sites that are involved in this activity.

You also put your account at dire risk if you obtain an item which has been stolen/laundered and as you use 3rd party sites, you have no protection like you would if you traded within the Steam platform. These sites are created for the purpose of laundering and turning items (many scammed) into cash.

Always use these at your own risk.
Nx Machina Oct 31, 2020 @ 7:10am 
Originally posted by ReBoot:
Drop it all right. The OP got what they wanted and, more importantly, the OP revoked their key. Conclusion: all what's going on from now on is about being right rather than a constructive discussion.

Not your decision whether I make a post. I politely suggest you refrain from doing so.
ReBoot Oct 31, 2020 @ 7:14am 
Originally posted by Kusa:
Originally posted by ReBoot:
Drop it all right. The OP got what they wanted and, more importantly, the OP revoked their key. Conclusion: all what's going on from now on is about being right rather than a constructive discussion.

Not your decision whether I make a post. I politely suggest you refrain from doing so.
I politely suggest you report posts instead of starting a personal feud as you're doing now.
< >
Showing 1-15 of 23 comments
Per page: 1530 50

Date Posted: Oct 31, 2020 @ 3:37am
Posts: 23