Windsurf + xCloud
Manage Your Hosting from Windsurf with xCloud
Windsurf is an AI code editor from Cognition, formerly Codeium, now shipped as Devin Desktop, and both of its agents, Devin Local and the legacy Cascade, can call tools from MCP servers. Connected to xCloud through the MCP server, the agent deploys repositories, takes backups, updates WordPress and diagnoses failures without leaving the editor.
- One devin mcp add command for Devin Local
- A serverUrl entry keeps legacy Cascade under its 100-tool cap
- Free with every xCloud account
Youshop.example.com is returning 502. Find out why.
sites_eventsread-only
AgentPHP-FPM stopped right after the last plugin update. I can restart the service.
YouDo it.
servers_services_restart
AgentRestarted. shop.example.com answers 200 again.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do I Connect Windsurf to xCloud?
Point Windsurf at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes.
Add xCloud to the Devin Local agent
New tabs in Devin Desktop use the Devin Local agent, which reads MCP servers from the Devin CLI config files. Run this in a terminal: the URL is treated as Streamable HTTP, and the second command opens the browser for the xCloud sign-in (the agent also prompts on first use). By default the entry lands in .devin/mcp_config.local.json for the current project; add -s user to the first command to share it across projects in ~/.config/devin/mcp_config.json, where the entry reads url plus transport http.
devin mcp add xcloud https://app.xcloud.host/mcp devin mcp login xcloudOr edit the legacy Cascade config
If your tab runs the legacy Cascade agent, click the three-dot menu in the Cascade panel, then the Open MCP config file icon in the MCPs section, and add this under mcpServers. Cascade allows 100 tools in total and the full xCloud server offers 188 operations plus two search tools, so point serverUrl at the compact profile, five tools that reach every operation through search and call; a single toolset such as ?toolsets=sites (60 tools) also fits, but sites and servers together are 121 tools. Windsurf's file has been at ~/.codeium/windsurf/mcp_config.json, and the current documentation lists ~/.config/devin/mcp_config.json on macOS and Linux and %APPDATA%\devin\mcp_config.json on Windows; the icon opens the one your version reads.
{ "mcpServers": { "xcloud": { "serverUrl": "https://app.xcloud.host/mcp?profile=compact" } } }No browser sign-in? Use an API key
Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_TOKEN and add a headers field to the xcloud entry. Both agents fill in the ${env:XCLOUD_TOKEN} reference from your environment, so the token itself stays out of the file. The Devin Local entry is shown; for Cascade the same headers field sits beside serverUrl.
"xcloud": { "url": "https://app.xcloud.host/mcp", "transport": "http", "headers": { "Authorization": "Bearer ${env:XCLOUD_TOKEN}" } }Check it worked
Devin Local signs in when you run devin mcp login xcloud or when the server is first used, and keeps the OAuth tokens locally and refreshes them; Cognition lists OAuth as supported for each Cascade transport as well. Without a browser, send an API key that carries the mcp:invoke scope and the read or write abilities it needs in the headers field.
Who am I on xCloud?
Three surfaces
Which Way Should I Connect Windsurf to xCloud?
The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.
| xCloud MCP server | xCloud Agent Skills | Public API | |
|---|---|---|---|
| Terminal needed | No (recommended for Windsurf) | Yes for the plugin or ClawHub install | Yes |
| Authentication | OAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Windsurf) | The MCP connection, or a read-scoped API token | API token with scoped abilities |
| What it adds | One tool per customer-facing xCloud operation (188 today) (recommended for Windsurf) | Workflow know-how: routing, dry run, confirm, poll, diagnose | Raw REST for your own code |
| Changes to your infrastructure | Yes, after confirmation (recommended for Windsurf) | Only through a connected MCP tool, after confirmation | Yes, with write scopes |
| Best for | Most people; every MCP client (recommended for Windsurf) | Agents that run shell commands and read skills | CI jobs, dashboards and long-running loops |
Background
What Is Windsurf?
Windsurf is an AI code editor from Cognition, which acquired it from Codeium and now ships it as Devin Desktop. A new tab opens with the Devin Local agent, and the older Cascade agent is still available as the legacy option. Both can use tools from MCP servers, and Cognition documents them on docs.devin.ai, which is where the pages you find for Windsurf's MCP support now live.
Devin Local takes its MCP servers from the Devin CLI config files: ~/.config/devin/mcp_config.json for your user, .devin/mcp_config.json for a project you share through git, and .devin/mcp_config.local.json for a gitignored local override, which is where devin mcp add writes by default. A remote entry is a url plus transport http, devin mcp login runs the OAuth sign-in, and the agent asks before an MCP tool runs unless you list the tool under permissions.allow.
Legacy Cascade reads mcp_config.json through the Cascade panel instead, supports stdio, Streamable HTTP and SSE servers with OAuth for each, and limits itself to 100 tools in total, which matters because the full xCloud server offers more than that. xCloud's MCP server is Streamable HTTP, so it fits either agent as a remote entry.
Why Windsurf with xCloud?
Deploy and fix from the editor
The code is open in Windsurf already. Ask the agent to deploy a repository, back a site up or find the cause of a 502, and it calls xCloud from the same panel while you keep working.
Decide what the agent may run
Devin Local prompts before an MCP tool runs unless you add it to permissions.allow, and deny and ask lists override that. Legacy Cascade shares 100 tool slots across every server, so the compact xCloud profile takes five of them, and disabledTools switches off individual tools.
Config files you can read
Both agents keep their servers in plain JSON, and a headers field supports ${env:VAR} references. That keeps an API token in your environment instead of in a file you might commit or share.
Guides
What Can Windsurf Do on xCloud?
One guide per hosting job, each with the Windsurf setup, the xCloud tools involved, a settings reference, example prompts and the limits that apply.
- Deploy from Git with WindsurfTurn a GitHub, GitLab or Bitbucket repository into a live site on a server you already have.
- Run Docker apps with WindsurfRun a Dockerfile or Docker Compose app on a Docker server, keep it backed up and recover it when a deploy fails.
- Install one-click apps with WindsurfPick an app from the xCloud catalogue, check it fits your server, install it and get the login details.
- Manage WordPress with WindsurfKeep WordPress sites updated, scanned and healthy, and create new ones, by asking in plain words.
- Back up and stage sites with WindsurfCheck that your sites are backed up, take a backup before a risky change, and open a staging copy to test it on.
- Manage SSL and domains with WindsurfCheck a site's certificate and DNS, install or renew HTTPS, and see which domains point at it.
- Manage servers with WindsurfSee how your servers are doing, change services and runtimes, tighten security and reboot with proof it worked.
- Troubleshoot a broken site with WindsurfFind out why a site returns a 500, 502 or 503, shows a critical error or has stopped answering.
- Speed up a slow site with WindsurfFind out why a site is slow, from real numbers, and learn which fix is a dashboard switch.
- Secure sites and servers with WindsurfFind vulnerable sites, manage server firewall rules and banned IPs, and see which protections are on.
Example prompts
What Can You Ask Windsurf to Do on xCloud?
Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
Deploy https://github.com/example/shop to my Frankfurt server and show me the dry run before you create anything.Which of my sites have pending WordPress updates? Back each one up first, then update and check the homepages.shop.example.com is returning 502. Find the cause and tell me what you would change before you change it.Renew the SSL certificate for shop.example.com and tell me when it expires now.Is example.com up, is SSL healthy, and does it have any known vulnerabilities?Good to know
- New tabs in Devin Desktop run the Devin Local agent, so the Cascade panel steps only apply when a tab uses the legacy Cascade agent. Devin Local reads MCP servers from the Devin CLI config files, which devin mcp add writes.
- The Devin Local MCP config file moved in Devin Local 3.6 (v3000.3): older versions keep mcpServers inside config.json, newer ones use mcp_config.json beside it, and entries migrate automatically. Legacy Cascade has used ~/.codeium/windsurf/mcp_config.json; the Open MCP config file icon opens the file your version reads.
- Legacy Cascade caps the total at 100 tools. The full xCloud profile is more than that on its own, so give Cascade https://app.xcloud.host/mcp?profile=compact. A single toolset such as ?toolsets=sites (60 tools) also fits, but ?toolsets=sites,servers is 121 tools and does not. No such cap is documented for Devin Local.
- Enterprise users must turn MCP on in settings. Once a team admin allowlists even one MCP server, every Cascade server that is not on the list is blocked, and Devin Local can be limited to a team MCP registry. The server ID must match the key name, xcloud, exactly.
More prompts, grouped by job: What you can ask xCloud MCP to do.
Windsurf and xCloud: Frequently Asked Questions
Short answers about connecting Windsurf, what it may change and what it costs.
How do I connect Windsurf to xCloud?
For the Devin Local agent, the default in new tabs, run devin mcp add xcloud https://app.xcloud.host/mcp and then devin mcp login xcloud, approve the xCloud sign-in in your browser and ask who am I on xCloud to confirm. If your tab runs the legacy Cascade agent, open the Cascade panel's three-dot menu, click Open MCP config file and add an xcloud entry under mcpServers with serverUrl set to https://app.xcloud.host/mcp?profile=compact.
Why do the Windsurf MCP docs mention Devin?
Windsurf's maker, Cognition, now ships Windsurf as Devin Desktop and documents it on docs.devin.ai. The default agent for new tabs is Devin Local, which is configured through the Devin CLI; the Cascade MCP page says its configuration applies to the legacy Cascade agent. This page gives the Devin Local path first and the Cascade path as the alternative.
Which config file does Windsurf read?
Devin Local reads ~/.config/devin/mcp_config.json for your user, .devin/mcp_config.json for the project and .devin/mcp_config.local.json for a gitignored local override; devin mcp add writes to the local file unless you pass -s user or -s project. Legacy Cascade has used ~/.codeium/windsurf/mcp_config.json, and the current documentation lists ~/.config/devin/mcp_config.json on macOS and Linux and %APPDATA%\devin\mcp_config.json on Windows; the Open MCP config file icon opens the one your version reads.
Should I use url or serverUrl for xCloud in Windsurf?
For Devin Local use url with transport set to http, the form devin mcp add writes. For legacy Cascade use serverUrl, the key shown in Windsurf's remote MCP example and in xCloud's own setup guide; the Cascade page says a remote entry takes serverUrl or url, so url may also work there, but serverUrl is the safe choice.
What is the 100-tool limit and how do I stay under it?
Legacy Cascade can use at most 100 tools across all your MCP servers at any time. xCloud offers 188 operations plus two search tools, so give Cascade https://app.xcloud.host/mcp?profile=compact, which exposes five tools, or load one area with a toolset such as ?toolsets=sites, which is 60 tools. Sites and servers together are 121 tools, so that pair does not fit. You can also list tool names in a server's disabledTools array. Cognition documents no such cap for Devin Local, so the full URL works there.
Can I use an API key instead of OAuth in Windsurf?
Yes. Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_TOKEN and add a headers field with Authorization set to Bearer ${env:XCLOUD_TOKEN} to the xcloud entry, beside url for Devin Local or serverUrl for Cascade. Both agents replace the reference with the value from your environment.
Can Windsurf change my servers without asking?
Not for the operations xCloud gates. Reads run straight away, and routine actions such as cache purges, backups, PageSpeed and vulnerability scans run without an xCloud prompt. Creating a site or server, deploying, updating plugins, rebooting, deleting or buying is refused by xCloud unless the call carries an explicit confirmation, so the agent asks you first. Devin Local adds its own prompt before any MCP tool runs unless you list the tool under permissions.allow, and that prompt is the only gate for the routine actions.
Does this work with the legacy Cascade agent?
Yes. The same server works, but the file and the key differ: Cascade reads mcp_config.json through the Open MCP config file icon in its panel and takes a serverUrl entry, and because it caps the total at 100 tools it should point at https://app.xcloud.host/mcp?profile=compact or a single toolset.
Why are xCloud's tools blocked on my team's Windsurf?
A team admin can allowlist MCP servers for Cascade, and once even one server is allowlisted every other server is blocked; Devin Local can be limited to a team MCP registry in the same way. Ask the admin to add a server ID of xcloud, which must match the key name in your config exactly, including its case.
Other agents
Also Works With
The same xCloud account, the same operations, a guide for each client.
- Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
Run Your Hosting from Windsurf
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.