Cisco Duo MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DUO_IKEY | No | Duo integration key. | |
| DUO_SKEY | No | Duo secret key (HMAC-SHA512 signing secret). | |
| AUTH_MODE | No | Authentication mode: env (default) reads DUO_IKEY/DUO_SKEY/DUO_API_HOST; gateway receives credentials per-request via X-Duo-Ikey/X-Duo-Skey/X-Duo-Api-Host headers. | env |
| LOG_LEVEL | No | Logging level: debug, info, warn, error. | info |
| DUO_API_HOST | No | This account's Duo API hostname. | |
| MCP_TRANSPORT | No | Transport type: stdio (default) or http. | stdio |
| CONDUIT_S2S_SECRET | No | When set, the HTTP transport requires a valid X-Gateway-S2S header on every /mcp request. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
| logging | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| duo_list_usersA | List users in the Duo account, optionally filtered by exact username. Returns user metadata (user_id, username, email, status, realname, phone/created timestamps) - PII, classified isAdmin. |
| duo_get_userA | Get full detail for a single user by user_id, including status and enrolled-factor summary. |
| duo_list_user_groupsB | List the groups a user belongs to. |
| duo_list_user_phonesA | List the phones enrolled to a user (number, platform/OS, capabilities - PII). |
| duo_list_user_tokensA | List the hardware tokens enrolled to a user (type, serial - never the token's secret seed, which is stripped). |
| duo_list_user_webauthn_credentialsA | List the WebAuthn credentials (security keys, platform authenticators) enrolled to a user. Never returns private key material. |
| duo_list_user_u2f_tokensA | List the legacy U2F security keys enrolled to a user. Never returns private key material. |
| duo_list_phonesB | List phones in the Duo account, optionally filtered by number/extension. Returns phone metadata (phone_id, number, platform/OS, type - PII). |
| duo_get_phoneA | Get full detail for a single phone by phone_id. |
| duo_list_hardware_tokensA | List hardware tokens (HOTP/TOTP/YubiKey) in the Duo account, optionally filtered by type/serial. Never returns a seed/secret. |
| duo_get_hardware_tokenA | Get full detail for a single hardware token by token_id. |
| duo_list_desktop_tokensB | List Duo Desktop tokens (platform, name, status). |
| duo_get_desktop_tokenA | Get full detail for a single Duo Desktop token by desktoptoken_id. |
| duo_list_groupsA | List groups in the Duo account (group_id, name, description, status). |
| duo_get_groupB | Get full detail for a single group by group_id. |
| duo_list_group_usersC | List the users belonging to a group. |
| duo_list_integrationsA | List integrations configured in the Duo account (integration_key, name, type, status). Metadata only - secret keys are stripped before this tool ever returns a response. |
| duo_get_integrationA | Get full metadata for a single integration by integration_key. Metadata only - secret keys are stripped before this tool ever returns a response. |
| duo_get_authentication_logA | Get the authentication log (v2) - every MFA authentication event, filterable by time range. mintime/maxtime are Unix epoch milliseconds. Paginate with next_offset (pass back the comma-joined pair from the previous response's metadata.next_offset). |
| duo_get_administrator_logA | Get the administrator log (v1) - actions taken by Duo administrators in this account. |
| duo_get_telephony_logA | Get the telephony log (v2) - phone call/SMS credit usage events. Paginate with next_offset (pass back the comma-joined pair from the previous response's metadata.next_offset). |
| duo_check_credentialsA | Validate that the configured Duo credentials (ikey/skey/api host) are correct and the Auth API is reachable. Side-effect-free - does not initiate any MFA transaction. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 22 tools
Each tool targets a distinct Duo resource and action, and the list/get pairing is clear. Some pairs like duo_list_user_phones vs duo_list_phones could be confused, but the descriptions consistently clarify user-specific vs account-wide scope.
All tool names follow the same duo_<verb>_<resource> pattern using only list/get verbs and snake_case. There is no mixed casing, vague verb usage, or naming drift across the set.
22 tools is somewhat heavy, but the count maps cleanly to Duo's major resource types and each list/get pair is justified. It stays within a reasonable range for a broad admin-focused server.
The surface is thorough for read-only inventory and log retrieval, but it contains zero create, update, delete, enroll, or unenroll operations. This leaves significant gaps for actual Duo administration and will cause failures for management workflows.