Connect Windsurf (Devin Desktop) to StackJack
Windsurf — now Devin Desktop, by Cognition — connects to remote MCP servers through its Cascade agent (renamed Devin Local after the June 2026 rebrand). MCP is the Model Context Protocol, the open…
Written By Christopher Scaminaci
Last updated 6 days ago
Windsurf — now Devin Desktop, by Cognition — connects to remote MCP servers through its Cascade agent (renamed Devin Local after the June 2026 rebrand). MCP is the Model Context Protocol, the open standard AI tools use to call external tools. It can sign in with just the server URL — no headers.
The rebrand was delivered as an over-the-air update, so your app may show either name. The configuration file path below is unchanged and works for both.
Prerequisites
- Windsurf / Devin Desktop installed (a current build; the app updates itself).
- A StackJack account that is a member of your workspace. Any team member can connect — no admin-created credentials needed for the sign-in path.
- Your StackJack MCP endpoint URL. Copy it from the MCP Setup page in the portal — that card shows the address for your workspace's region. The examples in this guide use the US address,
https://mcp.stackjack.io/mcp; other regions have their own hostname. See Your region and your endpoint.
Connect with sign-in (recommended)
Open Settings → Cascade → MCP Servers, or edit the config file directly:
- macOS/Linux:
~/.codeium/windsurf/mcp_config.json - Windows:
%USERPROFILE%\.codeium\windsurf\mcp_config.json
- macOS/Linux:
Add an entry with only the
serverUrl(note the key name — noturl):{ "mcpServers": { "stackjack": { "serverUrl": "https://mcp.stackjack.io/mcp" } } }Restart the app. On first use, Cascade opens a browser to sign in — use the same email, password, and MFA you use for the StackJack Portal.
Manual credentials (fallback)
An owner, co-owner, or Administrator creates an MCP client in the portal first (see Managing MCP credentials).
Before you paste a credential anywhere, three things about it.
- Base64 is encoding, not encryption. Anyone who can read the encoded string can decode it back to the client id and secret in one command. Treat the encoded value as the secret itself.
- A typed command lands in your shell history. Produce the encoding in a way that keeps the secret out of that file, or clear the entry afterwards.
- A config file inside a repository gets committed and shared. Keep credential-bearing config on your own machine, outside any repository. Where the client offers a secret prompt or a protected credential store, use it — the client's own documentation is what governs which of those it supports. For an automated environment, take the value from that platform's secret store rather than writing it into a file.
Base64-encode CLIENT_ID:CLIENT_SECRET, add a headers block, and restart the app:
{
"mcpServers": {
"stackjack": {
"serverUrl": "https://mcp.stackjack.io/mcp",
"headers": {
"Authorization": "Basic <BASE64_OF_CLIENT_ID:CLIENT_SECRET>"
}
}
}
}
Tool limits
Cascade limits how many tools it loads, and the budget is shared across all MCP servers combined rather than counted per server. StackJack can expose hundreds of tools depending on your connectors and plan, so the primary fix is catalog mode: switch StackJack to compact or minimal mode so it serves a small tool list and Cascade discovers the rest on demand, keeping you under the budget without hiding anything. The observed figure, alongside every other client's, is in Client tool limits — check it there rather than relying on a number quoted in a guide. Catalog mode may already be in effect: Windsurf is one of the clients StackJack recognizes as capping its tool list, so if your organization has never made an explicit catalog-mode choice and your catalog exceeds that cap, this connection is already served a minimal catalog automatically. If your organization has explicitly turned catalog modes off, an admin re-enables them on the Settings page. Trimming the client's tool selection or disabling other MCP servers you aren't using helps too. See Choosing tools for each client and managing harness tool limits.
Troubleshooting
- No sign-in prompt after adding the server — restart the app; the config file is read at startup.
- Sign-in says no account was found — sign up in the portal first, or ask your team admin for an invite.
- For anything else, see Connection troubleshooting.
More in AI client guides
Connect Amazon Q Developer CLI to StackJackConnect ChatGPT to StackJackConnect Claude Code to StackJackConnect Claude.ai and Claude Desktop to StackJackStill need help? Ask the team