an OSINT tool for exploring public Steam friend networks.
map a Steam user's friend network, find communities and hubs, and export Gephi-ready CSVs plus a probable-friends report.
- download Vapora. Windows has an installer and a portable EXE; Linux has an AppImage; macOS has a DMG.
- get a Steam API key.
- open the app, paste your key using the key button, then enter a Steam profile URL or ID.
- choose your depth and node cap, then Analyze. Start with the defaults: depth 2, 500 accounts.
- inspect Results, or open the output folder and import the CSVs into Gephi.
- classic Steam UI, with profile pictures, saved runs and a browser version.
- Steam IDs, profile URLs and vanity names.
- depth 1-5, optional node cap and request pacing, with retries. Set Nodes or Requests/min to 0 to remove that limit.
- estimate before scanning; cancel and resume without starting over.
- an explicit Skip private profiles checkbox, with missing data shown in the report.
- communities, degree, betweenness and hubs; searchable graphs and profile inspection.
- probable-friend rankings from mutuals, Jaccard, shared groups and shared games.
- saved settings, offline reranking and Gephi-ready exports.
- automatic SteamHistory loading, a full historical viewer, dated captures and comment ranking.
Screenshots use local fixture profiles. Rankings and location signals are heuristics, not proof of real-life relationships or residence. Vapora uses the Steam Web API and does not bypass privacy.
No Node.js or Python installation needed. Get the file for your system from the latest release:
| System | Download | Open it |
|---|---|---|
| Windows x64 | installer | run the installer |
| Windows x64 | portable EXE | run it from a writable folder |
| Linux x64 | AppImage | make executable, then open |
| macOS Apple Silicon | DMG | drag Vapora into Applications |
Portable runs and settings live in Vapora-data beside the EXE. Move both together. Installed-app data lives in the OS app-data directory under Vapora. Use a session key, or opt into Remember API key when secure OS storage is available. Keys never appear in reports.
Downloads are unsigned and not notarized. Check the release's SHA256SUMS.txt before approving an OS warning. Linux without FUSE can use --appimage-extract-and-run.
Install Node.js 24+ and Python 3.10+ for the one-time history-runtime build, then:
git clone https://github.com/Microck/vapora.git
cd vapora
npm ci
npm run build
npm run build:history
npm start -- serveOpen the printed local address. For a desktop window from source, use npm run desktop. For the CLI, set STEAM_API_KEY in .env or your environment:
npm start -- scan 'https://steamcommunity.com/id/example' --preset inner
npm start -- recent
npm start -- resume RUN_IDSee the usage guide for commands, settings, data locations and troubleshooting.
- resolve the target through Steam, then walk public friendships breadth first.
- save a checkpoint after each completed scan unit, so interrupted runs can resume.
- build the friendship graph and calculate communities, centrality and ranking signals.
- write reports and CSVs to a unique run folder.
outputs/<run-id>/
├─ scan.json
├─ analysis.json
├─ probable-friends.csv
├─ run.log
└─ gephi/
├─ nodes.csv
└─ edges.csv
Attached history also adds history.json. Missing observations and node-cap limits stay visible in the report.
- import
gephi/nodes.csvas a nodes table. - import
gephi/edges.csvas undirected edges. - filter
Kindtofriend; inspectgrouplinks separately. - run ForceAtlas2, color by
modularity_class, and size bybetweennessordegree.
CSV columns, ranking details and history imports.
npm run verify
VAPORA_BROWSER=/path/to/chrome npm run test:e2e
npm run packageCore CI checks Linux, Windows and macOS. Desktop CI launches the packaged downloads before release. See the product contract, history verification report and release runbook.
This is the TypeScript + Effect app. The original Python implementation stays on legacy, with its 1.0.2 release.
mit © microck. See LICENSE.

