Skip to main content

Overview

Windsurf supports MCP servers in its Cascade agent. This guide adds Ocean as a remote MCP server so Cascade can query threats, metrics, phishing reports, and allow/deny lists. For connection details and the full tool catalog, see the MCP Server Overview.

Prerequisites

  • Windsurf installed.
  • MCP access enabled for your tenant.
  • An Ocean account to sign in with — or, if you’re using the API key method, an Ocean API key (see Authentication).

Add the server

In the Cascade panel, open the … (Actions) menu, go to MCPs, and click Open MCP config file — or edit the file directly:
  • macOS / Linux: ~/.config/devin/mcp_config.json
  • Windows: %APPDATA%\devin\mcp_config.json
mcp_config.json
Windsurf prompts you to sign in the first time the server is used; complete the browser sign-in with your Ocean account and approve the access it asked for.
OAuth access to Ocean is read-only. If you need the allow/deny write tools, use an API key instead — see Authentication.

Add with an API key

Put your API key in the headers block instead:
mcp_config.json

Verify the connection

1

Check the server is enabled

In the Cascade panel’s … (Actions) menu, under MCPs, confirm ocean shows connected and its tools are listed.
2

Ask a question

In Cascade, try “Use Ocean to list recent phishing reports” and confirm Windsurf calls an Ocean tool.

Troubleshooting

  • Server shows disconnected. Confirm the URL is https://api.ocean.security/mcp and serverUrl (not url or command) is used for a remote server. Toggle the server off and on.
  • Stuck asking you to sign in. Remove the ocean entry, save, then add it back so Windsurf re-runs the OAuth flow from scratch.
  • 401 on tool calls. With an API key, the key is missing, expired, or inactive. With OAuth, sign in again.
  • No Ocean tools listed. MCP access may not be enabled for your tenant, or your identity lacks the relevant permissions. See the overview troubleshooting.