Setup guide for Windsurf and Devin Desktop

How to add an MCP server to Windsurf (now Devin Desktop)

Keep client records next to your code. With one entry in mcp_config.json and one browser sign-in, your AI can look up a client, log a call and set the follow-up without leaving the editor.

Last updated Oct 3, 2026

Last checked against Devin’s documentation on Oct 3, 2026. Spot an error? Tell us

To add a remote Model Context Protocol (MCP) server to Windsurf, now called Devin Desktop, open mcp_config.json from inside the app, add the server’s URL under mcpServers, save, and sign in when your browser opens. A server that supports OAuth needs no API key and no local bridge. This guide uses Zyflow as the example Windsurf MCP server. Zyflow is a lightweight small-business CRM your AI app keeps up to date (Claude, Cursor, ChatGPT Business, any MCP app). Every AI change is labeled. Start free. Free plan. No card.

Before you start: Windsurf is now Devin Desktop

Windsurf was renamed Devin Desktop on June 2, 2026, and Devin’s docs now give a new location for mcp_config.json. Devin’s announcement says your plan, pricing and extensions stay the same.

  • New tabs start with the Devin Local agent. Devin said it would keep the older Cascade agent, now labeled legacy, through July 1, 2026 for migration. Devin’s docs still describe Cascade, so the steps below cover both agents.
  • Older guides on how to add MCP to Windsurf edit ~/.codeium/windsurf/mcp_config.json. The current app may read a different file, so check the path table below before you edit anything.
  • If your company manages Devin Desktop, an admin may limit MCP servers to an allowlist. Once one server is allowlisted, all others are blocked. Devin’s docs also say Enterprise users must switch MCP on in settings.
  • You need a Zyflow account. You can create one, free and with no card, when sign-in opens.

Add the server to Windsurf’s mcp_config.json

Add one entry under mcpServers with your Zyflow link as its url, save, and refresh the server list. Open the file from inside the app, not by path: Devin’s docs list more than one location, and the app opens the file it reads.

  1. Open the MCP config file from the app.

  • Devin Local: open the MCP config file from the app’s MCP settings.
  • Cascade (legacy): the ... (Actions) menu at the top right of the Cascade panel, then Open MCP config file.
  1. Paste the Zyflow entry. If other servers are already listed, add “zyflow” inside the same mcpServers object and put a comma after the entry before it.

{
  "mcpServers": {
    "zyflow": {
      "url": "https://app.zyflowcrm.com/mcp"
    }
  }
}
  1. Save, then refresh the MCP servers or switch Zyflow on. Your AI’s first call to Zyflow starts sign-in.

Use url as the key: the legacy Cascade agent accepts serverUrl or url, and Devin’s agent config uses url. Devin Desktop signs in to Zyflow with OAuth, so you don’t need the npx mcp-remote bridge or the personal access token that some older Windsurf guides use.

Get your Zyflow link

Free plan. No card.

Where is mcp_config.json?

Current Devin Desktop reads ~/.config/devin/mcp_config.json on macOS and Linux, and %APPDATA%\devin\mcp_config.json on Windows. Windsurf builds from before June 2026 read ~/.codeium/windsurf/mcp_config.json.

Where mcp_config.json lives
Scope Current Devin Desktop Windsurf before June 2026
Your user, macOS and Linux ~/.config/devin/mcp_config.json (or $XDG_CONFIG_HOME/devin/mcp_config.json) ~/.codeium/windsurf/mcp_config.json
Your user, Windows %APPDATA%\devin\mcp_config.json %USERPROFILE%\.codeium\windsurf\mcp_config.json
One project, Devin Local .devin/mcp_config.json in the project folder None

Devin’s rename FAQ lists one more path, ~/.codeium/mcp_config.json (docs.devin.ai, checked Oct 3, 2026). Opening the file from the app, as in step 1, gets you the file the app reads. On a build from before June 2026, write serverUrl in place of url.

Read-only access with an API key (optional)

To let your AI look things up without changing anything, send a read-only API key as a header instead of signing in. Create the key on Zyflow’s Connect page. The ${env:ZYFLOW_API_KEY} value reads the key from an environment variable, so the key itself stays out of the file.

{
  "mcpServers": {
    "zyflow": {
      "url": "https://app.zyflowcrm.com/mcp",
      "headers": {
        "Authorization": "Bearer ${env:ZYFLOW_API_KEY}"
      }
    }
  }
}

Set ZYFLOW_API_KEY before you start Devin Desktop. A read-only key can still export your data and works until you revoke it, so keep it private.

Sign in and approve one workspace

The first time your AI calls Zyflow, Zyflow answers with a sign-in challenge and Devin Desktop opens Zyflow in your browser. It works like “Sign in with Google”: you sign in, pick one workspace and approve. You never paste a password into your AI app.

  1. Your browser opens Zyflow’s sign-in. If the server shows “Needs auth” instead, click Authenticate.

  2. Log in, or create a free account. New to Zyflow? Choose “Create a free account” under the “Welcome back” form.

  3. On the screen that reads “[App name] wants to use your Zyflow”, pick one workspace and click Approve within 10 minutes.

  4. Back in Devin Desktop, Zyflow is ready to use.

Under the hood, sign-in uses OAuth 2.1 with PKCE (S256) and either dynamic client registration or a client ID metadata document. Refresh tokens rotate on every use, and every token is stored as a hash. One connection reaches one workspace.

Use your customer records from the Windsurf editor

Ask in plain words, the way you’d tell a colleague. Your AI picks the Zyflow tool, and Zyflow keeps the record. Start by adding a customer, so the other prompts have something to find.

Add Maya Chen at Northwind as a customer, maya@northwind.example

Log a call with Maya: she approved the staging build and wants the invoice by Friday

What do we know about Northwind?

What’s on my plate today?

Undo what you just did

What you’ll see

  • By default, Devin Local asks you to approve each MCP tool call before it runs.
  • Each change is labeled with your app’s name and comes with an Undo.1
  • Live labels and Undo buttons appear in any open Zyflow tab. Every change is also in History.
  • AI apps can only move records and files to the 30-day trash, so anything your AI deletes can be restored for 30 days.

Check that it worked

Describe my Zyflow workspace

Your AI should reply with your workspace’s name, today’s date and your currency.

Windsurf MCP server not working? Common fixes

Most problems come from a file the app doesn’t read, a sign-in that didn’t finish, or an admin’s allowlist. Find your symptom below.

Windsurf MCP server fixes
Symptom Likely cause Fix
Zyflow isn’t in the MCP list You edited a file the app doesn’t read (often the old ~/.codeium/windsurf one), or the JSON has an error Open the file from the app, check commas and braces, save, then refresh or switch the server on
The server shows “Needs auth” Sign-in didn’t finish, or the stored token stopped working Click Authenticate and sign in again
“This connection request has expired” Approval took longer than 10 minutes Start the sign-in again from Devin Desktop
The server is blocked Your admin’s MCP allowlist Ask your admin to allowlist the server ID zyflow, matching its case exactly
Some Zyflow tools are missing Cascade’s limit of 100 tools across all servers (Zyflow has 32) Switch off servers you don’t use, or list unneeded tools under disabledTools
invalid_target error at sign-in oauthResource is set to another URL Remove oauthResource, or set it to your Zyflow link
Writes refused with 403 insufficient_scope A read-only API key or connection Use a read-and-write key, or disconnect on Zyflow’s Connect page and sign in again
Changes land in the wrong business You approved another workspace Disconnect the app on Zyflow’s Connect page, then sign in again and pick the right one

Questions about Windsurf and MCP

Is Windsurf now called Devin Desktop?

Yes. Windsurf became Devin Desktop on June 2, 2026, and Devin’s announcement says your plan, pricing and extensions stay the same. Searches and older guides still say Windsurf, so this guide uses both names.

Should I use serverUrl or url in mcp_config.json?

Use url. The legacy Cascade agent accepts either key, and Devin’s agent config uses url, so one entry works in both. Only Windsurf builds from before June 2026 need serverUrl.

Do my Windsurf MCP servers carry over to Devin Desktop?

Possibly, but plan to sign in again. Devin’s docs say Devin CLI imports servers from your old ~/.codeium/<channel>/mcp_config.json by default, and that each MCP client signs in on its own. If Zyflow isn’t in your list, add it with the steps above.

Do I need an API key?

No. You sign in with OAuth in your browser, so there’s no key to paste and no bridge to run. A read-only API key is optional, for when you want your AI to look things up without changing anything.

What can Devin Desktop see in Zyflow?

Only the one workspace you approve, with the same role you have. It never gets your password and can’t touch billing, members or API keys. Disconnect it on Zyflow’s Connect page, and its access ends at once.

Will Zyflow see my code?

By default, Devin Local asks you before each Zyflow tool call runs. Zyflow receives only what your AI app sends in its tool calls, not the rest of your chat. Zyflow runs no AI model and doesn’t train one on your data.

One workspace per connection

You sign in and approve, like “Sign in with Google”. Your AI app never gets your password, and it can’t touch billing, members or keys.

  1. 1 Undo works within your plan’s history window: 30 days on Free, up to 3 years on paid plans. Deleted items can be restored for 30 days on every plan. Settings changes, such as pipelines, custom fields and tag renames, are logged but can’t be undone. ↩
  2. 2 Export gives you six CSV files, or one JSON file with your records, documents, change history (up to 100,000 changes) and links to every file. File contents download separately from Files. ↩

Last updated Oct 3, 2026

One link for any MCP app.

Devin Desktop and Windsurf belong to their owners. Zyflow isn’t affiliated with or endorsed by them.

Related guides: Read the Cursor setup guide · Read the VS Code setup guide · Read the Claude Code setup guide · Other MCP apps · Read the MCP reference · See the setup guides