Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Windsurf

Connect Windsurf Cascade to the Probo MCP server

View as Markdown

Windsurf Cascade supports remote HTTP MCP servers. Connect it directly to Probo with the MCP endpoint and a Bearer token.

  • A current version of Windsurf
  • Access to a Probo instance
  • A scoped Probo OAuth token

Choose the endpoint for your Probo environment:

Environment MCP URL
Probo US https://us.probo.com/api/mcp/v1
Probo EU https://eu.probo.com/api/mcp/v1
Custom https://your-probo-instance.com/api/mcp/v1

The /v1 segment is required.

  1. Create a Probo OAuth token

    In Probo, open your account menu, select OAuth tokens, and create a scoped token named Windsurf. See Authentication for scope and expiration guidance.

  2. Set the token in your environment

    Terminal window
    export PROBO_API_TOKEN="your_api_token_here"

    Restart Windsurf after setting the variable so the application can read it.

  3. Open the MCP configuration

    In the Cascade panel, open MCPs and select View Raw Config. Windsurf stores this configuration at:

    ~/.codeium/windsurf/mcp_config.json
  4. Add the remote server

    {
    "mcpServers": {
    "probo": {
    "serverUrl": "https://us.probo.com/api/mcp/v1",
    "headers": {
    "Authorization": "Bearer ${env:PROBO_API_TOKEN}"
    }
    }
    }
    }

    Replace the URL if you use the EU region or a self-hosted instance.

  5. Refresh the server list

    Save the file, return to the MCP panel, and click Refresh. Confirm that probo is connected and enable the tools you want Cascade to use.

Start with a read-only request:

Use Probo to list the organizations I can access.

Cascade should ask for approval before running the tool and then return your Probo organizations. You can also ask:

List the open risks for organization org_xxx.
Summarize overdue compliance tasks without changing anything.

Give each environment its own server name and token:

{
"mcpServers": {
"probo-development": {
"serverUrl": "http://localhost:8080/api/mcp/v1",
"headers": {
"Authorization": "Bearer ${env:PROBO_DEV_TOKEN}"
}
},
"probo-production": {
"serverUrl": "https://us.probo.com/api/mcp/v1",
"headers": {
"Authorization": "Bearer ${env:PROBO_PROD_TOKEN}"
}
}
}
}

Use distinct token names so credentials cannot be sent to the wrong instance.

  • Open the configuration through MCPs → View Raw Config to confirm you edited the active file.
  • Validate the JSON and click Refresh.
  • Restart Windsurf after changing environment variables.
  • Confirm the environment variable is available to the Windsurf process.
  • Confirm the header begins with Bearer .
  • Generate a new token if the existing token was revoked or expired.

Confirm that serverUrl ends in /api/mcp/v1. The unversioned /api/mcp route is not a valid Probo MCP endpoint.

  • Confirm the individual tools are enabled in the MCP panel.
  • Confirm your Probo role can access the requested organization and operation.
  • Test the same endpoint with the MCP Inspector.

For Windsurf-specific configuration behavior, see the Windsurf MCP documentation.