> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ocean.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Windsurf

> Add the Ocean Security MCP server to Windsurf.

## Overview

[Windsurf](https://windsurf.com) supports MCP servers in its Cascade agent. This guide adds
Ocean as a remote MCP server so Cascade can query threats, metrics, phishing reports, and
allow/deny lists.

For connection details and the full tool catalog, see the
[MCP Server Overview](/api-reference/mcp/overview).

## Prerequisites

* Windsurf installed.
* MCP access enabled for your tenant.
* An Ocean account to sign in with — or, if you're using the API key method, an Ocean **API
  key** (see [Authentication](/api-reference/introduction#authentication)).

## Add the server

In the Cascade panel, open the **...** (Actions) menu, go to **MCPs**, and click **Open MCP
config file** — or edit the file directly:

* macOS / Linux: `~/.config/devin/mcp_config.json`
* Windows: `%APPDATA%\devin\mcp_config.json`

```json mcp_config.json theme={null}
{
  "mcpServers": {
    "ocean": {
      "serverUrl": "https://api.ocean.security/mcp"
    }
  }
}
```

Windsurf prompts you to sign in the first time the server is used; complete the browser
sign-in with your Ocean account and approve the access it asked for.

<Note>
  OAuth access to Ocean is **read-only**. If you need the allow/deny write tools, use an API
  key instead — see [Authentication](/api-reference/mcp/overview#authentication).
</Note>

## Add with an API key

Put your API key in the `headers` block instead:

```json mcp_config.json theme={null}
{
  "mcpServers": {
    "ocean": {
      "serverUrl": "https://api.ocean.security/mcp",
      "headers": {
        "X-Api-Key": "YOUR_API_KEY"
      }
    }
  }
}
```

## Verify the connection

<Steps>
  <Step title="Check the server is enabled">
    In the Cascade panel's **...** (Actions) menu, under **MCPs**, confirm `ocean` shows
    connected and its tools are listed.
  </Step>

  <Step title="Ask a question">
    In Cascade, try **"Use Ocean to list recent phishing reports"** and confirm Windsurf calls
    an Ocean tool.
  </Step>
</Steps>

## Troubleshooting

* **Server shows disconnected.** Confirm the URL is `https://api.ocean.security/mcp` and
  `serverUrl` (not `url` or `command`) is used for a remote server. Toggle the server off and
  on.
* **Stuck asking you to sign in.** Remove the `ocean` entry, save, then add it back so Windsurf
  re-runs the OAuth flow from scratch.
* **401 on tool calls.** With an API key, the key is missing, expired, or inactive. With OAuth,
  sign in again.
* **No Ocean tools listed.** MCP access may not be enabled for your tenant, or your identity
  lacks the relevant permissions. See the
  [overview troubleshooting](/api-reference/mcp/overview#troubleshooting).
