Duo Security Phones API

Phone device management

OpenAPI Specification

duo-security-phones-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Duo Admin Bulk Phones API
  description: The Duo Admin API provides programmatic access to the administrative functionality of Duo Security for managing
    users, groups, phones, hardware tokens, WebAuthn credentials, integrations, and bypass codes. Requests are authenticated
    using HMAC-SHA1 signed HTTP Basic credentials derived from your integration key and secret key.
  version: v1
  contact:
    name: Duo Security
    url: https://duo.com/docs/adminapi
  x-provenance:
    method: derived
    authored_by: API Evangelist
    derived_on: '2026-08-19'
    first_party: false
    provider_published: false
    source: Modelled from the provider's public HTML documentation.
    note: 'Not published by the provider. Probed 2026-08-19: no anonymously fetchable first-party contract. api.duosecurity.com
      answers 200 with an identical 130,977-byte HTML shell for invented paths — a soft 404, not a spec.'
servers:
- url: https://api-XXXXXXXX.duosecurity.com
  description: Duo Admin API host (replace XXXXXXXX with your tenant identifier)
security:
- basicAuth: []
tags:
- name: Phones
  description: Phone device management
paths:
  /admin/v1/users/{user_id}/phones:
    parameters:
    - name: user_id
      in: path
      required: true
      schema:
        type: string
    get:
      operationId: listUserPhones
      summary: List user phones
      tags:
      - Phones
      responses:
        '200':
          description: Successful response
    post:
      operationId: associateUserPhone
      summary: Associate phone with user
      tags:
      - Phones
      responses:
        '200':
          description: Phone associated
  /admin/v1/users/{user_id}/phones/{phone_id}:
    parameters:
    - name: user_id
      in: path
      required: true
      schema:
        type: string
    - name: phone_id
      in: path
      required: true
      schema:
        type: string
    delete:
      operationId: disassociateUserPhone
      summary: Disassociate phone from user
      tags:
      - Phones
      responses:
        '200':
          description: Phone disassociated
components:
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: HTTP Basic with HMAC-SHA1 signed credentials (integration key as user, signed signature as password).
externalDocs:
  description: Duo Admin API Documentation
  url: https://duo.com/docs/adminapi