Windsurf
Cascade desktop interface
Open Cascade's … (Actions) → MCPs to manage configured servers. In its mcp_config.json, merge:
{"mcpServers":{"morawp":{"serverUrl":"https://api.morawp.com/mcp"}}}
The current reference accepts serverUrl or url for remote HTTP services. Keep other servers and leave authentication headers empty. Enable MoraWP and use the OAuth sign-in offered by the client.
Verify in Cascade
Check that MoraWP's tools are enabled for the active Agent. Cascade's total tool limit can make some tools unavailable even when a server connected successfully. Enable only the tools you need locally; this cannot grant an Ability that MoraWP refuses.
Other Devin surfaces
This configuration is for Cascade's desktop MCP client. Do not assume the same file configures a cloud Devin session or the newer desktop Agent.
If it does not work
Check the installed product and its current documentation first. A team MCP allowlist can block a server regardless of a valid configuration. If OAuth is unavailable in that version, use another documented MoraWP client.
Approve and check access
First connect a WordPress website in MoraWP. When the client opens sign-in, review the Workspace, websites, and Ability access before approving. Read only limits changes; enabled Integrations may still expose private fields. No static Agent key is needed.
In a new session with MoraWP enabled, ask:
Use MoraWP to list the websites this connection can access.
Do not create, edit, delete, or publish anything.
Check: the intended website appears. Then read one page to check WordPress access. A configured server alone is not proof of a working read.
For missing tools, see Missing Abilities. To stop access, disconnect the Agent in MoraWP and remove its local server entry. Local removal alone is not MoraWP revocation.
Official references
Windsurf's MCP documentation · Current Cascade reference
Vendor instructions reviewed October 9, 2026. Client interfaces and account policies may change.