STEAM GROUP
Stea Supply Stea Supply
STEAM GROUP
Stea Supply Stea Supply
324
IN-GAME
1,384
ONLINE
Founded
October 3, 2017
Why do bots want my API Key?
Hi,

To start off, thank you so much for the service so far all these years!
I've been using steam.supply for a solid 3-4 years to level every major sale. Many hundreds of my keys have gone to good use (efficient leveling) thanks to your site.

But one thing's got me worried right about now. This winter sale, I noticed there's multiple bots now asking for your "Steam Trade API Key". They will say something like Due to recent Steam changes, we are unable to load your inventory anymore. Before to use some commands, you must first set up your own API Key. The first part is quite obviously a flat-out lie, as most of the other bots can still load my inventory just fine. And yet they will not trade with me without said key. So, what's the catch?

Because this looked super fishy to me, I started looking online and informing myself. And basically, from what I could gather, giving anyone your key is a massive risk, as this gives anyone with your API key full access to your trades... While having this key doesn't immediately allow one to take your items, it does allow them to see your trades, intercept one if it looks profitable, and then send you a fake trade offer to get your items instead of the intended target (Sources that prove this possibility: One[forums.steamrep.com] and Two[https//%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5%E2%99%A5], plenty more if you search)

I've also gotten into contact with at least one bot owner who very honestly told me it's so they don't need to pay for the API if they have your key (To protect this bot owner I won't name them, but I can provide proof in private if it's requested and absolutely needed). So while it might not be as ill-meant as written above, it's still a huge risk.

To summarize: It saves bot owners a quick buck at the cost of your own safety.

While one of the bots (the honest one, bless him) was willing to switch over their strategy again to the classic ways which most other bots use, I've also had a run-in with an owner who absolutely doubled down into this key thing, removing my comments, accusing me of not knowing anything, and saying "I could just revoke access to the key after I'm done trading". Yeah, that's cool and all, but apart from that being a hassle, if every bot is going to do this, my key is pretty much always floating around somewhere, and therefore I will be under constant risk. Yes, they really did say this, and then they removed their comment once I called them out on it, which I think is very suspicious, non-transparent and anti-consumer of them. Here is proof of this interaction.[imgur.com]

Now I'm definitely not an expert, and please let me know if I'm missing any information!!! But to me, this development sounds like a very anti-consumer strategy, and I've immediately solidified my position to NEVER give anyone my key; and to boy-cot any bots who use this strategy. But I'm worried that this might become a trend, as I've now already spotted at least 4 bots forcing you to hand over your key.

My question to you is: What is Steam Supply's stance on this? Sure, I wouldn't call them scam bots like the other obvious scam bots from the past, but I definitely can't appreciate how intrusive these bots are now, expecting you to give over API keys that give them full access to stuff. If every bot starts using this strategy, saving money on API costs at the costs of consumer safety, I fear for the worst. Having your key float around puts you under constant risk of the key falling in the hands of bad actors, them intercepting a trade, and then scamming you. The more bots you give the key, the bigger the risk. If this becomes a bigger trend, will Steam Supply allow it? Turn a blind eye, or will this become looked down upon, or report-able in a way?

Thanks again and yours sincerely,

Mike
Last edited by MikedeKokkie; Jan 3, 2023 @ 5:45pm
< >
Showing 1-10 of 10 comments
Calling the owner of the site so he can reply...

But as long as any of us is scamming anyone (as we are well-kown bots listed in the site for years already) and you can choose which bot use or not I do not see why we should not being allowed.

Remeber that you can revoke apikey in the same page where you create it, right after the trade. Also, there are 54654654 csgo sites asking for API Key since ages, i.e. BUFF136.
And the most important thing, you must blame valve and not us for the change. if you think we are doing mad money to cover the cost of all those proxies daily, most of us we are not unfortunately...

Anyway, you need 2FA being able to confirm any trade and the API Key gives you NOT access to that, yeah if you think a bot can stole your items bu having your API Key, we cannot.

Cheers
MikedeKokkie Jan 3, 2023 @ 4:48pm 
Feel free to call the site owner, I'd love to get their opinion/two cents on this honestly. If I as a long-time consumer have genuine concerns with proof, I see reason for them to care.

Sure, YOU aren't scamming anyone. But the more bots have my key floating around, the higher the chance it falls into the wrong hands. It's so simple, you cannot disagree with it.

Again with the API revoking. I see how that cleans your own hands of any dirty-doing, but unfortunately if every bot starts asking for keys this is just going to be either a major hassle or a constant layer of risk. Should I make a new key after every trade just to be safe? Madness.

I will agree we can blame Valve for slow inventories. But this is not the solution. I've never used third-party CSGO (gambling) sites, and I never will, so apologies if this is my first interaction with API Keys. But this is not CSGO, and just because they decided to use more intrusive methods doesn't mean you can too. All the other bots work fine even with the slowness sometimes. So don't tell me you can't work with this either.

"if you think a bot can stole your items bu having your API Key, we cannot." I did not say that. I've educated myself, read my main post again. Of course, 2FA is always needed and having the key will not bypass it. But if a scam bot intercepts my trade because they have my key, then 2FA will not save me, I will just accept the trade. That's how API scams work.

Still don't appreciate you removing my comments (and even your own comment!), so just in case you are wondering why I made this thread, there you go. You made it look too suspicious.

Cheers back
Last edited by MikedeKokkie; Jan 3, 2023 @ 4:55pm
You should add me and ask instead alarming people on bot profile.
Anyway, this is not the right forum anymore. Replied to you in the other Group as well.
Last edited by Jack Nolddor // ⇄ TF2 Keys; Jan 3, 2023 @ 5:00pm
MikedeKokkie Jan 3, 2023 @ 5:00pm 
Yep, saw it. Double posted just to be sure. Will reply there from now on. https://steamcommunity.com/groups/SteamDotSupply/discussions/0/3732953986131771327/
Last edited by MikedeKokkie; Jan 3, 2023 @ 5:00pm
Originally posted by MikedeKokkie:
Yep, saw it. Double posted just to be sure. Will reply there from now on.
Oka, contacted site owner myself. He just told me to reply to you tomorrow was busy right now.
MikedeKokkie Jan 3, 2023 @ 5:05pm 
Originally posted by Jack Nolddor // ⇄ TF2 Keys:
Originally posted by MikedeKokkie:
Yep, saw it. Double posted just to be sure. Will reply there from now on.
Oka, contacted site owner myself. He just told me to reply to you tomorrow was busy right now.

I'll await his reply then. Sorry for not adding you and asking directly but with you removing my comments, not adding me either to talk (it's a two way street!) and to this moment defending this system, which I saw as a suspicious, I thought this was the next best option. Please remember, I posted this to gather info and ask for opinions, not to cause a witch hunt to you.
Last edited by MikedeKokkie; Jan 3, 2023 @ 5:07pm
All good from my side.
MikedeKokkie Jan 3, 2023 @ 5:12pm 
:pureloveheart:
. Jan 3, 2023 @ 5:13pm 
No longer in control of this group do not trust any replies from steam.supply on it as they could be impersonators with no way of banning / deleting there comments
. Jan 3, 2023 @ 5:13pm 
i'll read and reply to the other group's post
< >
Showing 1-10 of 10 comments
Per page: 1530 50

Date Posted: Jan 3, 2023 @ 3:47pm
Posts: 10