# Duo Security (Two-Factor Authentication API) MCP for AI Agents AI Agent Connect

> Duo Security (Two-Factor Authentication API) lets you manage users and trigger MFA requests directly from your AI agent. It handles everything from user lifecycle tasks and account administration to real-time authentication checks. You can create users, restore accounts from the trash, and monitor your billing edition without leaving your chat interface.

## Overview
- **Category:** developer-tools
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_vZrSTXFunenPOtS5fqDzXaQfYS8LNoq0t0Z7onBU/ai-agent-connect
- **Tags:** 2fa, mfa, authentication, identity-management, duo-security

## Description

The Duo Security (Two-Factor Authentication API) MCP lets you manage users and trigger MFA requests directly from your AI agent. Managing identity and multi-factor authentication usually means jumping between browser tabs and digging through complex admin panels. This tool changes that by giving your AI agent direct access to your Duo Security instance. You can handle the heavy lifting of user management, like bulk creating accounts or modifying user details, through simple natural language. If you're in the middle of a security investigation, you can check authentication statuses or trigger specific factors like Duo Push or SMS passcodes instantly. It also covers the boring stuff, like checking telephony credits and managing billing editions for your sub-accounts. By connecting this through the Vinkius catalog, you move the control from a static dashboard into a conversational workflow where you just tell your agent what needs to happen. You can quickly audit your entire user directory to see who has access, or find a specific person by their email address without scrolling through endless lists. If an account needs to be suspended or a user needs to be restored from the trash, you can do it in seconds. It takes the manual labor out of security operations and puts the control back into your hands, letting you focus on high-level tasks while the AI handles the data entry.

## Tools

### list_users
Retrieve a paged list of users filtered by username, email, or user_id_list. This makes it easy to find specific people in a large organization.

### ping_auth
Perform a liveness check for the Auth API. This confirms that your connection to the Duo service is active and working.

### preauth
Determine if a user is authorized to log in and return available factors. This lets you check permissions before sending an MFA challenge.

### restore_users
Restore users from the trash. Use this to bring back users who were deleted within the last 7 days.

### set_billing_edition
Set the billing edition for an account. This allows you to upgrade or downgrade the plan for a specific sub-account.

### create_account
Create a child account for your organization. This allows you to separate different business units or clients within your Duo instance.

### create_user
Create a new user in Duo. Use this to add new team members to your directory quickly.

### delete_account
Delete a child account. This removes a specific sub-account from your managed list.

### get_billing_edition
Get the billing edition for an account. This helps you keep track of which plan a specific sub-account is on.

### get_telephony_credits
Get the telephony credits for an account. Use this to monitor your remaining balance for voice-based 2FA.

### list_accounts
Retrieve child accounts for Duo MSP partners. This gives you a full view of every managed account in your partner portal.

### modify_user
Change user details. Use this to update names, emails, or other attributes for existing users.

### set_telephony_credits
Set the telephony credits for an account. Use this to manually adjust the credit balance for your voice services.

### trash_users
Send users to trash (pending deletion for 7 days). This marks users for deletion without making the change permanent immediately.

### auth_status
Poll for the status of an asynchronous authentication request. This helps you track if a user has successfully completed their MFA challenge.

### auth
Perform second-factor authentication. Use this to trigger a Duo Push, SMS, or phone call to a specific user.

### bulk_create_users
Create up to 100 users in one request. This is the fastest way to onboard new employees or large groups of users.

### check_auth
Verify integration keys and signature generation. Use this to test your API credentials and ensure your setup is correct.

## Prompt Examples

**Prompt:** 
```
List the first 10 users from our Duo directory.
```

**Response:** 
```
I've retrieved the user list. Found users:

| Username | Status |
| :--- | :--- |
| jdoe | Active |
| asmith | Bypass |
| lking | Active |
| mrossi | Active |

Would you like to see the full details for any of these users?
```

**Prompt:** 
```
Send a Duo Push authentication request to username 'mrossi'.
```

**Response:** 
```
Authentication request sent to **mrossi** via Push.

*   **Transaction ID:** `TX123456`
*   **Status:** Pending

I'll monitor the status for you and let you know as soon as it's completed.
```

**Prompt:** 
```
Check if user 'lking' is authorized to log in and what factors they can use.
```

**Response:** 
```
User **lking** is authorized to log in. Here are the available factors:

*   Duo Push
*   Phone Call
*   SMS Passcode

Which one would you like me to trigger?
```

## Capabilities

### Trigger Duo Push or SMS
Send instant multi-factor authentication challenges to your users.

### Bulk Create Users
Provision up to 100 new users in a single request.

### Check Auth Status
Poll for real-time results of asynchronous authentication requests.

### Restore Deleted Users
Bring users back from the trash into your active directory.

### Monitor Billing and Credits
Track telephony credits and billing editions for all sub-accounts.

## Use Cases

### Rapid Team Onboarding
Use bulk_create_users to set up 50 new employee accounts in one go when a new department launches.

### Suspicious Login Investigation
Use preauth to see which factors a user has and auth to trigger a Duo Push to verify their identity during a security alert.

### MSP Account Auditing
Use list_accounts to get a full overview of every child account managed within your Duo partner portal.

### Accidental Deletion Recovery
Use restore_users to bring back a staff member who was accidentally moved to the trash during a cleanup.

## Benefits

- Audit your entire user directory in seconds using list_users to see exactly who has access without manual searching.
- Speed up employee onboarding by using bulk_create_users to provision dozens of accounts in a single step.
- Respond to security incidents faster by using auth_status to poll for real-time login results and MFA completions.
- Keep your directory clean by using trash_users and restore_users to manage the user lifecycle without permanent mistakes.
- Monitor your overhead easily by checking get_billing_edition and get_telephony_credits on demand for every sub-account.

## How It Works

The bottom line is you get a conversational interface for your Duo Security admin tools.

1. Subscribe to the Connector on the Vinkius marketplace.
2. Enter your Duo API Hostname, Integration Key, and Secret Key.
3. Ask your AI client to list users, trigger a push, or check your billing.

## Frequently Asked Questions

**Can I use the Duo Security MCP to manage my users through an AI agent?**
Yes, this Connector connects your Duo Security instance to your AI agent. You can use natural language to create, modify, and list users, making it much faster than using the web console.

**How does the Duo Security MCP handle multi-factor authentication?**
It allows your agent to trigger specific MFA factors like Duo Push, SMS, or phone calls. You can also check the real-time status of these requests.

**Can I use Duo Security MCP to check my billing and telephony credits?**
Yes, it can retrieve your current billing edition and telephony credits for your accounts, helping you monitor your usage without leaving your chat.

**Does the Duo Security MCP support bulk user creation?**
It does. You can use the tool to create up to 100 users in a single request, which is ideal for large-scale onboarding.

**What happens if I accidentally delete a user in Duo Security?**
The Connector includes a tool to restore users from the trash, allowing you to quickly recover any accounts deleted within the last 7 days.

**Is the Duo Security MCP safe for my company's identity management?**
It uses your existing Duo API credentials to perform actions. It gives your agent the ability to do exactly what you can do in the admin panel, but through a conversational interface.

**Can I trigger a Duo Push notification for a specific user?**
Yes. Use the `auth` tool and set the `factor` to 'push'. You can provide either the `username` or `user_id` to target the correct person.

**How do I check which authentication factors are available for a user?**
Run the `preauth` tool with the user's details. It will return whether the user is authorized and a list of supported factors like push, phone, or SMS.

**Is it possible to change a user's status to 'bypass' or 'disabled'?**
Yes, the `modify_user` tool allows you to update the `status` field to 'active', 'bypass', or 'disabled' using the user's unique ID.