Skip to content
MicrockPublic

Repository files navigation

Vapora

an OSINT tool for exploring public Steam friend networks.

MIT license Stars Issues


tl;dr

map a Steam user's friend network, find communities and hubs, and export Gephi-ready CSVs plus a probable-friends report.

  • download Vapora. Windows has an installer and a portable EXE; Linux has an AppImage; macOS has a DMG.
  • get a Steam API key.
  • open the app, paste your key using the key button, then enter a Steam profile URL or ID.
  • choose your depth and node cap, then Analyze. Start with the defaults: depth 2, 500 accounts.
  • inspect Results, or open the output folder and import the CSVs into Gephi.

the classic green Steam scan interface


features

  • classic Steam UI, with profile pictures, saved runs and a browser version.
  • Steam IDs, profile URLs and vanity names.
  • depth 1-5, optional node cap and request pacing, with retries. Set Nodes or Requests/min to 0 to remove that limit.
  • estimate before scanning; cancel and resume without starting over.
  • an explicit Skip private profiles checkbox, with missing data shown in the report.
  • communities, degree, betweenness and hubs; searchable graphs and profile inspection.
  • probable-friend rankings from mutuals, Jaccard, shared groups and shared games.
  • saved settings, offline reranking and Gephi-ready exports.
  • automatic SteamHistory loading, a full historical viewer, dated captures and comment ranking.

network exploration and profile inspection

Screenshots use local fixture profiles. Rankings and location signals are heuristics, not proof of real-life relationships or residence. Vapora uses the Steam Web API and does not bypass privacy.


installation

desktop

No Node.js or Python installation needed. Get the file for your system from the latest release:

System Download Open it
Windows x64 installer run the installer
Windows x64 portable EXE run it from a writable folder
Linux x64 AppImage make executable, then open
macOS Apple Silicon DMG drag Vapora into Applications

Portable runs and settings live in Vapora-data beside the EXE. Move both together. Installed-app data lives in the OS app-data directory under Vapora. Use a session key, or opt into Remember API key when secure OS storage is available. Keys never appear in reports.

Downloads are unsigned and not notarized. Check the release's SHA256SUMS.txt before approving an OS warning. Linux without FUSE can use --appimage-extract-and-run.

browser / CLI / from source

Install Node.js 24+ and Python 3.10+ for the one-time history-runtime build, then:

git clone https://github.com/Microck/vapora.git
cd vapora
npm ci
npm run build
npm run build:history
npm start -- serve

Open the printed local address. For a desktop window from source, use npm run desktop. For the CLI, set STEAM_API_KEY in .env or your environment:

npm start -- scan 'https://steamcommunity.com/id/example' --preset inner
npm start -- recent
npm start -- resume RUN_ID

See the usage guide for commands, settings, data locations and troubleshooting.


how it works

  1. resolve the target through Steam, then walk public friendships breadth first.
  2. save a checkpoint after each completed scan unit, so interrupted runs can resume.
  3. build the friendship graph and calculate communities, centrality and ranking signals.
  4. write reports and CSVs to a unique run folder.
outputs/<run-id>/
├─ scan.json
├─ analysis.json
├─ probable-friends.csv
├─ run.log
└─ gephi/
   ├─ nodes.csv
   └─ edges.csv

Attached history also adds history.json. Missing observations and node-cap limits stay visible in the report.

gephi how-to

  1. import gephi/nodes.csv as a nodes table.
  2. import gephi/edges.csv as undirected edges.
  3. filter Kind to friend; inspect group links separately.
  4. run ForceAtlas2, color by modularity_class, and size by betweenness or degree.

CSV columns, ranking details and history imports.


development

npm run verify
VAPORA_BROWSER=/path/to/chrome npm run test:e2e
npm run package

Core CI checks Linux, Windows and macOS. Desktop CI launches the packaged downloads before release. See the product contract, history verification report and release runbook.

This is the TypeScript + Effect app. The original Python implementation stays on legacy, with its 1.0.2 release.


license

mit © microck. See LICENSE.

Releases

Packages

Used by

Contributors

Languages