Windsurf + xCloud

Manage Your Hosting from Windsurf with xCloud

Windsurf is an AI code editor from Cognition, formerly Codeium, now shipped as Devin Desktop, and both of its agents, Devin Local and the legacy Cascade, can call tools from MCP servers. Connected to xCloud through the MCP server, the agent deploys repositories, takes backups, updates WordPress and diagnoses failures without leaving the editor.

  • One devin mcp add command for Devin Local
  • A serverUrl entry keeps legacy Cascade under its 100-tool cap
  • Free with every xCloud account

Youshop.example.com is returning 502. Find out why.

sites_eventsread-only

AgentPHP-FPM stopped right after the last plugin update. I can restart the service.

YouDo it.

servers_services_restart

AgentRestarted. shop.example.com answers 200 again.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do I Connect Windsurf to xCloud?

Point Windsurf at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes.

  1. Add xCloud to the Devin Local agent

    New tabs in Devin Desktop use the Devin Local agent, which reads MCP servers from the Devin CLI config files. Run this in a terminal: the URL is treated as Streamable HTTP, and the second command opens the browser for the xCloud sign-in (the agent also prompts on first use). By default the entry lands in .devin/mcp_config.local.json for the current project; add -s user to the first command to share it across projects in ~/.config/devin/mcp_config.json, where the entry reads url plus transport http.

    Shell
    devin mcp add xcloud https://app.xcloud.host/mcp
    devin mcp login xcloud
  2. Or edit the legacy Cascade config

    If your tab runs the legacy Cascade agent, click the three-dot menu in the Cascade panel, then the Open MCP config file icon in the MCPs section, and add this under mcpServers. Cascade allows 100 tools in total and the full xCloud server offers 188 operations plus two search tools, so point serverUrl at the compact profile, five tools that reach every operation through search and call; a single toolset such as ?toolsets=sites (60 tools) also fits, but sites and servers together are 121 tools. Windsurf's file has been at ~/.codeium/windsurf/mcp_config.json, and the current documentation lists ~/.config/devin/mcp_config.json on macOS and Linux and %APPDATA%\devin\mcp_config.json on Windows; the icon opens the one your version reads.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "serverUrl": "https://app.xcloud.host/mcp?profile=compact"
        }
      }
    }
  3. No browser sign-in? Use an API key

    Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_TOKEN and add a headers field to the xcloud entry. Both agents fill in the ${env:XCLOUD_TOKEN} reference from your environment, so the token itself stays out of the file. The Devin Local entry is shown; for Cascade the same headers field sits beside serverUrl.

    JSON
    "xcloud": {
      "url": "https://app.xcloud.host/mcp",
      "transport": "http",
      "headers": {
        "Authorization": "Bearer ${env:XCLOUD_TOKEN}"
      }
    }
  4. Check it worked

    Devin Local signs in when you run devin mcp login xcloud or when the server is first used, and keeps the OAuth tokens locally and refreshes them; Cognition lists OAuth as supported for each Cascade transport as well. Without a browser, send an API key that carries the mcp:invoke scope and the read or write abilities it needs in the headers field.

    Prompt
    Who am I on xCloud?

Three surfaces

Which Way Should I Connect Windsurf to xCloud?

The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.

xCloud MCP serverxCloud Agent SkillsPublic API
Terminal neededNo (recommended for Windsurf)Yes for the plugin or ClawHub installYes
AuthenticationOAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Windsurf)The MCP connection, or a read-scoped API tokenAPI token with scoped abilities
What it addsOne tool per customer-facing xCloud operation (188 today) (recommended for Windsurf)Workflow know-how: routing, dry run, confirm, poll, diagnoseRaw REST for your own code
Changes to your infrastructureYes, after confirmation (recommended for Windsurf)Only through a connected MCP tool, after confirmationYes, with write scopes
Best forMost people; every MCP client (recommended for Windsurf)Agents that run shell commands and read skillsCI jobs, dashboards and long-running loops

Background

What Is Windsurf?

Windsurf is an AI code editor from Cognition, which acquired it from Codeium and now ships it as Devin Desktop. A new tab opens with the Devin Local agent, and the older Cascade agent is still available as the legacy option. Both can use tools from MCP servers, and Cognition documents them on docs.devin.ai, which is where the pages you find for Windsurf's MCP support now live.

Devin Local takes its MCP servers from the Devin CLI config files: ~/.config/devin/mcp_config.json for your user, .devin/mcp_config.json for a project you share through git, and .devin/mcp_config.local.json for a gitignored local override, which is where devin mcp add writes by default. A remote entry is a url plus transport http, devin mcp login runs the OAuth sign-in, and the agent asks before an MCP tool runs unless you list the tool under permissions.allow.

Legacy Cascade reads mcp_config.json through the Cascade panel instead, supports stdio, Streamable HTTP and SSE servers with OAuth for each, and limits itself to 100 tools in total, which matters because the full xCloud server offers more than that. xCloud's MCP server is Streamable HTTP, so it fits either agent as a remote entry.

Why Windsurf with xCloud?

Deploy and fix from the editor

The code is open in Windsurf already. Ask the agent to deploy a repository, back a site up or find the cause of a 502, and it calls xCloud from the same panel while you keep working.

Decide what the agent may run

Devin Local prompts before an MCP tool runs unless you add it to permissions.allow, and deny and ask lists override that. Legacy Cascade shares 100 tool slots across every server, so the compact xCloud profile takes five of them, and disabledTools switches off individual tools.

Config files you can read

Both agents keep their servers in plain JSON, and a headers field supports ${env:VAR} references. That keeps an API token in your environment instead of in a file you might commit or share.

Guides

What Can Windsurf Do on xCloud?

One guide per hosting job, each with the Windsurf setup, the xCloud tools involved, a settings reference, example prompts and the limits that apply.

Example prompts

What Can You Ask Windsurf to Do on xCloud?

Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Deploy https://github.com/example/shop to my Frankfurt server and show me the dry run before you create anything.
Prompt
Which of my sites have pending WordPress updates? Back each one up first, then update and check the homepages.
Prompt
shop.example.com is returning 502. Find the cause and tell me what you would change before you change it.
Prompt
Renew the SSL certificate for shop.example.com and tell me when it expires now.
Prompt
Is example.com up, is SSL healthy, and does it have any known vulnerabilities?

Good to know

  • New tabs in Devin Desktop run the Devin Local agent, so the Cascade panel steps only apply when a tab uses the legacy Cascade agent. Devin Local reads MCP servers from the Devin CLI config files, which devin mcp add writes.
  • The Devin Local MCP config file moved in Devin Local 3.6 (v3000.3): older versions keep mcpServers inside config.json, newer ones use mcp_config.json beside it, and entries migrate automatically. Legacy Cascade has used ~/.codeium/windsurf/mcp_config.json; the Open MCP config file icon opens the file your version reads.
  • Legacy Cascade caps the total at 100 tools. The full xCloud profile is more than that on its own, so give Cascade https://app.xcloud.host/mcp?profile=compact. A single toolset such as ?toolsets=sites (60 tools) also fits, but ?toolsets=sites,servers is 121 tools and does not. No such cap is documented for Devin Local.
  • Enterprise users must turn MCP on in settings. Once a team admin allowlists even one MCP server, every Cascade server that is not on the list is blocked, and Devin Local can be limited to a team MCP registry. The server ID must match the key name, xcloud, exactly.

More prompts, grouped by job: What you can ask xCloud MCP to do.

Windsurf and xCloud: Frequently Asked Questions

Short answers about connecting Windsurf, what it may change and what it costs.

How do I connect Windsurf to xCloud?

For the Devin Local agent, the default in new tabs, run devin mcp add xcloud https://app.xcloud.host/mcp and then devin mcp login xcloud, approve the xCloud sign-in in your browser and ask who am I on xCloud to confirm. If your tab runs the legacy Cascade agent, open the Cascade panel's three-dot menu, click Open MCP config file and add an xcloud entry under mcpServers with serverUrl set to https://app.xcloud.host/mcp?profile=compact.

Why do the Windsurf MCP docs mention Devin?

Windsurf's maker, Cognition, now ships Windsurf as Devin Desktop and documents it on docs.devin.ai. The default agent for new tabs is Devin Local, which is configured through the Devin CLI; the Cascade MCP page says its configuration applies to the legacy Cascade agent. This page gives the Devin Local path first and the Cascade path as the alternative.

Which config file does Windsurf read?

Devin Local reads ~/.config/devin/mcp_config.json for your user, .devin/mcp_config.json for the project and .devin/mcp_config.local.json for a gitignored local override; devin mcp add writes to the local file unless you pass -s user or -s project. Legacy Cascade has used ~/.codeium/windsurf/mcp_config.json, and the current documentation lists ~/.config/devin/mcp_config.json on macOS and Linux and %APPDATA%\devin\mcp_config.json on Windows; the Open MCP config file icon opens the one your version reads.

Should I use url or serverUrl for xCloud in Windsurf?

For Devin Local use url with transport set to http, the form devin mcp add writes. For legacy Cascade use serverUrl, the key shown in Windsurf's remote MCP example and in xCloud's own setup guide; the Cascade page says a remote entry takes serverUrl or url, so url may also work there, but serverUrl is the safe choice.

What is the 100-tool limit and how do I stay under it?

Legacy Cascade can use at most 100 tools across all your MCP servers at any time. xCloud offers 188 operations plus two search tools, so give Cascade https://app.xcloud.host/mcp?profile=compact, which exposes five tools, or load one area with a toolset such as ?toolsets=sites, which is 60 tools. Sites and servers together are 121 tools, so that pair does not fit. You can also list tool names in a server's disabledTools array. Cognition documents no such cap for Devin Local, so the full URL works there.

Can I use an API key instead of OAuth in Windsurf?

Yes. Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_TOKEN and add a headers field with Authorization set to Bearer ${env:XCLOUD_TOKEN} to the xcloud entry, beside url for Devin Local or serverUrl for Cascade. Both agents replace the reference with the value from your environment.

Can Windsurf change my servers without asking?

Not for the operations xCloud gates. Reads run straight away, and routine actions such as cache purges, backups, PageSpeed and vulnerability scans run without an xCloud prompt. Creating a site or server, deploying, updating plugins, rebooting, deleting or buying is refused by xCloud unless the call carries an explicit confirmation, so the agent asks you first. Devin Local adds its own prompt before any MCP tool runs unless you list the tool under permissions.allow, and that prompt is the only gate for the routine actions.

Does this work with the legacy Cascade agent?

Yes. The same server works, but the file and the key differ: Cascade reads mcp_config.json through the Open MCP config file icon in its panel and takes a serverUrl entry, and because it caps the total at 100 tools it should point at https://app.xcloud.host/mcp?profile=compact or a single toolset.

Why are xCloud's tools blocked on my team's Windsurf?

A team admin can allowlist MCP servers for Cascade, and once even one server is allowlisted every other server is blocked; Devin Local can be limited to a team MCP registry in the same way. Ask the admin to add a server ID of xcloud, which must match the key name in your config exactly, including its case.

Other agents

Also Works With

The same xCloud account, the same operations, a guide for each client.

Run Your Hosting from Windsurf

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.