Duo Mobile icon

Duo Mobile MFA Data API: Endpoints and Fields

Cisco Systems, Inc. · Identity

Duo Mobile is Cisco Systems' authenticator for Duo Security, the enterprise multi-factor product Cisco acquired in 2018. On the account-list screen users keep one card per enrolled Duo tenant, each showing a rotating HOTP or TOTP passcode; a push notification opens an approve-or-deny prompt that can require a step-up code, GPS, Bluetooth proximity or a biometric PIN. Around that prompt the app enrolls a phone by scanning a QR activation code, reconnects or restores accounts when a handset is replaced (instant restore and encrypted Google backup), surfaces security alerts when an authentication factor is added or an identity-verification inquiry starts, and supports passwordless Windows logon over Bluetooth plus a trusted-endpoint check for inline browser authentication. Cisco sells Duo to IT teams that protect VPN, SSO and SaaS logins; the listing here covers the US, where Duo is headquartered, and the app sits alongside Microsoft Authenticator, Okta Verify, Google Authenticator and Twilio Authy in the workplace MFA category.

Pending sign-in approvals anchor the dataset: each request is keyed by urgId and the phone's pkey, and carries a summary, a type, an expirationSec window and an optional stepUpCodeInfo challenge. The device-status call adds tenant policy and posture — os_status, integrity_status, require_mdm, has_trusted_endpoints — alongside account chrome such as customer_name and customer_logo.

Security-alert rows report who changed an authentication factor — username, ipAddress, authFactorType, canQuarantine — with changeType values such as new_auth_device or identity_verification, and identity-verification inquiries attach an identityVerificationId. Phone-replacement recovery exchanges ir_nonce for encrypted_hotp_key and can be cut off at revocationDeadline. SOC pipelines, MDM inventory and identity-governance tools consume those fields; openData Studio turns them into callable open data.

Screenshots

  • Duo Mobile screenshot 1
  • Duo Mobile screenshot 2
  • Duo Mobile screenshot 3
  • Duo Mobile screenshot 4
  • Duo Mobile screenshot 5
  • Duo Mobile screenshot 6

API surface

The endpoints and request/response examples below are reconstructed from the app's interface — illustrative, not a live capture.

  • Activate a Duo account on this phone

    POST /v1/enrollment/activate osint

    Exchanges a scanned activation code for the phone's pkey, HMAC akey, HOTP/TOTP secret and tenant chrome (customer_name, logo, card colour) that seed every later device call.

    Auth: Unauthenticated enrollment. The activation code from the QR / email link is submitted in the request body with customer_protocol=1. The response akey is the HMAC secret and pkey the phone id used to sign later device calls.

    • stat
    • pkey
    • akey
    • hotp_secret
    • use_totp
    • customer_name
    • customer_logo
    • customer_logo_md5
    • card_accent_color
    • current_app_version
    • current_os_version
    • app_status
    • os_status
    • admin
    • force_disable_analytics
    • has_trusted_endpoints
    • instant_restore_status
    • integrity_nonce
    • security_checkup_enabled
    • auth_mute_duration
    • auth_mute_expiration
    POST /v1/enrollment/activate HTTP/1.1
    Content-Type: application/json
    
    {
      "activation_code": "abc123def456",
      "customer_protocol": 1,
      "app_id": "com.duosecurity.duomobile",
      "app_version": "4.123.0",
      "platform": "Android",
      "os_version": "14",
      "manufacturer": "Google",
      "model": "Pixel 8",
      "jailbroken": false,
      "full_disk_encryption": true
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ",
        "akey": "9f8e7d6c5b4a39281706f5e4d3c2b1a09876543210",
        "hotp_secret": "JBSWY3DPEHPK3PXP",
        "use_totp": true,
        "customer_name": "Contoso",
        "customer_logo": "https://logo.example/contoso.png",
        "customer_logo_md5": "5d41402abc4b2a76b9719d911017c592",
        "card_accent_color": "#6B4C9A",
        "current_app_version": "4.123.0",
        "current_os_version": "14",
        "app_status": 1,
        "os_status": 1,
        "admin": 0,
        "force_disable_analytics": false,
        "has_trusted_endpoints": true,
        "instant_restore_status": "enrolled",
        "integrity_nonce": "n-8f21c0aa",
        "security_checkup_enabled": true,
        "auth_mute_duration": 0,
        "auth_mute_expiration": 0.0
      }
    }
  • Read enrolled-device info and tenant policy

    GET /v1/devices/status opendata

    Returns the enrolled phone's pkey, urg_token, tenant policy flags (require_mdm, has_trusted_endpoints, security_checkup_enabled) and posture statuses (app_status, os_status, integrity_status).

    Auth: HMAC-SHA1 of the request signed with the account akey; the authorization header is attached once a Duo account is enrolled, and pkey identifies the phone. The urg_token from a previous status or activation response may also attach. Device telemetry (app_id, platform, jailbroken, full_disk_encryption) is sent with the call.

    • stat
    • pkey
    • akey
    • urg_token
    • customer_name
    • customer_logo
    • app_status
    • os_status
    • integrity_status
    • integrity_nonce
    • new_keys_required
    • require_mdm
    • has_trusted_endpoints
    • has_device_change_feature
    • instant_restore_status
    • security_checkup_enabled
    • use_totp
    • admin
    • force_disable_analytics
    GET /v1/devices/status HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ",
        "akey": "9f8e7d6c5b4a39281706f5e4d3c2b1a09876543210",
        "urg_token": "urg-7f2c91aa",
        "customer_name": "Contoso",
        "customer_logo": "https://logo.example/contoso.png",
        "customer_logo_md5": "5d41402abc4b2a76b9719d911017c592",
        "card_accent_color": "#6B4C9A",
        "current_app_version": "4.123.0",
        "current_os_version": "14",
        "app_status": 1,
        "os_status": 1,
        "integrity_status": 1,
        "integrity_nonce": "n-8f21c0aa",
        "new_keys_required": 0,
        "require_mdm": 0,
        "has_trusted_endpoints": true,
        "has_device_change_feature": true,
        "instant_restore_status": "enrolled",
        "security_checkup_enabled": true,
        "use_totp": true,
        "admin": 0,
        "force_disable_analytics": false,
        "auth_mute_duration": 0,
        "auth_mute_expiration": 0.0
      }
    }
  • Register the FCM push token

    POST /v1/devices/push-token opendata

    Uploads the Firebase Cloud Messaging token stored as gcm_token (prefixed GCM:) so Duo can deliver login-request and security-alert pushes to this handset.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. Sent after the platform push service issues a new token.

    • stat
    • pkey
    • gcm_token
    • platform
    • app_version
    POST /v1/devices/push-token HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "gcm_token": "GCM:cXyzFcmRegistrationToken",
      "platform": "Android",
      "app_version": "4.123.0"
    }
    {
      "stat": "OK"
    }
  • List pending MFA push transactions

    GET /v1/auth-requests osint

    Pages the outstanding login-request pushes for this phone: each entry carries id (urgId), summary, type, expirationSec, step-up digit count and organisation/user attribute triples.

    Auth: HMAC-SHA1 signed with the account akey; pkey identifies the phone.

    • stat
    • current_time
    • transactions
    • id
    • txid
    • summary
    • type
    • expirationSec
    • requireSecondAuth
    • mustRotateOnApprove
    • stepUpCodeInfo
    • numDigits
    • requireGps
    • isProximityPush
    • isStrictProximityPush
    • passwordlessOsLoginId
    • attributes
    GET /v1/auth-requests HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "current_time": 1770000000,
        "transactions": [
          {
            "id": "urg-aa11bb22",
            "txid": "tx-998877",
            "summary": "Login to VPN from Chrome on macOS",
            "type": "auth",
            "expirationSec": 60,
            "requireSecondAuth": false,
            "mustRotateOnApprove": false,
            "blockBiometricPinFallback": false,
            "isProximityPush": false,
            "isStrictProximityPush": false,
            "requireGps": false,
            "passwordlessOsLoginId": null,
            "passwordlessOsOfflineEnrollment": null,
            "stepUpCodeInfo": { "numDigits": 2 },
            "attributes": [
              [["Organization", "Contoso"], ["Application", "VPN"]],
              [["username", "[email protected]"], ["location", "Austin, TX"]],
              []
            ]
          }
        ]
      }
    }
  • Fetch one MFA push transaction

    GET /v1/auth-requests/{requestId} osint

    Loads a single pending login request by urgId so the approve/deny screen can render summary, type, step-up digits and the organisation/user attribute triples.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. The urgId comes from the push payload or the pending-requests list.

    • stat
    • current_time
    • transaction
    • id
    • txid
    • summary
    • type
    • expirationSec
    • requireSecondAuth
    • mustRotateOnApprove
    • blockBiometricPinFallback
    • stepUpCodeInfo
    • numDigits
    • attributes
    GET /v1/auth-requests/urg-aa11bb22 HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "current_time": 1770000000,
        "transaction": {
          "id": "urg-aa11bb22",
          "txid": "tx-998877",
          "summary": "Login to Office 365",
          "type": "auth",
          "expirationSec": 60,
          "requireSecondAuth": true,
          "mustRotateOnApprove": true,
          "blockBiometricPinFallback": true,
          "isProximityPush": false,
          "isStrictProximityPush": false,
          "requireGps": false,
          "passwordlessOsLoginId": null,
          "stepUpCodeInfo": { "numDigits": 2 },
          "attributes": [
            [["Organization", "Contoso"], ["Application", "Office 365"]],
            [["username", "[email protected]"], ["browser", "Edge"]],
            []
          ]
        }
      }
    }
  • Approve or deny an MFA push

    POST /v1/auth-requests/{requestId}/decision osint

    Writes the user's approve/deny (and optional step_up_code) for a pending login. On passwordless OS logon the response returns passwordlessOsLoginEncryptedSecret and the wrapped offline key.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. Posted when the user taps Approve, Deny or enters a step-up code on the sign-in prompt.

    • stat
    • pkey
    • answer
    • step_up_code
    • step_up_code_autofilled
    • remediationBody
    • remediationTitle
    • passwordlessOsLoginId
    • passwordlessOsLoginEncryptedSecret
    • passwordlessOsOfflineWrappedSymmetricKey
    POST /v1/auth-requests/urg-aa11bb22/decision HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "answer": "approve",
      "step_up_code": "14",
      "step_up_code_autofilled": false
    }
    {
      "stat": "OK",
      "response": {
        "remediationBody": null,
        "remediationTitle": null,
        "passwordlessOsLoginId": null,
        "passwordlessOsLoginEncryptedSecret": null,
        "passwordlessOsOfflineWrappedSymmetricKey": null
      }
    }
  • List authentication-factor security alerts

    GET /v1/security-events osint

    Returns outstanding security alerts (auth-factor added/removed, identity verification) with actor username, ipAddress, location and whether the user can quarantine the change.

    Auth: HMAC-SHA1 signed with the account akey; pkey identifies the phone.

    • stat
    • notifications
    • notificationID
    • changeType
    • expiration
    • time
    • username
    • location
    • ipAddress
    • authFactorName
    • authFactorType
    • phoneNumber
    • canQuarantine
    • ssoEmail
    • identityVerificationId
    GET /v1/security-events HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "notifications": [
          {
            "notificationID": "n-44cc55dd",
            "changeType": "new_auth_device",
            "expiration": 1770003600,
            "info": {
              "time": 1770000000.0,
              "username": "[email protected]",
              "location": "Austin, TX",
              "ipAddress": "203.0.113.10",
              "authFactorName": "Hardware token",
              "authFactorType": "token",
              "phoneNumber": null,
              "canQuarantine": true,
              "ssoEmail": "[email protected]",
              "identityVerificationId": null
            }
          }
        ]
      }
    }
  • Fetch one security alert

    GET /v1/security-events/{eventId} osint

    Loads a single security-alert row by notificationID, including identityVerificationId when the alert is an identity-verification inquiry.

    Auth: HMAC-SHA1 signed with the account akey; pkey identifies the phone.

    • stat
    • notificationID
    • changeType
    • expiration
    • username
    • location
    • ipAddress
    • ssoEmail
    • canQuarantine
    • identityVerificationId
    GET /v1/security-events/n-44cc55dd HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "notificationID": "n-44cc55dd",
        "changeType": "identity_verification",
        "expiration": 1770003600,
        "info": {
          "time": 1770000000.0,
          "username": "[email protected]",
          "location": "Austin, TX",
          "ipAddress": "203.0.113.10",
          "authFactorName": null,
          "authFactorType": null,
          "phoneNumber": null,
          "canQuarantine": false,
          "ssoEmail": "[email protected]",
          "identityVerificationId": "inq_8e21c0"
        }
      }
    }
  • Start handling a security alert

    POST /v1/security-events/{eventId}/begin osint

    Marks a security alert as in_progress and returns status plus expiresAt so the factor-change or identity-verification flow can proceed before the window closes.

    Auth: HMAC-SHA1 signed with the account akey; pkey identifies the phone.

    • stat
    • pkey
    • status
    • expiresAt
    POST /v1/security-events/n-44cc55dd/begin HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ"
    }
    {
      "stat": "OK",
      "response": {
        "status": "in_progress",
        "expiresAt": 1770003600.0
      }
    }
  • Reply to a security alert

    POST /v1/security-events/{eventId}/respond osint

    Writes the user's approve / deny / quarantine decision for an authentication-factor change or identity-verification alert.

    Auth: HMAC-SHA1 signed with the account akey; pkey identifies the phone.

    • stat
    • pkey
    • answer
    • can_quarantine
    POST /v1/security-events/n-44cc55dd/respond HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "answer": "approve",
      "can_quarantine": true
    }
    {
      "stat": "OK"
    }
  • Enroll the phone in instant restore

    POST /v1/recovery/enroll osint

    Registers this handset's instant-restore public key (new_ir_pubkey) so a replacement phone can later reactivate the same Duo account without a new QR code.

    Auth: HMAC-SHA1 signed with the account akey; pkey identifies the phone.

    • stat
    • pkey
    • new_ir_pubkey
    • public_key_version
    • instant_restore_status
    POST /v1/recovery/enroll HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "public_key_version": 1
    }
    {
      "stat": "OK",
      "response": {
        "instant_restore_status": "enrolled",
        "pkey": "DPABC123XYZ"
      }
    }
  • Start an instant-restore handshake

    POST /v1/recovery/handshake osint

    Opens the instant-restore handshake: the replacement phone sends ir_nonce and new_ir_pubkey and receives new_ir_nonce before encrypted_hotp_key can be delivered.

    Auth: HMAC-SHA1 signed with restore material from the old phone or the encrypted backup; used before reactivation.

    • stat
    • pkey
    • ir_nonce
    • new_ir_nonce
    • new_ir_pubkey
    • public_key_version
    • instant_restore_status
    POST /v1/recovery/handshake HTTP/1.1
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "ir_nonce": "irn-0a1b2c3d",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "public_key_version": 1
    }
    {
      "stat": "OK",
      "response": {
        "new_ir_nonce": "irn-9f8e7d6c",
        "instant_restore_status": "started"
      }
    }
  • Reactivate an account via Android instant restore

    POST /v1/recovery/reactivate-mobile osint

    Reactivates a Duo account on a new Android handset and returns the new pkey plus encrypted_hotp_key so TOTP/HOTP generation can resume.

    Auth: HMAC-SHA1 signed with the restore material from the old phone / encrypted backup; the response issues a new pkey.

    • stat
    • pkey
    • encrypted_hotp_key
    • use_totp
    • new_ir_pubkey
    • platform
    • app_version
    POST /v1/recovery/reactivate-mobile HTTP/1.1
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "platform": "Android",
      "app_version": "4.123.0"
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPNEW456XYZ",
        "encrypted_hotp_key": "U2FsdGVkX1+encryptedHotpKey==",
        "use_totp": true
      }
    }
  • Reactivate via cross-platform instant restore

    POST /v1/recovery/reactivate osint

    Reactivates a Duo account on a replacement handset (non-Android-specific path) and returns the new pkey plus encrypted_hotp_key so TOTP/HOTP generation can resume.

    Auth: HMAC-SHA1 signed with the restore material from the old phone / encrypted backup; the response issues a new pkey. Sibling of the mobile-specific reactivation call; both return the same payload.

    • stat
    • pkey
    • encrypted_hotp_key
    • use_totp
    • ir_nonce
    • new_ir_nonce
    • new_ir_pubkey
    • public_key_version
    POST /v1/recovery/reactivate HTTP/1.1
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "ir_nonce": "irn-0a1b2c3d",
      "new_ir_nonce": "irn-9f8e7d6c",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "public_key_version": 1
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPNEW456XYZ",
        "encrypted_hotp_key": "U2FsdGVkX1+encryptedHotpKey==",
        "use_totp": true
      }
    }
  • Revoke a pending instant restore

    POST /v1/recovery/cancel osint

    Cancels a pending auto-restore / reactivation from the old handset and returns revocationDeadline (wire revocation_deadline) after which the restore window closes.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the still-enrolled old phone.

    • stat
    • pkey
    • revocationDeadline
    • revocation_deadline
    POST /v1/recovery/cancel HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ"
    }
    {
      "stat": "OK",
      "response": {
        "revocationDeadline": 1770086400.0
      }
    }
  • Rotate the HOTP/TOTP secret

    POST /v1/credentials/rotate osint

    Issues a new encrypted_hotp_secret after an approve that required rotation, replacing the passcode seed stored on the phone.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. Triggered when a sign-in request has mustRotateOnApprove or the device status sets new_keys_required.

    • stat
    • pkey
    • pubkey
    • encrypted_hotp_secret
    POST /v1/credentials/rotate HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ",
        "encrypted_hotp_secret": "U2FsdGVkX1+rotatedHotpSecret=="
      }
    }
  • Check the phone's HOTP/TOTP key

    POST /v1/credentials/verify osint

    Proves this handset still holds the expected key material (pubkey) without rotating it; used when the device status sets new_keys_required or before a rotation.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. Runs alongside the credential-rotation call.

    • stat
    • pkey
    • pubkey
    POST /v1/credentials/verify HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ"
      }
    }
  • Submit a Play Integrity attestation

    POST /v1/devices/attestation opendata

    Posts a Play Integrity attestation minted against the integrity_nonce so the tenant can set integrity_status and refuse pushes from a compromised handset.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. The attestation nonce and pkey come from the integrity_nonce on the device-status response.

    • stat
    • pkey
    • nonce
    • integrity_status
    POST /v1/devices/attestation HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "nonce": "n-8f21c0aa"
    }
    {
      "stat": "OK",
      "response": {
        "integrity_status": 1,
        "pkey": "DPABC123XYZ"
      }
    }
  • Verify a trusted endpoint for inline auth

    POST /v1/devices/trust-check osint

    Checks whether the browser/device origin is a trusted endpoint. Returns trusted_endpoint, optional bypass_auth, origin_check_failure_reason and the inline-auth transaction when a login is attached.

    Auth: HMAC-SHA1 signed with akey; pkey identifies the phone. Used from the inline browser sign-in flow when has_trusted_endpoints is true.

    • stat
    • trusted_endpoint
    • bypass_auth
    • origin_check_failure_reason
    • urgid
    • current_time
    • transaction
    • id
    • txid
    • summary
    • trusted_endpoints_uri
    POST /v1/devices/trust-check HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "trusted_endpoints_uri": "https://access.example/trusted"
    }
    {
      "stat": "OK",
      "response": {
        "trusted_endpoint": true,
        "bypass_auth": false,
        "origin_check_failure_reason": null,
        "urgid": "urg-aa11bb22",
        "current_time": 1770000000,
        "transaction": {
          "id": "urg-aa11bb22",
          "txid": "tx-998877",
          "summary": "Inline login from Chrome",
          "type": "auth",
          "expirationSec": 60,
          "requireSecondAuth": false,
          "attributes": []
        }
      }
    }

Data categories

  • mfa_transactions
  • device_posture
  • security_alerts
  • account_enrollment

Where teams use this data

  • SOC stream of MFA approve/deny

    A SIEM connector pages pending transactions by urgId and records each approve or deny together with summary, type, username attributes and step_up_code presence, so analysts can correlate Duo pushes with VPN and SSO logs.

  • MDM posture gate

    An MDM or device-compliance job reads app_status, os_status, integrity_status, require_mdm, jailbroken and full_disk_encryption from device info and Play Integrity, then blocks access when a handset fails the tenant's bar.

  • Auth-factor change watch

    Identity-governance tooling consumes security-alert rows (changeType, ipAddress, authFactorType, canQuarantine, identityVerificationId) to ticket unexpected hardware-token adds or to drive a Persona inquiry when identity verification is required.

  • Replacement-phone restore

    An IT onboarding playbook enrolls instant restore on the old handset, starts the handshake (ir_nonce / new_ir_nonce) on the replacement phone, reactivates to recover pkey and encrypted_hotp_key, or revokes the window before revocationDeadline if the old phone is still in hand.

Frequently asked questions

What identifies a Duo phone after enrollment?

Activation returns pkey (the phone id) and akey (the HMAC secret). Later device calls sign with akey and send pkey; the device-status call also returns urg_token for subsequent request fetches.

Which fields describe a pending MFA login?

Each request has id (urgId), txid, summary, type, expirationSec, requireSecondAuth, stepUpCodeInfo.numDigits and nested organisation/user attribute triples. Approve or deny posts answer plus an optional step_up_code.

Does the app expose device-posture data?

Yes. The device-status call returns app_status, os_status, integrity_status, require_mdm, has_trusted_endpoints and instant_restore_status. Play Integrity posts an attestation against integrity_nonce so the tenant can refuse a compromised handset. Phone replacement can be started, reactivated or revoked (revocationDeadline).

What are security alerts in Duo Mobile?

The security-events feed lists factor-change and identity-verification events with notificationID, changeType (new_auth_device, removed_auth_device, password_reset, bypass_code_generated, identity_verification), username, ipAddress, location, authFactorType, canQuarantine and identityVerificationId. The user begins the flow, then responds approve, deny or quarantine.

Apps similar to Duo Mobile

  • Microsoft Authenticator — Microsoft's authenticator generates TOTP codes, sends push approvals, and supports passwordless sign-in and passkeys for Microsoft accounts and Entra ID work or school accounts.
  • Google Authenticator — Google's authenticator implements TOTP and HOTP so that, when signing in to Google or a supported third-party site, the app shows a six- to eight-digit one-time password.
  • Twilio Authy — Twilio Authy is a two-factor app that stores one-time codes with online backup after the user registers a phone number, and it runs on Android and iOS.
  • Okta Verify — Okta's MFA app confirms sign-in to Okta accounts and Okta-protected apps via push notification or a one-time code, and it can also serve as a third-party authenticator for sites such as GitHub, Facebook, or Google.
  • PingID — Ping Identity's workforce MFA product protects SSO apps with methods such as mobile push, email or SMS OTP, TOTP authenticator apps, QR codes and FIDO2, and it integrates with Azure AD, AD FS, Windows login, Mac login and SSH.
  • RSA SecurID — RSA SecurID is a two-factor system in which a hardware or software token generates a new authentication code at a fixed interval for signing in to a network resource.

Topics

  • Duo Mobile API
  • Cisco Duo MFA endpoints
  • MFA sign-in requests urgId
  • Duo pkey akey
  • Duo security alerts
  • Duo phone restore
  • Play Integrity Duo
  • trusted endpoint Duo

Need this app's data API integrated?

We deliver scoped integrations for any named app — from USD 500 with source-code handoff, or hosted access billed per call. Tell us the data you need.

  • NDA + SOW on every engagement
  • Delivery in 3–7 days
  • Payment only after acceptance
  • Work scoped to authorized use

Get a quote