Before you start: Windsurf is now Devin Desktop
Windsurf was renamed Devin Desktop on June 2, 2026, and Devin’s docs now give a new location for mcp_config.json. Devin’s announcement says your plan, pricing and extensions stay the same.
- New tabs start with the Devin Local agent. Devin said it would keep the older Cascade agent, now labeled legacy, through July 1, 2026 for migration. Devin’s docs still describe Cascade, so the steps below cover both agents.
- Older guides on how to add MCP to Windsurf edit ~/.codeium/windsurf/mcp_config.json. The current app may read a different file, so check the path table below before you edit anything.
- If your company manages Devin Desktop, an admin may limit MCP servers to an allowlist. Once one server is allowlisted, all others are blocked. Devin’s docs also say Enterprise users must switch MCP on in settings.
- You need a Zyflow account. You can create one, free and with no card, when sign-in opens.
Add the server to Windsurf’s mcp_config.json
Add one entry under mcpServers with your Zyflow link as its url, save, and refresh the server list. Open the file from inside the app, not by path: Devin’s docs list more than one location, and the app opens the file it reads.
-
Open the MCP config file from the app.
- Devin Local: open the MCP config file from the app’s MCP settings.
- Cascade (legacy): the ... (Actions) menu at the top right of the Cascade panel, then Open MCP config file.
-
Paste the Zyflow entry. If other servers are already listed, add “zyflow” inside the same mcpServers object and put a comma after the entry before it.
{
"mcpServers": {
"zyflow": {
"url": "https://app.zyflowcrm.com/mcp"
}
}
} -
Save, then refresh the MCP servers or switch Zyflow on. Your AI’s first call to Zyflow starts sign-in.
Use url as the key: the legacy Cascade agent accepts serverUrl or url, and Devin’s agent config uses url. Devin Desktop signs in to Zyflow with OAuth, so you don’t need the npx mcp-remote bridge or the personal access token that some older Windsurf guides use.
Free plan. No card.
Where is mcp_config.json?
Current Devin Desktop reads ~/.config/devin/mcp_config.json on macOS and Linux, and %APPDATA%\devin\mcp_config.json on Windows. Windsurf builds from before June 2026 read ~/.codeium/windsurf/mcp_config.json.
| Scope | Current Devin Desktop | Windsurf before June 2026 |
|---|---|---|
| Your user, macOS and Linux | ~/.config/devin/mcp_config.json (or $XDG_CONFIG_HOME/devin/mcp_config.json) | ~/.codeium/windsurf/mcp_config.json |
| Your user, Windows | %APPDATA%\devin\mcp_config.json | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
| One project, Devin Local | .devin/mcp_config.json in the project folder | None |
Devin’s rename FAQ lists one more path, ~/.codeium/mcp_config.json (docs.devin.ai, checked Oct 3, 2026). Opening the file from the app, as in step 1, gets you the file the app reads. On a build from before June 2026, write serverUrl in place of url.
Read-only access with an API key (optional)
To let your AI look things up without changing anything, send a read-only API key as a header instead of signing in. Create the key on Zyflow’s Connect page. The ${env:ZYFLOW_API_KEY} value reads the key from an environment variable, so the key itself stays out of the file.
{
"mcpServers": {
"zyflow": {
"url": "https://app.zyflowcrm.com/mcp",
"headers": {
"Authorization": "Bearer ${env:ZYFLOW_API_KEY}"
}
}
}
} Set ZYFLOW_API_KEY before you start Devin Desktop. A read-only key can still export your data and works until you revoke it, so keep it private.
Sign in and approve one workspace
The first time your AI calls Zyflow, Zyflow answers with a sign-in challenge and Devin Desktop opens Zyflow in your browser. It works like “Sign in with Google”: you sign in, pick one workspace and approve. You never paste a password into your AI app.
-
Your browser opens Zyflow’s sign-in. If the server shows “Needs auth” instead, click Authenticate.
-
Log in, or create a free account. New to Zyflow? Choose “Create a free account” under the “Welcome back” form.
-
On the screen that reads “[App name] wants to use your Zyflow”, pick one workspace and click Approve within 10 minutes.
-
Back in Devin Desktop, Zyflow is ready to use.
Under the hood, sign-in uses OAuth 2.1 with PKCE (S256) and either dynamic client registration or a client ID metadata document. Refresh tokens rotate on every use, and every token is stored as a hash. One connection reaches one workspace.
Use your customer records from the Windsurf editor
Ask in plain words, the way you’d tell a colleague. Your AI picks the Zyflow tool, and Zyflow keeps the record. Start by adding a customer, so the other prompts have something to find.
Add Maya Chen at Northwind as a customer, maya@northwind.example
Log a call with Maya: she approved the staging build and wants the invoice by Friday
What do we know about Northwind?
What’s on my plate today?
Undo what you just did
What you’ll see
- By default, Devin Local asks you to approve each MCP tool call before it runs.
- Each change is labeled with your app’s name and comes with an Undo.1
- Live labels and Undo buttons appear in any open Zyflow tab. Every change is also in History.
- AI apps can only move records and files to the 30-day trash, so anything your AI deletes can be restored for 30 days.
Check that it worked
Describe my Zyflow workspace
Your AI should reply with your workspace’s name, today’s date and your currency.
Windsurf MCP server not working? Common fixes
Most problems come from a file the app doesn’t read, a sign-in that didn’t finish, or an admin’s allowlist. Find your symptom below.
| Symptom | Likely cause | Fix |
|---|---|---|
| Zyflow isn’t in the MCP list | You edited a file the app doesn’t read (often the old ~/.codeium/windsurf one), or the JSON has an error | Open the file from the app, check commas and braces, save, then refresh or switch the server on |
| The server shows “Needs auth” | Sign-in didn’t finish, or the stored token stopped working | Click Authenticate and sign in again |
| “This connection request has expired” | Approval took longer than 10 minutes | Start the sign-in again from Devin Desktop |
| The server is blocked | Your admin’s MCP allowlist | Ask your admin to allowlist the server ID zyflow, matching its case exactly |
| Some Zyflow tools are missing | Cascade’s limit of 100 tools across all servers (Zyflow has 32) | Switch off servers you don’t use, or list unneeded tools under disabledTools |
| invalid_target error at sign-in | oauthResource is set to another URL | Remove oauthResource, or set it to your Zyflow link |
| Writes refused with 403 insufficient_scope | A read-only API key or connection | Use a read-and-write key, or disconnect on Zyflow’s Connect page and sign in again |
| Changes land in the wrong business | You approved another workspace | Disconnect the app on Zyflow’s Connect page, then sign in again and pick the right one |
- Spot an error? Tell us
- See the setup guides
Questions about Windsurf and MCP
Is Windsurf now called Devin Desktop?
Yes. Windsurf became Devin Desktop on June 2, 2026, and Devin’s announcement says your plan, pricing and extensions stay the same. Searches and older guides still say Windsurf, so this guide uses both names.
Should I use serverUrl or url in mcp_config.json?
Use url. The legacy Cascade agent accepts either key, and Devin’s agent config uses url, so one entry works in both. Only Windsurf builds from before June 2026 need serverUrl.
Do my Windsurf MCP servers carry over to Devin Desktop?
Possibly, but plan to sign in again. Devin’s docs say Devin CLI imports servers from your old ~/.codeium/<channel>/mcp_config.json by default, and that each MCP client signs in on its own. If Zyflow isn’t in your list, add it with the steps above.
Do I need an API key?
No. You sign in with OAuth in your browser, so there’s no key to paste and no bridge to run. A read-only API key is optional, for when you want your AI to look things up without changing anything.
What can Devin Desktop see in Zyflow?
Only the one workspace you approve, with the same role you have. It never gets your password and can’t touch billing, members or API keys. Disconnect it on Zyflow’s Connect page, and its access ends at once.
Will Zyflow see my code?
By default, Devin Local asks you before each Zyflow tool call runs. Zyflow receives only what your AI app sends in its tool calls, not the rest of your chat. Zyflow runs no AI model and doesn’t train one on your data.
One workspace per connection
You sign in and approve, like “Sign in with Google”. Your AI app never gets your password, and it can’t touch billing, members or keys.
Every AI change labeled
Export any time