Authdog
Log In

Passwordless · Setup

Set up Duo

Duo signs users in through a Generic SSO OpenID Connect application.

Authdog uses the standard authorize, token, and userinfo endpoints on the issuer Duo gives that application. Use a Generic OIDC application. Duo Universal Prompt is a different protocol and is not this connector.

Copy the redirect URI

In the Authdog console, select the project and environment, open Authentication > Providers, find Duo, and click Enable. Copy the redirect URI shown in the form:

https://identity.authdog.com/api/v1/callback/<connectionId>

Create the application

  1. In the Duo Admin Panel, add a Generic OIDC SSO application.
  2. Set the redirect URI to the value copied from Authdog.
  3. Grant the scopes openid, profile, and email.
  4. Copy the Client ID and Client secret.
  5. Open the application's OIDC metadata and copy the issuer value. That issuer, without /.well-known/openid-configuration, is the Domain URI.

Configure Authdog

Field Value
Client ID The client identifier from the Duo application
Client Secret The client secret from the Duo application
Domain URI The OIDC issuer, e.g. https://sso-abc1def2.sso.duosecurity.com/oidc/DIXXXXXXXXXXXXXXXXXX

Save, then toggle the connection active.

What Duo returns

Authdog requests the openid profile email scopes and reads the profile from <issuer>/userinfo.

The userinfo endpoint returns sub, name, and email claims for the authenticated user.

Paste the issuer itself as the Domain URI, not the authorize URL and not the well-known metadata URL.

Test it

  1. Open your environment's hosted sign-in page, or link to https://identity.authdog.com/api/v1/signin/<connectionId>.
  2. Select the Duo button and complete the flow.
  3. Confirm the user appears under Users in the console with a Duo identity linked.

Troubleshooting

Symptom Cause
invalid_client Client ID or secret from a different Duo application
Redirect or callback URL error The URI registered with Duo does not match Authdog's exactly
404 on authorize The Domain URI is not the OIDC issuer
Works in one environment only Each environment has its own connectionId, and so its own redirect URI to register
Read To learn how to
Connectors Set up any other social provider