Security & Identity · Integration

Duo Security

Add Duo Security to your product for your customers, and give your AI agents governed access to it.

Embed a Duo Security integration so your customers can work their own users, groups, enrolled devices, and authentication activity from inside your product, with governed agent access to the same records. Each customer grants access to their own Duo tenant, permissions are scoped per tenant, and every call is recorded, so an access change can be traced to its source. Only the scopes required for the actions you enable are requested, because the blast radius of a mistake here is large.

Start freeBook a demo

In your product

Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.

Let customers read their own Duo users, groups, and enrolled devices into your product.

Read authentication events so sign-in activity appears in your product's own audit view.

Update user or group state from your product as part of a governed access workflow.

Trigger your product when an authentication is denied or a device enrolment changes.

For your AI agents

Governed, audited access for the agents you build, through the MCP server.

An agent reviews a user's recent authentication activity before an access decision is made.

An agent changes a user's group or status within governed, least-privilege permissions.

An agent reacts to a denied authentication and raises it to the right owner.

Example prompt

List users with denied authentications in the last 24 hours and show which device and group each belongs to.

Set up Duo Security in 4 steps

  1. 01Open the Duo Security connector from your fastn dashboard.
  2. 02Have each customer authenticate their Duo tenant with least-privilege credentials.
  3. 03Map the users, groups, and events your product uses, then enable actions and triggers.
  4. 04Call them from your product, or expose them to an agent through the MCP server.

Why teams use the Duo Security integration

What you get by embedding it with fastn instead of building it yourself.

  • Ship a Duo Security integration without building it. Your customers connect their own Duo Security account inside your product and work their users, groups and roles there, with no per-customer code on your side.
  • Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Duo Security update is not your on-call problem.
  • One integration serves your product and your agents. The same governed Duo Security connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.

Used by these teams

Security & IT

Compare with

Okta

Works well with

ServiceNowGitHub

Often used alongside

Tools the same teams tend to run next to Duo Security, across other categories.

DatadogPagerDutyAWS CloudWatchAWS Security Hub

Duo Security integration FAQ

How do I add a Duo Security integration to my product?

Enable the Duo Security connector in your fastn dashboard, then let each customer authenticate their own Duo Security account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Duo Security client code in your app and no per-customer branch in your codebase. Setup is 4 steps.

Do my customers each connect their own Duo Security account?

Yes. Every connection is scoped to the individual customer, so each authorises their own Duo Security account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.

Can AI agents use this Duo Security integration?

Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent reviews a user's recent authentication activity before an access decision is made.

Who maintains the Duo Security integration?

fastn does. When Duo Security changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.

What permissions does the Duo Security integration need?

Only the scopes required for the actions you enable. Each customer grants access to their own Duo Security tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.

Can access changes be automated safely?

Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.

What can I build with the Duo Security integration?

A common starting point: read their own Duo users, groups, and enrolled devices into your product. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.

How much does the Duo Security integration cost?

It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Duo Security does not change your per-connector cost. You can start free with 3 connected accounts.

Add Duo Security to your product

Start free with 3 connected accounts. No sales call required, and no per-customer integration code.

Start freeRead the docs
← All integrations