Skip to main content
Glama
WYRE-AI

Cisco Duo MCP Server

by WYRE-AI

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
DUO_IKEYNoDuo integration key.
DUO_SKEYNoDuo secret key (HMAC-SHA512 signing secret).
AUTH_MODENoAuthentication mode: env (default) reads DUO_IKEY/DUO_SKEY/DUO_API_HOST; gateway receives credentials per-request via X-Duo-Ikey/X-Duo-Skey/X-Duo-Api-Host headers.env
LOG_LEVELNoLogging level: debug, info, warn, error.info
DUO_API_HOSTNoThis account's Duo API hostname.
MCP_TRANSPORTNoTransport type: stdio (default) or http.stdio
CONDUIT_S2S_SECRETNoWhen set, the HTTP transport requires a valid X-Gateway-S2S header on every /mcp request.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{}
logging
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
duo_list_usersA

List users in the Duo account, optionally filtered by exact username. Returns user metadata (user_id, username, email, status, realname, phone/created timestamps) - PII, classified isAdmin.

duo_get_userA

Get full detail for a single user by user_id, including status and enrolled-factor summary.

duo_list_user_groupsB

List the groups a user belongs to.

duo_list_user_phonesA

List the phones enrolled to a user (number, platform/OS, capabilities - PII).

duo_list_user_tokensA

List the hardware tokens enrolled to a user (type, serial - never the token's secret seed, which is stripped).

duo_list_user_webauthn_credentialsA

List the WebAuthn credentials (security keys, platform authenticators) enrolled to a user. Never returns private key material.

duo_list_user_u2f_tokensA

List the legacy U2F security keys enrolled to a user. Never returns private key material.

duo_list_phonesB

List phones in the Duo account, optionally filtered by number/extension. Returns phone metadata (phone_id, number, platform/OS, type - PII).

duo_get_phoneA

Get full detail for a single phone by phone_id.

duo_list_hardware_tokensA

List hardware tokens (HOTP/TOTP/YubiKey) in the Duo account, optionally filtered by type/serial. Never returns a seed/secret.

duo_get_hardware_tokenA

Get full detail for a single hardware token by token_id.

duo_list_desktop_tokensB

List Duo Desktop tokens (platform, name, status).

duo_get_desktop_tokenA

Get full detail for a single Duo Desktop token by desktoptoken_id.

duo_list_groupsA

List groups in the Duo account (group_id, name, description, status).

duo_get_groupB

Get full detail for a single group by group_id.

duo_list_group_usersC

List the users belonging to a group.

duo_list_integrationsA

List integrations configured in the Duo account (integration_key, name, type, status). Metadata only - secret keys are stripped before this tool ever returns a response.

duo_get_integrationA

Get full metadata for a single integration by integration_key. Metadata only - secret keys are stripped before this tool ever returns a response.

duo_get_authentication_logA

Get the authentication log (v2) - every MFA authentication event, filterable by time range. mintime/maxtime are Unix epoch milliseconds. Paginate with next_offset (pass back the comma-joined pair from the previous response's metadata.next_offset).

duo_get_administrator_logA

Get the administrator log (v1) - actions taken by Duo administrators in this account.

duo_get_telephony_logA

Get the telephony log (v2) - phone call/SMS credit usage events. Paginate with next_offset (pass back the comma-joined pair from the previous response's metadata.next_offset).

duo_check_credentialsA

Validate that the configured Duo credentials (ikey/skey/api host) are correct and the Auth API is reachable. Side-effect-free - does not initiate any MFA transaction.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.5/5.0

Scored across 22 tools

Disambiguation4/5

Each tool targets a distinct Duo resource and action, and the list/get pairing is clear. Some pairs like duo_list_user_phones vs duo_list_phones could be confused, but the descriptions consistently clarify user-specific vs account-wide scope.

Naming Consistency5/5

All tool names follow the same duo_<verb>_<resource> pattern using only list/get verbs and snake_case. There is no mixed casing, vague verb usage, or naming drift across the set.

Tool Count4/5

22 tools is somewhat heavy, but the count maps cleanly to Duo's major resource types and each list/get pair is justified. It stays within a reasonable range for a broad admin-focused server.

Completeness2/5

The surface is thorough for read-only inventory and log retrieval, but it contains zero create, update, delete, enroll, or unenroll operations. This leaves significant gaps for actual Duo administration and will cause failures for management workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues