---
canonical: https://docs.jentic.com/guides/mcp/windsurf-remote/
representation: markdown-alternate
# Canonical page: https://docs.jentic.com/guides/mcp/windsurf-remote/
# This is the Markdown alternate of the page above.
title: "Use Jentic MCP Tools in Windsurf"
description: >-
  Enable Jentic remote MCP tools in Windsurf with OAuth or an API key so you can search,
  load, and execute thousands of external APIs inside your coding workflow.
---

# Jentic + Windsurf

> **Goal** — Connect Windsurf to Jentic's URL-based MCP servers: the **hosted directory** for natural-language discovery before you've installed anything, and your **self-hosted Jentic One** as a custom connector for the full **search → inspect → execute** loop against your registry.

Windsurf's MCP server configuration points a client at an MCP server over HTTP with an `Authorization` header — which is exactly the shape both Jentic surfaces expose.

## 1. Hosted directory search (discovery)

Add the hosted MCP server to Windsurf's MCP config to search the public Jentic API directory in natural language — *"find an operation that creates a GitHub issue"* — and get back concrete API operations:

```json
{
  "mcpServers": {
    "jentic": {
      "url": "https://api.jentic.com/mcp"
    }
  }
}
```

No token to configure — the hosted server uses OAuth (Dynamic Client Registration), so Windsurf registers itself and prompts you to authorize on first connect.

This surface is for discovery before you've installed anything — which API and which operation solves the task. It reads the public directory and does not touch your registry or credentials.

## 2. Self-hosted Jentic One (full search → inspect → execute)

For the full loop against your own registry — **search** your imported operations, **inspect** a contract, then **execute** it — connect a **self-hosted Jentic One** instance whose operator has enabled the hosted `/mcp` endpoint (`server.mcp.enabled: true`). How it authenticates depends on the deployment:

**OAuth (no token to paste)** — if the operator also set `server.mcp.oauth.enabled: true`, the endpoint uses OAuth with Dynamic Client Registration, like the hosted directory. Windsurf registers itself and prompts you to authorize on first connect (the self-registered client waits for operator approval unless `auto_approve_clients` is on):

```json
{
  "mcpServers": {
    "jentic": {
      "url": "https://<your-jentic-one-host>/mcp"
    }
  }
}
```

**Manual bearer** — with only `server.mcp.enabled: true` (OAuth off), supply the agent's bearer per request:

```json
{
  "mcpServers": {
    "jentic": {
      "url": "https://<your-jentic-one-host>/mcp",
      "headers": { "Authorization": "Bearer <agent-api-key>" }
    }
  }
}
```

The agent's bearer comes from registering it against your instance (`jentic register`). Credentials for the upstream APIs are decrypted only inside your Broker at execution time — they never pass through the Windsurf session. See the [MCP overview](./remote-mcp.md) and the [Quickstart](../../getting-started/quickstart.md) to stand up an instance and register an agent.

> If the endpoint is not enabled on your deployment, Windsurf's URL entry cannot reach it (the control plane answers 404 on `/mcp` by default). Enable it in the backend config, or drive the instance from a CLI-capable runtime instead — see the [MCP overview](./remote-mcp.md).

## Support

- **Discord:** [https://discord.com/invite/TdbWXZsUSm](https://discord.com/invite/TdbWXZsUSm)
