Skip to main content
Connector guides

Connect Cisco Duo

Cisco Duo is a multi-factor authentication and identity-security platform. StackJack connects to it through Duo's two published APIs — the Admin API, which manages your Duo directory, and the Auth…

Written By Christopher Scaminaci

Last updated 6 days ago

Cisco Duo is a multi-factor authentication and identity-security platform. StackJack connects to it through Duo's two published APIs — the Admin API, which manages your Duo directory, and the Auth API, which performs authentications — covering users, phones, hardware tokens, passkeys, desktop authenticators, groups, policies, protected applications, administrators, authentication logs, Trust Monitor, custom branding, and MSP subaccounts.

Connecting Duo to StackJack gives your AI assistant a broad family of duo_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Audit your directory — users and their enrolled devices, groups, bypass codes, passkeys, desktop authenticators, and endpoints
  • Investigate authentications — read authentication, activity, telephony, administrator and offline-enrollment logs, plus Trust Monitor events
  • Review policy and posture — list policies, retrieve any policy or the global policy, and calculate the effective policy that actually applies
  • Report on the account — utilization summaries, telephony credits used, and authentication-attempt reports
  • Manage the directory (on Pro plans) — create and modify users, phones, tokens, groups, administrators and administrative units; associate and disassociate devices; block and unblock registered devices
  • Manage configuration (on Pro plans) — protected applications, policies, global settings, Passport, and the draft/live custom-branding workflow
  • Run authentications (on Pro plans, with the Auth API configured) — pre-authenticate a user, send a Duo Push or place a phone callback, validate a passcode, and enroll a new user
  • Administer subaccounts (on Pro plans) — list, create and delete MSP subaccounts and set their edition and telephony credits

How StackJack authenticates to Cisco Duo

Duo does not issue access tokens. Instead, every request is signed individually: StackJack computes a signature from the request itself using your secret key, and Duo verifies it. There is nothing to expire, nothing to refresh, and no consent screen — but it does mean two things matter.

Duo's Admin API and Auth API are two separate applications. Each is created independently in the Duo Admin Panel and each has its own integration key and secret key. They are not interchangeable: entering one application's keys in the other's fields is the most common setup mistake, and Duo reports it as a permission error rather than an invalid-key error. StackJack accepts either or both:

  • The Admin API pair powers everything that reads or manages your Duo directory, policies, applications, logs and reports. Add this one first.
  • The Auth API pair is optional and powers the authentication family (pre-authentication, push, passcode, phone callback, enrollment and status polling). Add it only if you want your AI to run authentications.

The API hostname is specific to your account. It looks like api-abc12345.duosecurity.com. Copy it exactly as it appears in the Duo Admin Panel — it is not a region you choose, and it cannot be worked out from an integration key.

Because each request is signed with a timestamp, Duo rejects requests whose clock is far from its own. StackJack handles this for you, but a badly wrong server clock is worth ruling out if every Duo tool suddenly fails to authenticate at once.

Permissions are set per application

Duo application permissions are independent of your own administrator role. A correctly signed request can still be refused because the application it came from was never granted that permission. When you create the Admin API application you tick the permissions it may use — reads and writes for resources such as users, phones and policies; log reading; settings; administrator management; identity verification; and the subaccount permissions if you are an MSP. Grant only what the tools you intend to use require.

Duo also validates the signature before applying any source-IP restriction you have configured. That ordering is useful to know: a request that is correctly signed but refused because it came from an unknown IP address can be a sign that your secret key has leaked.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In Duo: you need an administrator with the Owner role — only an Owner can create or modify an Admin API application.
  • Plan requirements: the Admin API is included with Duo Essentials, Advantage and Premier, and with new Advantage or Premier trials. The Auth API is additionally available to Duo Free and trial accounts. Some individual endpoints still require a specific edition.

Step 1 — Create an Admin API application in Duo

  1. Sign in to the Duo Admin Panel as an administrator with the Owner role.
  2. Go to Applications → Application Catalog.
  3. Locate Admin API and click + Add.

Step 2 — Grant the permissions you need

On the new application's page, tick the permissions matching the tools you plan to use — for example resource read and write for users, phones and policies; log reading for the authentication and activity logs; settings for global settings and branding; and the administrator permissions for managing administrators and administrative units. MSPs administering subaccounts also need the accounts and user-limit permissions.

You can widen these later, but a missing permission shows up as a refused tool call rather than a setup error, so it is worth getting right now.

Step 3 — Copy the hostname and key pair

From the application's details, copy:

  • the API hostname (for example api-abc12345.duosecurity.com),
  • the integration key, and
  • the secret key.

Treat the secret key like a password.

Step 4 (optional) — Create an Auth API application

Only needed if you want the authentication tools. Return to Applications → Application Catalog, locate Auth API with the 2FA label, click + Add, and copy that application's own integration key and secret key. It is a different application with a different key pair. Before testing, grant the users who will authenticate access to the new application; new applications do not allow active users until you set User access for selected groups or all users.

Step 5 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the Cisco Duo card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
  3. Paste the API Hostname.
  4. Paste the Admin API Integration Key and Admin API Secret Key.
  5. If you created an Auth API application, paste its Auth API Integration Key and Auth API Secret Key in the optional fields.
  6. Click Save.

What happens when you save

  • Both key pairs are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure Duo, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials with a small account read. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
  • Because Duo checks the signature before checking permissions, a validation result of "permission denied" still confirms your keys are correct — it only means the application has not been granted that particular read. StackJack treats that as valid.
  • The connector card shows the connection and validity status from then on.

When you later update the connector, leaving a secret field blank keeps the stored value, so you can change the hostname or one pair without re-entering the other.

How Duo returns results

Duo wraps every response in a status envelope, and StackJack passes it through unchanged. Two things follow from that:

  • A request can succeed at the HTTP level and still report a failure. Duo returns a status of FAIL together with a code and message when it rejects a request — a bad parameter, a policy denial, an expired code. Your AI reads that and can adjust; it is not a StackJack outage.
  • Paging differs between the logs and everything else. Ordinary lists page by a numeric offset. The authentication, activity and telephony logs instead return a cursor that must be passed back exactly as received, and they take their time ranges in milliseconds. Your AI handles this, but it is why a log query looks different from a user query.

Authentication log results have an intentional two-minute delay before new events appear, and Duo recommends requesting logs no more than once a minute. A query for the last few seconds legitimately comes back empty.

Plans and available tools

  • Free includes list and get operations across users, devices, groups, policies, applications, administrators, endpoints, Trust Monitor, logs, settings, branding and account reports, plus enrollment- and authentication-status polling.
  • Pro adds create, modify and delete operations across the directory; policy, settings, application and branding changes; device block/unblock; subaccount and billing management; and authentication actions.
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated Cisco Duo tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Duo issues account-scoped integration keys rather than per-user logins, so there is no per-user attribution — all AI traffic authenticates as the application. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note — tools that reach real people. Some Pro tools do more than change a record. Sending a Duo Push, placing a phone callback, or texting passcodes, activation codes or installation links contacts a real person's device and spends telephony credits, and Duo provides no way to recall or de-duplicate one — a repeated authentication request is also how MFA-fatigue attacks work. Separately, deleting a user is immediate and permanent and does not use Duo's restorable Trash; resetting an application's client secret breaks every client using it; restricting administrator authentication factors can lock administrators out of the Duo Admin Panel; and a handful of read tools deliberately return existing secret material. Every one of these is flagged as requiring confirmation. Scope your AI's access deliberately — use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.

Rate limits

Duo does not publish a single account-wide request quota. It does publish a per-user authentication limit — 10 authentications per user per minute on Duo Free, and 30 per user per minute on Essentials, Advantage and Premier — and per-operation limits on its bulk user endpoints. StackJack paces tool calls per tenant and honors Duo's backoff responses, so a burst is slowed rather than sent all at once. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

The per-user authentication limit is worth knowing because it is per user, not per account: repeatedly authenticating one person can hit it while your overall traffic is low. StackJack never treats a rate-limit response as a successful authentication.

Rotating or replacing the credentials

The secret keys are the recovery secrets. If you regenerate a secret key in Duo, or delete and recreate an application, the stored credential stops working. To restore access, open Connectors → Cisco Duo → Configure in StackJack, paste the new key pair, and Save. You only need to re-enter the pair that changed — leaving the other blank keeps it.

Several customers

Every customer has their own Duo account. Add one connection per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.

Troubleshooting

SymptomLikely causeWhat to do
"Saved but validation failed" right after savingA mis-typed key, the wrong API hostname, or the two key pairs entered in each other's fieldsRe-copy the hostname and the Admin pair from the application's page in Duo, and confirm the Auth pair came from the Auth API application
Every Duo tool fails to authenticate at once, having worked beforeA secret key was regenerated in Duo, or this server's clock has drifted badlyRe-enter the key pair in Connectors → Cisco Duo → Configure; if the keys are unchanged, check the server clock
One tool is refused while others succeedThe Duo application lacks that endpoint's permissionOpen the application in the Duo Admin Panel and tick the permission that tool needs
The authentication tools are refused but directory tools workThe Auth API pair is missing, or the Admin pair was entered in the Auth fieldsCreate an Auth API application in Duo and enter its key pair in the Auth fields
A log query returns nothing for the last minute or twoNormal — new authentication events are intentionally delayed about two minutesWiden the time range, and query logs no more than once a minute
A correctly configured connector is refused from some networksThe Duo application is restricted to specific source IP addressesAdd StackJack's outbound addresses to the application's allowed list (they are not published; open a support ticket to get the current addresses for your region), or remove the restriction
Write or authentication tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the Duo connector plan and check your tool selections on the MCP Setup page

Cisco Duo tools

duo_ · 174 tools · Free 78 · Pro 96

Auth API

ToolWhat it does
duo_authenticate
Pro · Destructive
Perform a real second-factor authentication: send a Duo Push, validate a passcode, place a phone callback, or send a new batch of SMS passcodes.
duo_check_integration
Free · Read-only
Validate the Auth API integration key, secret key and request signature, returning Duo's server time on success.
duo_enroll_user
Pro · Destructive
Create a new Duo user and issue activation material for a smartphone running Duo Mobile.
duo_get_app_logo
Free · Read-only
Download the logo stored on the Duo Auth API application.
duo_get_auth_status
Free · Read-only
Long-poll for the next update to an asynchronous authentication started by duo_authenticate with async="1".
duo_get_enrollment_status
Free · Read-only
Check whether activation material issued by duo_enroll_user has been claimed.
duo_ping
Free · Read-only
Check that the Duo service is reachable and return Duo's current server time as Unix seconds.
duo_preauth
Pro · Destructive
Evaluate Duo policy for a user and, when a second factor is needed, return the devices and factors they may use.

Users

ToolWhat it does
duo_bulk_create_users
Pro · Write
Create up to 100 Duo users in a single call, rate-limited by Duo to 50 calls per minute.
duo_bulk_restore_users
Pro · Destructive
Restore up to 100 users from Duo's Trash, rate-limited by Duo to 50 calls per minute.
duo_bulk_send_users_to_trash
Pro · Destructive
Move up to 100 users to Duo's Trash, where they remain pending deletion for seven days and can be brought back with duo_bulk_restore_users.
duo_create_user
Pro · Write
Create a Duo user.
duo_delete_user
Pro · Destructive
PERMANENTLY delete a Duo user, IMMEDIATELY.
duo_enroll_user_via_email
Pro · Destructive
Create a Duo user and EMAIL THEM an enrolment link so they can enroll their own device.
duo_get_user
Free · Read-only
Get one Duo user by user id, including their status, aliases, real name, email, notes, group memberships and enrolled devices.
duo_get_user_verification_push_response
Free · Read-only
Read the outcome of a verification push sent with duo_send_user_verification_push, using the push id that call returned.
duo_list_directory_syncs
Free · Read-only
List the external directory synchronizations configured for the account (for example Active Directory or Azure AD), with their keys and status.
duo_list_users
Free · Read-only
List or search Duo users.
duo_modify_user
Pro · Destructive
Modify an existing Duo user.
duo_send_user_verification_push
Pro · Destructive
Send a verification push to one of a user's enrolled phones — typically to confirm the right person holds the device before a help-desk action.
duo_sync_user_from_directory
Pro · Destructive
Synchronize a single user from an external directory immediately, instead of waiting for the scheduled sync.

User Associations

ToolWhat it does
duo_associate_group_with_user
Pro · Destructive
Add a user to a group.
duo_associate_phone_with_user
Pro · Destructive
Attach an EXISTING phone record to a user, giving them the ability to authenticate with it.
duo_associate_token_with_user
Pro · Destructive
Attach an EXISTING hardware OTP token to a user so they can authenticate with its passcodes.
duo_create_user_bypass_codes
Pro · Destructive
Generate bypass codes for a user — one-time codes that let them authenticate WITHOUT a second factor, typically to recover a lost phone.
duo_disassociate_group_from_user
Pro · Destructive
Remove a user from a group.
duo_disassociate_phone_from_user
Pro · Destructive
Detach a phone from a user, REMOVING THEIR ABILITY TO AUTHENTICATE with it.
duo_disassociate_token_from_user
Pro · Destructive
Detach a hardware OTP token from a user, removing their ability to authenticate with it.
duo_list_user_bypass_codes
Free · Read-only
List metadata about a user's bypass codes — how many exist, when they expire and how many uses remain.
duo_list_user_desktop_authenticators
Free · Read-only
List a user's Duo Desktop authenticators — the desktop devices registered for endpoint verification and offline access.
duo_list_user_groups
Free · Read-only
List the groups a user belongs to.
duo_list_user_phones
Free · Read-only
List the phones enrolled to a user, with each phone's id, number, type, platform and activation state.
duo_list_user_tokens
Free · Read-only
List the hardware OTP tokens attached to a user, with each token's id, type and serial.
duo_list_user_webauthn_credentials
Free · Read-only
List a user's WebAuthn credentials — passkeys, security keys and platform authenticators such as Touch ID or Windows Hello.

Phones

ToolWhat it does
duo_create_phone
Pro · Write
Create a phone record.
duo_create_phone_activation_code
Pro · Destructive
Generate a Duo Mobile activation code and URL for a phone and RETURN them to you.
duo_delete_phone
Pro · Destructive
Delete a phone record.
duo_get_phone
Free · Read-only
Get one phone record by id, including its number, type, platform, activation state and the users it is attached to.
duo_list_phones
Free · Read-only
List phone records in the account, with each phone's id, number, name, type, platform and activation state.
duo_modify_phone
Pro · Destructive
Modify a phone record.
duo_send_phone_sms_activation
Pro · Destructive
Generate a Duo Mobile activation code and TEXT IT to the phone.
duo_send_phone_sms_installation
Pro · Destructive
Text Duo Mobile installation instructions to a phone.
duo_send_phone_sms_passcodes
Pro · Destructive
Text a fresh batch of one-time passcodes to a phone.

Hardware Tokens

ToolWhat it does
duo_create_token
Pro · Write
Register a hardware OTP token.
duo_delete_token
Pro · Destructive
Delete a hardware OTP token.
duo_get_token
Free · Read-only
Get one hardware OTP token by id, including its type, serial and the users it is attached to.
duo_list_tokens
Free · Read-only
List hardware OTP tokens registered in the account, with each token's id, type and serial number.
duo_resync_token
Pro · Write
Resynchronize a hardware OTP token whose counter has drifted out of step with Duo, which is the usual reason a physically working token stops being accepted.

WebAuthn Credentials

ToolWhat it does
duo_delete_webauthn_credential
Pro · Destructive
Delete a WebAuthn credential — a passkey, security key or platform authenticator.
duo_get_webauthn_credential
Free · Read-only
Get one WebAuthn credential by its key, including its label, type and owning user.
duo_list_webauthn_credentials
Free · Read-only
List WebAuthn credentials across the whole account — passkeys, security keys and platform authenticators such as Touch ID or Windows Hello — with each credential's key, label and owning user.

Desktop Authenticators

ToolWhat it does
duo_create_shared_device_auth_config
Pro · Destructive
Create a shared device authentication configuration, changing how members of the named groups authenticate on shared machines.
duo_delete_desktop_authenticator
Pro · Destructive
Delete a Duo Desktop authenticator, removing that machine's registration.
duo_delete_shared_device_auth_config
Pro · Destructive
Delete a shared device authentication configuration.
duo_get_desktop_authenticator
Free · Read-only
Get one Duo Desktop authenticator by its key, including the machine's details and owning user.
duo_get_shared_device_auth_config
Free · Read-only
Get one shared device authentication configuration by its shared-device key, including whether it is active and which groups and trusted-endpoint integrations it covers.
duo_list_desktop_authenticators
Free · Read-only
List Duo Desktop authenticators — the desktop and laptop machines registered for endpoint verification and offline access.
duo_list_shared_device_auth_configs
Free · Read-only
List shared device authentication configurations — the rules that control how members of particular groups authenticate on shared machines, each tied to a set of groups and trusted-endpoint integrations.
duo_update_shared_device_auth_config
Pro · Destructive
Update a shared device authentication configuration.

Bypass Codes

ToolWhat it does
duo_delete_bypass_code
Pro · Destructive
Invalidate a bypass code immediately.
duo_get_bypass_code
Free · Read-only
Get one bypass code's metadata by id — its owning user, expiry and remaining uses.
duo_list_bypass_codes
Free · Read-only
List bypass code metadata across the whole account — which users hold codes, when they expire and how many uses remain.

Subaccounts

ToolWhat it does
duo_create_subaccount
Pro · Destructive
Create a new subaccount under this parent account and return the newly created account.
duo_delete_subaccount
Pro · Destructive
Delete a subaccount from the system.
duo_get_subaccount_edition
Free · Read-only
Get the Duo edition currently in effect for one subaccount, which determines both its feature set and its billing.
duo_get_subaccount_telephony_credits
Free · Read-only
Get the telephony credits currently available to one subaccount, returned as credits.
duo_list_subaccounts
Free · Read-only
List the subaccounts belonging to this parent account, each with its account_id (a 20-character string), name, and api_hostname.
duo_set_subaccount_edition
Pro · Destructive
Set the effective Duo edition for a subaccount.
duo_set_subaccount_telephony_credits
Pro · Destructive
Set the TOTAL number of telephony credits a subaccount will hold.

Groups

ToolWhat it does
duo_create_group
Pro · Write
Create a group.
duo_delete_group
Pro · Destructive
Delete a group.
duo_get_group
Free · Read-only
Get one group's own attributes by id — name, description and authentication status.
duo_list_group_members
Free · Read-only
List the members of a group, each as user_id and username.
duo_list_groups
Free · Read-only
List groups, each with its group_id, name, description and authentication status (Active = members must complete secondary authentication, Bypass = members skip it after primary authentication, Disabled = members cannot authenticate).
duo_update_group
Pro · Destructive
Update a group.

Identity Verification

ToolWhat it does
duo_cancel_identity_verification
Pro · Destructive
Cancel a user's in-flight identity verification.
duo_get_identity_verification_status
Free · Read-only
Get the current status of a user's most recent identity verification.
duo_start_identity_verification
Pro · Destructive
Begin Duo Identity Verification for a user, generating the access_code the user must supply to be redirected to Persona for proofing.

Bulk Operations

ToolWhat it does
duo_bulk_user_operations
Pro · Destructive
Execute a list of user operations in one request.

Endpoints

ToolWhat it does
duo_get_endpoint
Free · Read-only
Get one endpoint record by its endpoint key, including the device's detected posture and the users seen on it.
duo_list_endpoints
Free · Read-only
List endpoint records — the devices Duo has observed authenticating, along with the posture it detected such as operating system and version, browser, disk-encryption, firewall and password state, and whether Duo Desktop was present.

Registered Devices

ToolWhat it does
duo_block_device
Pro · Destructive
Block ONE registered device by its device key, immediately denying it access to every application protected by a Duo policy that requires device registration.
duo_block_devices
Pro · Destructive
Block SEVERAL registered devices at once.
duo_list_blocked_devices
Free · Read-only
List only the BLOCKED registered devices.
duo_list_registered_devices
Free · Read-only
List registered devices — the devices enrolled through Duo's device-registration flow, which policies can require before granting access.
duo_unblock_device
Pro · Destructive
Unblock ONE registered device by its device key, restoring its access to applications that require device registration.
duo_unblock_devices
Pro · Destructive
Unblock SEVERAL registered devices at once, RESTORING their access to applications that require device registration.

Trust Monitor

ToolWhat it does
duo_list_trust_monitor_events
Free · Read-only
Retrieve Trust Monitor security events — the authentications and registrations Duo itself flagged as anomalous, each with the reasons it was surfaced (for example a new country, new device, new factor, unusual network, or unrealistic geovelocity) and a link an administrator can use to triage it in the Duo Admin Panel.

Integrations

ToolWhat it does
duo_create_integration
Pro · Destructive
Create a new Duo integration (application).
duo_delete_integration
Pro · Destructive
Permanently delete a Duo integration.
duo_get_integration
Free · Read-only
Get a single Duo integration (application) by its integration key.
duo_get_integration_secret_key
Free · Read-only
Retrieve an integration's FULL secret key (skey).
duo_get_oauth_client_secret
Free · Read-only
Retrieve the existing client_secret for one client of an OAuth 2.0 Client Credentials integration.
duo_get_oidc_client_secret
Free · Read-only
Retrieve the existing client_secret for a Generic OIDC Relying Party integration.
duo_list_integrations
Free · Read-only
List the integrations (applications) protected by Duo, one page at a time.
duo_modify_integration
Pro · Destructive
Modify an existing Duo integration — its name, notes, greeting, user access, allowed groups, attached policy, prompt settings, and (on Admin API integrations) its own API permissions.
duo_reset_oauth_client_secret
Pro · Destructive
ROTATE the client_secret for one client of an OAuth 2.0 Client Credentials integration and return the new value.
duo_reset_oidc_client_secret
Pro · Destructive
ROTATE the client_secret for a Generic OIDC Relying Party integration and return the new value.

Integrations (Legacy v2)

ToolWhat it does
duo_create_integration_v2
Pro · Destructive
LEGACY handler: create a new Duo integration through the older v2 endpoint.
duo_delete_integration_v2
Pro · Destructive
LEGACY handler: permanently delete a Duo integration through the older v2 endpoint.
duo_get_integration_v2
Free · Read-only
LEGACY handler: get a single Duo integration by its integration key through the older v2 endpoint.
duo_get_oauth_client_secret_v2
Free · Read-only
LEGACY handler: retrieve the existing client_secret for one client of an OAuth 2.0 Client Credentials integration through the older v2 endpoint.
duo_get_oidc_client_secret_v2
Free · Read-only
LEGACY handler: retrieve the existing client_secret for a Generic OIDC Relying Party integration through the older v2 endpoint.
duo_list_integrations_v2
Free · Read-only
LEGACY handler: list Duo integrations (applications) through the older v2 endpoint.
duo_modify_integration_v2
Pro · Destructive
LEGACY handler: modify an existing Duo integration through the older v2 endpoint.
duo_reset_oauth_client_secret_v2
Pro · Destructive
LEGACY handler: ROTATE the client_secret for one client of an OAuth 2.0 Client Credentials integration through the older v2 endpoint, returning the new value.
duo_reset_oidc_client_secret_v2
Pro · Destructive
LEGACY handler: ROTATE the client_secret for a Generic OIDC Relying Party integration through the older v2 endpoint, returning the new value.

Policies

ToolWhat it does
duo_calculate_resulting_policy
Free · Read-only
Calculate the EFFECTIVE policy for one user and one application — what Duo will actually enforce for that pair, built from the top-most section of the entire stack of policies that applies to that integration.
duo_copy_policy
Pro · Write
Copy an existing policy into one or more NEW custom policies carrying the same settings.
duo_create_policy
Pro · Write
Create a new custom policy and return its new policy key.
duo_delete_policy
Pro · Destructive
Delete an entire custom policy.
duo_get_global_policy
Free · Read-only
Get the account's GLOBAL policy with all of its section data.
duo_get_policy
Free · Read-only
Get one policy by its policy key, including all of its section data and the applications and groups it is applied to.
duo_get_policy_summary
Free · Read-only
Summarize every policy in the account: each policy's name and key, the total policy_count, and exactly where each one is applied — the applications (by app_name and app_integration_key), whether it is attached to the whole application or to groups within it (apply_type of app or group_app), the group stacking order, and the groups themselves.
duo_list_policies
Free · Read-only
List policies with their COMPLETE section data — every enabled section and all of its keys and values, plus policy_key, policy_name, is_global_policy, created_at and updated_at (both Unix timestamps, and both blank for policies untouched since November 2023) and policy_applies_to.
duo_update_policies
Pro · Destructive
BULK-update policy section data across many policies at once — or across EVERY policy in the account.
duo_update_policy
Pro · Destructive
Update ONE policy: rename it, change its section data, and change where it is applied.

Passport

ToolWhat it does
duo_get_passport_config
Free · Read-only
Get the account's Duo Passport configuration.
duo_modify_passport_config
Pro · Destructive
Change the account's Duo Passport configuration — its enabled status and the groups it applies to.

Administrators

ToolWhat it does
duo_clear_admin_expiration
Pro · Destructive
Clear the "Expired" status Duo applies to an administrator who has been inactive too long.
duo_create_admin
Pro · Destructive
Create a new Duo Admin Panel administrator.
duo_create_admin_activation
Pro · Destructive
Create an ACCOUNT-LEVEL pending activation: a link to the Duo activation form for a BRAND-NEW administrator identified only by their EMAIL ADDRESS.
duo_create_admin_activation_link
Pro · Destructive
Create a PER-ADMIN activation link for an administrator record that ALREADY EXISTS and is in the "Pending Activation" status, identified by admin_id.
duo_delete_admin
Pro · Destructive
Permanently delete a Duo Admin Panel administrator.
duo_delete_admin_activation
Pro · Destructive
Delete an ACCOUNT-LEVEL pending administrator activation, cancelling that invitation.
duo_delete_admin_activation_link
Pro · Destructive
Delete and INVALIDATE an existing administrator's current per-admin activation link.
duo_email_admin_activation_link
Pro · Destructive
Email an existing administrator's CURRENT per-admin activation link to them.
duo_get_admin
Free · Read-only
Retrieve one Duo Admin Panel administrator by admin_id.
duo_list_admin_activations
Free · Read-only
List the ACCOUNT-LEVEL pending administrator activations — the queue of outstanding invitations created by duo_create_admin_activation — one page at a time.
duo_list_admins
Free · Read-only
List the administrators who can sign in to the Duo Admin Panel, one page at a time.
duo_modify_admin
Pro · Destructive
Change an existing administrator's name, phone, role, account status, administrative-unit restriction or hardware token.
duo_reset_admin_auth_attempts
Pro · Destructive
Clear an administrator's failed-login counter, which UNLOCKS an administrator who was disabled by too many failed authentication attempts and lets them sign in to the Duo Admin Panel again.

Admin Access

ToolWhat it does
duo_get_admin_auth_factors
Free · Read-only
Retrieve which secondary authentication factors administrators are currently permitted to use when signing in to the Duo Admin Panel.
duo_get_admin_password_mgmt
Free · Read-only
Retrieve one administrator's external password management configuration by admin_id.
duo_list_admin_password_mgmt
Free · Read-only
List every administrator with a flag showing whether their Duo Admin Panel password is managed externally, one page at a time.
duo_modify_admin_password_mgmt
Pro · Destructive
Enable or disable external password management for one administrator, and/or SET THAT ADMINISTRATOR'S DUO ADMIN PANEL PASSWORD.
duo_restrict_admin_auth_factors
Pro · Destructive
RESTRICT which secondary authentication factors administrators may use to sign in to the Duo Admin Panel.
duo_sync_admin_from_directory
Pro · Destructive
Sync ONE administrator, identified by email address, against a single configured admin directory sync — creating them, updating them, or marking them for deletion according to what the source directory (Active Directory, OpenLDAP or Entra ID) now says.

Admin Roles

ToolWhat it does
duo_get_admin_role
Free · Read-only
Retrieve assignment detail for one administrative role, standard or custom, by role_id.
duo_list_admin_roles
Free · Read-only
List every administrative role in the Duo account — the eight standard roles (owner, service_manager, application_manager, user_manager, security_analyst, help_desk, billing, read_only) and any custom roles.

Administrative Units

ToolWhat it does
duo_add_admin_to_admin_unit
Pro · Destructive
Assign an administrator to an administrative unit, WIDENING what that administrator can see by adding this unit's groups and applications to their scope.
duo_add_group_to_admin_unit
Pro · Destructive
Assign a Duo user group to an administrative unit, so every administrator restricted to that unit can see the group's users.
duo_add_integration_to_admin_unit
Pro · Destructive
Assign an application (integration) to an administrative unit, so every administrator restricted to that unit can see and manage it.
duo_create_admin_unit
Pro · Destructive
Create an administrative unit, optionally seeding the administrators, Duo groups and applications it scopes.
duo_delete_admin_unit
Pro · Destructive
Delete an administrative unit.
duo_get_admin_unit
Free · Read-only
Retrieve full detail for one administrative unit by admin_unit_id, including its members: the admins (by admin_id), groups (by group_id) and integrations (by integration_key) assigned to it, plus its name, description, restrict_by_groups and restrict_by_integrations flags.
duo_list_admin_units
Free · Read-only
List the administrative units that scope what restricted administrators can see in the Duo Admin Panel, one page at a time.
duo_modify_admin_unit
Pro · Destructive
Change an administrative unit's name, description, restriction flags and/or assigned administrators, groups and applications.
duo_remove_admin_from_admin_unit
Pro · Destructive
Unassign an administrator from an administrative unit, NARROWING what that administrator can see.
duo_remove_group_from_admin_unit
Pro · Destructive
Unassign a Duo user group from an administrative unit, removing that group's users from the view of every administrator restricted to the unit.
duo_remove_integration_from_admin_unit
Pro · Destructive
Unassign an application (integration) from an administrative unit, removing it from the view of every administrator restricted to that unit.

Logs

ToolWhat it does
duo_get_activity_logs
Free · Read-only
Retrieve account activity events — the audit trail of changes made in the Duo Admin Panel and through the Admin API.
duo_get_administrator_logs
Free · Read-only
Retrieve the administrator-action audit log — what Duo administrators did and when.
duo_get_authentication_logs
Free · Read-only
Retrieve authentication events — who authenticated, from where, with which factor, and whether it succeeded.
duo_get_offline_enrollment_logs
Free · Read-only
Retrieve offline-access enrolment and activation events for Duo Authentication for Windows Logon — which endpoints enrolled for offline access and when they used it.
duo_get_telephony_logs
Free · Read-only
Retrieve telephony events — the SMS messages and voice calls Duo has sent, including the telephony credits each consumed.

Settings

ToolWhat it does
duo_delete_account_logo
Pro · Destructive
Remove the legacy account logo from the Duo prompt and from future Duo Mobile activations.
duo_get_account_logo
Free · Read-only
Download the legacy account logo shown in the Duo prompt and Duo Mobile.
duo_get_settings
Free · Read-only
Retrieve the account's global Duo settings — the same values shown on the Settings page of the Duo Admin Panel.
duo_modify_account_logo
Pro · Destructive
Replace the legacy account logo.
duo_modify_settings
Pro · Destructive
Change global Duo settings for the whole account.

Custom Branding

ToolWhat it does
duo_add_draft_branding_user
Pro · Write
Let one Duo user preview the DRAFT custom branding.
duo_get_custom_messaging
Free · Read-only
Retrieve the custom help text and help links shown to end users in the Duo prompt — typically how to reach your help desk.
duo_get_draft_branding
Free · Read-only
Retrieve the staged DRAFT custom branding along with the users nominated to preview it.
duo_get_live_branding
Free · Read-only
Retrieve the custom branding currently LIVE for end users — the logo, background image, page background color, card accent color, the "powered by Duo" setting, and any custom SSO username label.
duo_modify_custom_messaging
Pro · Destructive
Change the custom help text and help links shown to end users in the Duo prompt.
duo_modify_draft_branding
Pro · Write
Change the DRAFT custom branding.
duo_modify_live_branding
Pro · Destructive
Change the LIVE custom branding, which EVERY END USER SEES IMMEDIATELY — there is no preview and no undo, and the previous values are replaced.
duo_publish_draft_branding
Pro · Destructive
Promote the DRAFT custom branding to LIVE.
duo_remove_draft_branding_user
Pro · Destructive
Stop one Duo user from previewing the DRAFT custom branding; they return to seeing the live branding.

Account Reports

ToolWhat it does
duo_get_account_summary
Free · Read-only
Retrieve the account utilization summary — counts of users, protected applications, administrators and telephony credits remaining.
duo_get_authentication_attempts
Free · Read-only
Report authentication attempts over a period, aggregated by result (for example successes, denials and fraud reports).
duo_get_telephony_credits_used
Free · Read-only
Report telephony credits consumed over a period — useful for spotting unexpected SMS or voice spend before credits run out.
duo_get_user_auth_attempts
Free · Read-only
Report authentication attempts over a period broken down PER USER, so you can see which people are authenticating, which are failing repeatedly, and which have not authenticated at all.