Duo signs users in through a Generic SSO OpenID Connect application. Authdog uses the standard authorize, token, and userinfo endpoints on the issuer Duo gives that application.

Use a Generic OIDC application. Duo Universal Prompt is a different protocol and is not this connector.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Duo**, and click **Enable**. Copy the redirect URI shown in the form:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Create the application

1. In the Duo Admin Panel, add a **Generic OIDC** SSO application.
2. Set the redirect URI to the value copied from Authdog.
3. Grant the scopes `openid`, `profile`, and `email`.
4. Copy the **Client ID** and **Client secret**.
5. Open the application's OIDC metadata and copy the `issuer` value. That issuer, without `/.well-known/openid-configuration`, is the Domain URI.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | The client identifier from the Duo application |
| **Client Secret** | The client secret from the Duo application |
| **Domain URI** | The OIDC issuer, e.g. `https://sso-abc1def2.sso.duosecurity.com/oidc/DIXXXXXXXXXXXXXXXXXX` |

Save, then toggle the connection **active**.

## What Duo returns

Authdog requests the `openid profile email` scopes and reads the profile from `<issuer>/userinfo`.

The userinfo endpoint returns `sub`, name, and email claims for the authenticated user.

Paste the issuer itself as the Domain URI, not the authorize URL and not the well-known metadata URL.

## Test it

1. Open your environment's hosted sign-in page, or link to `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select the Duo button and complete the flow.
3. Confirm the user appears under **Users** in the console with a Duo identity linked.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `invalid_client` | Client ID or secret from a different Duo application |
| Redirect or callback URL error | The URI registered with Duo does not match Authdog's exactly |
| 404 on authorize | The Domain URI is not the OIDC issuer |
| Works in one environment only | Each environment has its own `connectionId`, and so its own redirect URI to register |

## Related

| Read | To learn how to |
| --- | --- |
| [Connectors](/docs/connectors) | Set up any other social provider |
