<div dir="ltr">My colleague needs to leverage our existing IdP-AWS integration for scripted logins to use AWS APIs.  The script provided by AWS at <br><a href="https://aws.amazon.com/blogs/security/how-to-implement-a-general-solution-for-federated-apicli-access-using-saml-2-0/">https://aws.amazon.com/blogs/security/how-to-implement-a-general-solution-for-federated-apicli-access-using-saml-2-0/</a><br>works for users who do *not* use Duo in the IdP, but it does not extend to those with Duo enabled because it does not know to consume and provide appropriate responses as user agent to the Duo prompts for choice of 2nd factor (push, phone, key, etc.).<div><br></div><div>We're hoping someone here has successfully done such integration and is willing to share how you did it.</div><div><br></div><div>David Bantz</div><div>UA OIT IAM<br><br></div></div>