duo.com
Duo is Cisco’s cloud identity security platform for multi-factor authentication, single sign-on, device trust, and related access-control features. It is used by organizations to protect application, VPN, desktop, and web access with strong authentication and policy enforcement.
Duo exposes four documented developer-facing HTTP integration surfaces: the Auth API, Admin API, OIDC Auth API, and Duo Single Sign-On as an OAuth/OIDC provider (including MCP-oriented docs); all require Duo-issued application credentials created in the Duo Admin Panel. No public GraphQL API, MCP server endpoint, or first-party general-purpose developer CLI was found on duo.com.
- Duo Auth APIdiscovered
- Duo Single Sign-On OIDC/OAuth providerdiscovered
In the Duo Admin Panel, go to Applications → Application Catalog, add the application/integration you need, and copy the generated ikey (integration key) and skey (secret key). The Protecting Applications guide documents creating applications, and the Getting Started guide confirms Auth API and Web SDK access.
In the Duo Admin Panel, create a Duo OIDC/OAuth application for either the OIDC Auth API / Web SDK or Duo Single Sign-On. Copy the client_id, client_secret (for confidential clients), issuer/hostname metadata, and configure the allowed redirect URI(s). The MCP/OIDC setup guide and OIDC SSO guide document registering clients in Duo.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://duo.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing