{
  "compartment_id": "section-10",
  "number": "Section 10",
  "title_local": "The Web API paradox: a rule against the automation Valve ships",
  "title_english": "The Web API paradox: a rule against the automation Valve ships",
  "source_url": "https://phishdestroy.io/steam_dossier/#api-paradox",
  "source_document": "index.html",
  "content": {
    "html": "<section class=\"border-t border-gray-800 pt-6 avoid-break\" id=\"api-paradox\">\n<div class=\"max-w-7xl mx-auto space-y-8\">\n<div class=\"section-head section-head-balanced\"><div class=\"section-head-primary\">\n<span class=\"kicker\">Part B — Rules and enforcement record · Section 10</span>\n<h2>An automation API. A rule against automation.</h2>\n\n<section class=\"dossier-note chapter-context\"><div class=\"dossier-note-title\">Context &amp; source limits</div><p class=\"chapter-context-text\">The question this section puts is how the two are reconciled: which uses of the API are authorised, by whom, and on what published criteria. No count of authorised commercial API users is estimated here, and none is implied by the absence of a published list — the absence is the finding, not a number behind it. The Steam Support messages quoted above are reproduced by the ArchiSteamFarm project in its own FAQ (verified verbatim 2026-09-22); they are not Valve publications, and the accounts they were sent to are not identified.</p></section>\n</div><div class=\"section-head-intro\"><p class=\"lede\"><b class=\"text-white\">The rule (SSA § 4.C):</b> no scripts, no bots, no non-human systems on Steam. <b class=\"text-white\">The record:</b> Valve ships a headless REST API whose entire purpose is server-to-server automation, and hands the key to any account. <strong class=\"text-white\">Users are banned for automation; the automation interface is Valve's own product.</strong> Which commercial uses are authorised has never been published.</p></div></div>\n<div class=\"grid grid-cols-1 lg:grid-cols-12 gap-6 items-start\">\n<div class=\"lg:col-span-7 bg-gray-950 border border-gray-800 rounded-lg p-8 space-y-6 relative overflow-hidden\">\n<div class=\"flex items-center gap-3 border-b border-gray-900 pb-4\">\n<div class=\"bg-purple-500/10 p-2 rounded text-purple-400 border border-purple-500/20\"><svg class=\"w-6 h-6\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path d=\"M8 9l3 3-3 3m5 0h3M5 20h14a2 2 0 002-2V6a2 2 0 00-2-2H5a2 2 0 00-2 2v12a2 2 0 002 2z\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\"></path></svg></div>\n<h3 class=\"text-xl font-black text-white uppercase tracking-wider\">The \"Game Developer\" Fallacy</h3>\n</div>\n<div class=\"grid grid-cols-1 lg:grid-cols-2 gap-4 font-mono text-xs\">\n<div class=\"bg-gray-900/50 border border-gray-800 p-4 rounded-xl\"><span class=\"text-gray-400 font-bold uppercase tracking-widest text-xs block mb-2\">Steamworks SDK (Legitimate)</span><p class=\"text-gray-400 leading-relaxed\">Used by legitimate game studios to integrate achievements, matchmaking, and leaderboards into their game clients. Requires complex C++ integration and official partner onboarding.</p></div>\n<div class=\"bg-purple-950/20 border border-purple-900/40 p-4 rounded-xl\"><span class=\"text-purple-400 font-bold uppercase tracking-widest text-xs block mb-2\">Steam Web API (The Loophole)</span><p class=\"text-gray-300 leading-relaxed\">A headless JSON/REST architecture designed for external web servers. In the hijack pattern documented here it is used to read inventories and manipulate peer-to-peer trades from remote servers; its legitimate uses are not catalogued in this dossier.</p></div>\n</div>\n<div class=\"bg-rose-950/20 border-l-4 border-rose-500 p-4 rounded text-sm text-gray-300 leading-relaxed mt-4\"><span class=\"text-rose-400 font-bold uppercase text-xs tracking-widest block mb-1\">Who the key is for</span>An ordinary Steam user has no in-client need for a Web API key; the key page lives under a developer URL and its documented purpose is external, server-side access. The archived hijack complaints describe victims who did not know the page existed until a key had been registered on their account.</div>\n</div>\n<div class=\"lg:col-span-5 space-y-6\">\n<div class=\"bg-gray-900/60 border border-gray-800 rounded-lg p-6 relative\"><h4 class=\"text-gray-200 font-mono font-bold text-xs uppercase mb-2\">The Automation Contradiction</h4><p class=\"text-[11px] text-gray-400 leading-relaxed font-mono\">SSA § 4.C provides: <span class=\"text-white\">\"You may not use any form of scripts, bots, macros, or other non-human-controlled systems ('Automation') to interact with Content and Services on Steam in any manner.\"</span> Yet the Web API endpoints (like <code class=\"text-rose-400\">CancelTradeOffer</code>) require no human UI and no captcha and bypass the Steam client entirely. The API is designed for server-to-server automation; the rule prohibits automation by users; the boundary between the two is not published.</p></div>\n<div class=\"bg-gray-950 border border-gray-700 rounded-lg p-6\"><div class=\"flex items-center gap-2 mb-3\"><h4 class=\"text-gray-200 font-mono font-bold text-sm uppercase\">A server-side position in the trade flow</h4></div><p class=\"text-xs text-gray-400 leading-relaxed mb-4\">A Web API key lets a third-party server act on the account's trades without the Steam client. In the hijack pattern, that server sits between the account holder and the trade server.</p><ul class=\"text-xs text-gray-400 font-mono space-y-2\"><li class=\"flex gap-2\"><span class=\"text-amber-500\">→</span> No trade-confirmation screen is shown for the key's actions.</li><li class=\"flex gap-2\"><span class=\"text-amber-500\">→</span> Allows background polling (GetTradeOffers).</li><li class=\"flex gap-2\"><span class=\"text-amber-500\">→</span> Cancels and re-issues offers without user interaction.</li></ul><div class=\"mt-4 pt-4 border-t border-gray-800 text-xs text-gray-300 font-mono font-bold\">Valve built the interface, prohibited user automation in its rules, and has published no criteria for which commercial uses are authorised.</div></div>\n</div>\n</div>\n</div>\n</section>"
  },
  "original_content_sha256": "5e128eefd56aca8718dbe75f911377cd9b7aad14350b4f4a9b270260aa984524",
  "author_pseudonym": "Agent Dylan",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_10_agent_dylan.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_10_agent_dylan.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_10_agent_dylan.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_10_agent_dylan.json",
    "signature_file": "steam_dossier_section_10_agent_dylan.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_10_agent_dylan.pdf",
    "sha256": "4a8672270739b3843213941d937bab9c1af2179ffe96d84d89062771f0c5e164",
    "pages": 4
  }
}
