Guides8 min read

Best MCP Servers for Windsurf IDE in 2026

Top MCP servers for Windsurf, Codeium's AI-powered IDE. Database access, GitHub integration, browser automation, and web search — step-by-step configuration.

By MyMCPTools Team·

Windsurf is Codeium's AI-first IDE — built from the ground up for developers who want an agentic coding experience without the context-switching tax of external tools. Its Cascade agent can plan multi-step tasks, write code, run terminal commands, and iterate on feedback. Connect MCP servers and Windsurf becomes something more powerful still: an IDE with direct access to your databases, browsers, APIs, and version control, all without leaving your editor.

This guide covers the best MCP servers for Windsurf in 2026, how to configure them, and the workflows they unlock.

How Windsurf Handles MCP Servers

Windsurf supports MCP servers through its Cascade configuration panel. Once connected, the Cascade agent can invoke MCP tools as part of its planning and execution loop. Unlike passive AI completions, Cascade actively uses MCP tools to gather information, take action, and verify results — all as part of a single conversation thread.

Configure MCP servers through Windsurf's settings: Settings → Cascade → MCP Servers. The configuration format is identical to Claude Desktop's JSON format, so any server that works there will work in Windsurf.

1. Filesystem MCP Server — Essential Foundation

The Filesystem server is the starting point for any Windsurf MCP setup. While Windsurf's native editor access already gives Cascade read/write capability within open files, the Filesystem MCP server extends this to structured directory operations — listing, reading metadata, and navigating project structure programmatically.

Why it matters: Cascade's multi-file refactoring and code generation tasks work best when it can survey the full project structure rather than only the files you've opened. The Filesystem server makes this survey fast and explicit.

Setup:

{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem", "/path/to/your/project"]
    }
  }
}

2. GitHub MCP Server — Full Repository Control

The GitHub MCP server gives Cascade the ability to manage your repositories without leaving the IDE. Create branches, commit changes, open pull requests, review diffs, and manage issues — the complete PR workflow inside Windsurf.

Power workflows with Windsurf + GitHub MCP:

  • Ask Cascade to "implement this feature, create a branch, and open a PR with a description" — it handles the entire flow
  • Have Cascade review an open PR's diff and suggest test cases
  • Search across your org's repos for prior implementations before writing new code
  • Let Cascade draft release notes from recent merged PRs

Setup:

{
  "mcpServers": {
    "github": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": { "GITHUB_PERSONAL_ACCESS_TOKEN": "your-token-here" }
    }
  }
}

3. PostgreSQL MCP Server — Schema-Aware Database Work

Database queries are where Windsurf's Cascade agent truly earns its keep. The PostgreSQL MCP server lets Cascade inspect your actual schema — table names, column types, relationships, indices — before writing SQL, ORM code, or migration scripts. No more generated queries that fail because of a column name mismatch.

What becomes possible:

  • Ask "write a migration that adds soft delete to the orders table" — Cascade reads the existing schema and writes the correct migration
  • Debug a failing query by having Cascade explain the execution plan
  • Generate ORM models directly from an existing database schema

4. Playwright MCP Server — Browser Testing in Your Agent Loop

The Playwright MCP server gives Cascade the ability to control a real browser. After making frontend changes, Cascade can navigate to your dev server, interact with the UI, and verify that its changes work visually — closing the loop without requiring manual testing between every iteration.

Key workflows:

  • Build a component in Windsurf, then have Cascade navigate to localhost and screenshot the result
  • Write an end-to-end test and have Cascade run it against your dev environment
  • Scrape API documentation from external sites when docs aren't available in text format
  • Test form submissions and verify the full user flow after implementing a feature

5. Git MCP Server — Version Control Context

The Git MCP server gives Cascade direct access to your repository's commit history, diffs, and branch state. This context is invaluable for understanding why code was written a certain way — blame and log tell the story that comments usually don't.

Useful for:

  • Understanding which commit introduced a bug ("find when this function's signature changed")
  • Generating meaningful commit messages based on actual diffs
  • Reviewing your own changes before opening a PR

6. Brave Search MCP Server — Live Documentation Lookup

Windsurf's Cascade has a training data cutoff. The Brave Search MCP server fills the gap — when Cascade needs current library documentation, recent error message solutions, or updated API references, it can search the web in real time.

Most useful when:

  • Working with libraries that have released breaking changes since Cascade's training cutoff
  • Looking up recent Stack Overflow answers for specific error messages
  • Verifying that a proposed API pattern is still recommended in the current version

7. SQLite MCP Server — Local Development Databases

For projects using SQLite — common in local development, mobile apps, or smaller self-contained tools — the SQLite MCP server gives Cascade direct query access. Useful for inspecting test fixtures, verifying migration outputs, and debugging data-layer issues without switching to a separate database client.

8. Docker MCP Server — Container Management

The Docker MCP server lets Cascade interact with running containers and compose stacks. When debugging a containerized application, Cascade can check container logs, inspect environment variables, and verify service health — all as part of its diagnostic reasoning loop.

9. Redis MCP Server — Cache Debugging

The Redis MCP server gives Cascade read access to your Redis instance. Useful for debugging caching issues, inspecting session state, or verifying that cache invalidation logic works correctly after implementing changes in Windsurf.

Recommended Windsurf MCP Stack

Start here:

  1. Filesystem — project navigation foundation
  2. GitHub — complete PR workflow without leaving the IDE
  3. PostgreSQL or SQLite — database-aware code generation
  4. Brave Search — current documentation lookup

Add Playwright for frontend work, Docker for containerized environments, and Redis as your stack grows in complexity. Avoid loading every available server at once — each server adds tools to Cascade's context, and more isn't always better.

Windsurf vs Other MCP Clients

Windsurf's Cascade agent is agentic by design — it plans multi-step tasks and executes them, not just completes individual prompts. This makes MCP particularly powerful in Windsurf compared to passive clients: Cascade can chain multiple MCP tool calls together as part of a single task without waiting for you to approve each step.

See the full Windsurf MCP server integration list or browse coding category servers for more developer tools. Also see Best MCP Servers for Cline and Best MCP Servers for Cursor for comparison.

Recommended Tools

Better Stack

Free Plan

Get alerted when your APIs, browser tests, payment pipelines, or MCP server dependencies go down. Used by 100K+ developers.

Start monitoring free →

1Password

14-day Free Trial

Store and inject API keys, payment credentials, tokens, and file access secrets into your MCP server configs. Trusted by 150K+ developers.

Try 1Password free →

🔧 MCP Servers Mentioned in This Article

📁

Filesystem MCP Server

sandboxed read, write, edit, move and search access to an explicit whitelist of local directories, and it is the reference implementation most other filesystem MCP servers are modelled on. Shipped by Anthropic in the official modelcontextprotocol/servers monorepo (89,000+ stars, actively maintained), it is a Node.js server published to npm as @modelcontextprotocol/server-filesystem. The part worth understanding before you install is the access-control model, because there are now two ways to grant directories and they do not compose. Method one is command-line arguments: `npx -y @modelcontextprotocol/server-filesystem /path/one /path/two`. Method two, and the one the maintainers recommend, is MCP Roots — a client that supports the roots protocol sends its roots at initialization, and those roots COMPLETELY REPLACE any directories passed on the command line, then get replaced again on every `notifications/roots/list_changed`. That means allowed directories can change at runtime without restarting the server, but it also means a roots-capable client silently overrides your CLI arguments. If the server starts with no arguments and the client either does not support roots or sends an empty list, initialization throws an error. The tool surface is broad: `read_text_file` (with mutually exclusive `head`/`tail` line windows), `read_media_file` returning base64 image/audio content blocks, `read_multiple_files` which keeps going when individual reads fail, `write_file`, `edit_file`, `create_directory`, `list_directory`, `list_directory_with_sizes`, `move_file`, `search_files`, `directory_tree`, `get_file_info` and `list_allowed_directories`. `edit_file` is the one to learn — it does line-based and multi-line pattern matching with indentation detection and preservation, returns a git-style diff with context, and supports `dryRun: true` so you can preview a change before applying it; the maintainers recommend always running a dry run first. Every operation is refused outside the allowed set, and `list_allowed_directories` is the fastest way to confirm what the server actually believes it can touch.

Local
💻

GitHub MCP Server

authenticated access to the whole GitHub platform — repositories, files, branches, issues, pull requests, Actions runs, security alerts, discussions and notifications — from Claude, Cursor, VS Code, Copilot CLI and any other MCP host. There is no npm package for this server, and that trips up most people who try to install it: `@github/mcp-server` is not published to the npm registry, so any `npx` line you find for it will fail. GitHub ships it three other ways. The easiest is the hosted remote server at https://api.githubcopilot.com/mcp/, which needs no install at all — point an HTTP-transport MCP client at that URL and log in with OAuth (VS Code 1.101+, Claude Desktop, Claude Code, Cursor and Windsurf all support this). The second is the official Docker image ghcr.io/github/github-mcp-server, which is what the copy-paste command on this page runs; on github.com it now performs a browser-based OAuth login on first use and keeps the token in memory only, which is why the published Docker configs map a fixed loopback callback port (-p 127.0.0.1:8085:8085 with GITHUB_OAUTH_CALLBACK_PORT=8085) so the container can receive the callback. Prefer a token? Set GITHUB_PERSONAL_ACCESS_TOKEN instead — it takes precedence over OAuth, and the minimum useful scopes are repo, read:org and read:packages. The third is the native Go binary from the repository's releases, which needs no fixed port for the OAuth flow. GitHub Enterprise Server has no hosted option: use the local server with --gh-host or GITHUB_HOST set to your instance (include the https:// scheme — it defaults to http://, which GHES rejects). Toolsets can be narrowed with GITHUB_TOOLSETS, and an insiders channel is available at /mcp/insiders or via the X-MCP-Insiders header.

Auth required📘
🗄️

PostgreSQL MCP Server

The PostgreSQL MCP server was the Model Context Protocol reference server for Postgres, and it is retired: the source now sits in modelcontextprotocol/servers-archived — a repository GitHub reports as archived, described as "Reference MCP servers that are no longer maintained" — and the npm package @modelcontextprotocol/server-postgres carries a deprecation notice reading "Package no longer supported." It still installs and still runs, which is why most third-party setup articles have not caught up. What it provides is deliberately small: a single tool, query, which executes read-only SQL inside a READ ONLY transaction, plus per-table schema information exposed as MCP resources at postgres://<host>/<table>/schema, with column names and data types discovered from database metadata. There is no index advice, no health check, no separate schema-listing tool, and no write mode. Install is npx @modelcontextprotocol/server-postgres with a postgres:// connection string as the argument. For active work against Postgres, the maintained alternative is Postgres MCP Pro (crystaldba/postgres-mcp), which exposes nine tools including index tuning against hypothetical indexes and a database health check, and has an explicit restricted access mode; if your database is hosted on Supabase or Neon, their platform servers add branching and logs that a raw Postgres connection cannot see. Reach for this archived server only when you want the smallest possible surface — one process, one read-only query tool, nothing else.

Local📘
🌍

Playwright MCP Server (ExecuteAutomation)

ExecuteAutomation's Playwright MCP Server is a community-maintained browser automation server (5,500+ GitHub stars) distinct from Microsoft's official microsoft/playwright-mcp — it leans further into test generation and visual workflows rather than pure accessibility-tree navigation. Beyond standard navigate/click/fill/screenshot tools, it can generate Playwright test code from a live browsing session, scrape full page content and structured data, execute arbitrary JavaScript in the page context, and drive API testing (GET/POST/PUT/PATCH/DELETE requests) alongside the browser tools. A standout feature is 143 real device presets for responsive testing — a single call like playwright_resize({ device: "iPhone 13" }) swaps in the correct viewport, user-agent, touch support, and device pixel ratio, and natural-language prompts like "test on iPad landscape" work directly through Claude. Install via `npm install -g @executeautomation/playwright-mcp-server`, Smithery, mcp-get, or the one-line `claude mcp add --transport stdio playwright npx @executeautomation/playwright-mcp-server` for Claude Code; VS Code one-click installers are also published. No API keys are required — it launches and drives a local Chromium/Firefox/WebKit browser directly. Choose this over Microsoft's official server when you specifically need auto-generated Playwright test scripts, JS execution, or device-emulation testing; choose Microsoft's for pure lightweight accessibility-tree page navigation. One maintenance fact the listings omit, checked against GitHub and npm on 2026-08-15: this repository has not been pushed since 2025-12-13 and npm 1.0.12 was published 2025-12-12, with 32 issues open. It is neither archived nor deprecated, so nothing warns you at install time — it installs, connects and works while its Playwright dependency drifts, whereas Microsoft's server ships continuously. Weigh the codegen, 143-preset device emulation and HTTP request tools against running an eight-month-old build. Note also that headless defaults to false on playwright_navigate, so it opens a visible browser window unless told otherwise, and that stdio-mode logging goes only to ~/playwright-mcp-server.log to keep the JSON-RPC stream clean.

Local📘
💻

Git

Tools to read, search, and manipulate Git repositories. Full Git operations support.

Local
🔍

Brave Search MCP Server

The Brave Search MCP Server is the official server from Brave that gives AI assistants privacy-first web search through the independent Brave Search API — no tracking, no profiling, and results drawn from Brave's own web index rather than Google or Bing. It exposes five distinct tools that map directly to the Brave Search API endpoints: brave_web_search for general queries with pagination, freshness filters, and safe-search controls; brave_local_search for businesses, restaurants, and points of interest with automatic location filtering; brave_news_search for recent articles and current events; brave_image_search for image discovery; and brave_video_search for finding videos across the web. Authentication uses a single BRAVE_API_KEY (free tier available at brave.com/search/api) or a mounted BRAVE_API_KEY_FILE for Docker-secret setups. Install in Claude Desktop, Cursor, Windsurf, or VS Code with one npx command and choose stdio or streamable-HTTP transport. Because Brave operates its own crawler and index, the Brave Search MCP server is a strong choice for developers who want an alternative to Google-dependent search tools, need reproducible non-personalized results, or care about data privacy in agent workflows — Claude can pull fresh web context, verify facts, and research topics without leaking queries to ad-tech pipelines.

Local
🔧

Docker MCP Server

The Docker MCP server (ckreiling/mcp-server-docker) gives an AI assistant direct control of a Docker daemon over the Model Context Protocol: containers, images, networks and volumes, as tools rather than shell commands. It is the community server most people mean by "Docker MCP" — distinct from Docker’s own Docker MCP Gateway, which does not manage your containers at all but runs *other* MCP servers inside containers. If you want to ask Claude why the postgres container keeps restarting, you want this one; if you want a single secure endpoint in front of twenty catalog servers, you want the gateway. The tool surface is explicit and small enough to reason about: list_containers, create_container, run_container, recreate_container, start_container, fetch_container_logs, stop_container and remove_container for containers; list_images, pull_image, push_image, build_image and remove_image for images; list_networks / create_network / remove_network and list_volumes / create_volume / remove_volume for the rest. Two resource templates, docker://containers/{id}/logs and docker://containers/{id}/stats, let a client read logs and live stats by container ID or name without a tool call. It also ships a docker_compose prompt that puts the model into a plan-then-apply loop — you describe the containers you want under a project name, the model proposes a concise plan, and nothing runs until you approve it; reopening the prompt with the same project name re-reads the state of everything created under it, which is how you clean up after a lost chat. It runs on the Python Docker SDK’s from_env, so DOCKER_HOST applies: set ssh://user@host and the same server administers a remote engine. Two limits are deliberate and stated by the project — privileged options like --privileged and --cap-add/--cap-drop are not supported, and container configuration passes through the model, so no secrets belong in it.

Local📘
🗄️

SQLite MCP Server

conversational read and write access to any SQLite database file, plus a running business-insights memo that accumulates what the analysis turns up. It is a Python server on PyPI, not a Node one, and the difference is the single most common reason setups fail here: `@modelcontextprotocol/server-sqlite` does not exist on npm, so every npx line for it 404s. The working invocation is `uvx mcp-server-sqlite --db-path /path/to/database.db` (PyPI package mcp-server-sqlite, v2025.4.25), or the equivalent `mcp/sqlite` Docker image with a volume mounted at /mcp. The --db-path argument is required and points at the .db file; the server will create it if it is not there yet. Six tools are exposed, deliberately split by risk: read_query for SELECT only, write_query for INSERT/UPDATE/DELETE, create_table for DDL, list_tables and describe-table for schema introspection, and append_insight, which writes into a memo://insights resource that updates live as findings accumulate — that resource, not the SQL tools, is what makes this server different from a generic database connector. It also ships an mcp-demo prompt that takes a business topic, generates a plausible schema and sample data, and walks through an analysis end to end, which is the fastest way to see the memo behaviour without wiring up real data. One caveat to weigh before adopting it: this is an Anthropic reference implementation that now lives in modelcontextprotocol/servers-archived, archived on 2025-05-28. The published package still installs and runs, but it is frozen — no new features, no dependency updates, and no security patches.

Local
🗄️

Redis MCP Server

The Redis MCP Server (redis/mcp-redis) is Redis's own natural-language interface for agentic applications, letting an AI client read and write Redis data over the Model Context Protocol. Note which one you install: the server most tutorials still point at is Anthropic's reference implementation, which now lives in modelcontextprotocol/servers-archived, and its npm package @modelcontextprotocol/server-redis is explicitly marked "Package no longer supported" with a last publish of 2025-04-25. The maintained server is a Python package instead, run with uvx --from redis-mcp-server@latest, and it covers far more of Redis than the reference one did: string, hash, list, set and sorted-set tools; JSON document tools; pub/sub with stateful channel and pattern subscriptions; Streams tools including consumer-group create, read, acknowledge and destroy; vector index management and vector search through the query engine; a docs search tool; and a server-management tool for database info. Connection is a redis:// or rediss:// URL passed as --url, or the REDIS_HOST/REDIS_PORT/REDIS_PWD/REDIS_SSL environment variables, with Redis Cluster mode behind REDIS_CLUSTER_MODE and EntraID service-principal, managed-identity and default-credential auth flows for Azure Managed Redis. There is no --read-only flag: the documented way to stop an agent writing is a Redis ACL user (ACL SETUSER readonlyuser on >pw ~* +@read -@write). Ships as a PyPI package, a GitHub install via uvx, and an official mcp/redis Docker image; stdio transport only.

Local📘

📚 More from the Blog