duo-client
Reference client for Duo Security APIs
Decision gist · record as of 2026-08-14
Yes. Duo-client is actively maintained, has low install friction, carries no known vulnerabilities, and is the official library for Duo Security integration. Install it if you need to integrate Duo authentication or identity management into a Python application. The activity endpoint is in public preview, so verify its stability for your use case if you plan to rely on it.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires valid Duo Security API credentials (integration key, secret key, and API host) to authenticate with Duo's services.
- Low install friction with a single pure-Python dependency (setuptools).
- Actively maintained with a recent release 169 days ago and ongoing repository activity.
License · maintenance · safety
BSD (permissive) — BSD permissive license allows use in both open-source and proprietary projects with minimal restrictions.
last release 2026-02-26 (169 days) · last repo commit 2026-07-27 · 150 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 600,207 downloads/mo, #5,822 on PyPI
Alternatives
Verify before relying
pip install duo-client
import duo_client
# Example: initialize an Admin API client
admin_api = duo_client.Admin(
ikey='your_integration_key',
skey='your_secret_key',
host='api-xxxxxxxx.duosecurity.com'
)- Whether the activity endpoint preview is stable enough for production use, given its documented 'subject to change' status.
- Performance characteristics and rate-limiting behavior for high-volume API calls.
- Whether all four API modules (Auth, Admin, Accounts, Activity) are equally mature and production-ready.
What it is and what it does
Duo-client is the official Python reference implementation for Duo Security's cloud-based authentication and identity management APIs. It provides a unified interface to interact with Duo's Auth API (for authentication flows), Admin API (for user and device management), Accounts API (for account configuration), and Activity API (currently in public preview). The library handles HTTP communication, request signing, and response parsing, abstracting away the low-level details of Duo's REST endpoints.
The package is designed for developers integrating Duo's two-factor authentication or identity services into Python applications—whether for building custom authentication workflows, managing users and devices programmatically, or querying activity logs. It supports Python 3.7 and higher, uses TLS 1.2/1.3 via Python's ssl module and OpenSSL, and has minimal dependencies, making it straightforward to add to existing projects.
Use it for
- Build custom authentication flows by integrating Duo's Auth API into a web application or service.
- Automate user and device provisioning by managing Duo accounts programmatically via the Admin API.
- Query and audit authentication activity and user behavior through the Activity API.
- Implement multi-factor authentication for internal tools or third-party integrations.
- Sync user directories or device inventories with Duo's backend via bulk Admin API operations.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Duo-client is actively maintained, has low install friction, carries no known vulnerabilities, and is the official library for Duo Security integration. Install it if you need to integrate Duo authentication or identity management into a Python application. The activity endpoint is in public preview, so verify its stability for your use case if you plan to rely on it.
Install
duo-client on PyPI
Before you install
Low install friction with a single pure-Python dependency (setuptools). Actively maintained with a recent release 169 days ago and ongoing repository activity. Tested against Python 3.7 through 3.12.
Requires valid Duo Security API credentials (integration key, secret key, and API host) to authenticate with Duo's services.
License in practice
BSD permissive license allows use in both open-source and proprietary projects with minimal restrictions.
Quickstart
pip install duo-client
import duo_client
# Example: initialize an Admin API client
admin_api = duo_client.Admin(
ikey='your_integration_key',
skey='your_secret_key',
host='api-xxxxxxxx.duosecurity.com'
)
Verify before relying
- Whether the activity endpoint preview is stable enough for production use, given its documented 'subject to change' status.
- Performance characteristics and rate-limiting behavior for high-volume API calls.
- Whether all four API modules (Auth, Admin, Accounts, Activity) are equally mature and production-ready.
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagesetuptools |
| Maintenance | Actively maintained 169 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 600,207 / month, #5,822 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: BSD LicenseProgramming Language :: Python |
Evidence: duo_client-5.6.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “duo security api client”
- duo-clientPython client library for Duo Security's authentication, admin,…
- authentik-clientA Python client library for the authentik identity and access…
- dlintDlint is a flake8 plugin that adds security-focused and best-practice…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also authentik-client · google-reauth · django-allauth-2fa · googleauthentication · supertokens-python · gcloud-rest-auth · dj-rest-auth · django-two-factor-auth · google-auth-oauthlib · streamlit-authenticator