Windsurf
Windsurf connects to MCP servers through its Cascade
agent. Servers are defined in ~/.codeium/windsurf/mcp_config.json, which you can
open from Windsurf Settings → Cascade → Manage MCP servers → View raw config.
Hosted server (header token)
Section titled “Hosted server (header token)”Add a remote server. Windsurf uses serverUrl (not url) for the endpoint,
alongside a headers object:
{ "mcpServers": { "oceanum-datamesh": { "serverUrl": "https://mcp.oceanum.io/datamesh", "headers": { "X-DATAMESH-TOKEN": "your-datamesh-token" } } }}Replace your-datamesh-token with your Datamesh token.
Windsurf supports the ${env:VAR} syntax in serverUrl and headers if you
prefer to keep the token in an environment variable. After saving, press
Refresh in the MCP panel.
The hosted server is read-only and returns query_data results inline (up to
~50 MB), so large results can’t come back in the conversation. To get large
data, call export_query: on the hosted server it returns a time-limited
download link to the full result, which you fetch out-of-band (e.g. with
curl) — the link needs no token, so treat it like a password. The
local server below instead writes export_query output to
a file on your machine.
Local server (stdio)
Section titled “Local server (stdio)”For full read/write, and to have export_query write results straight to a file
on your machine (NetCDF, Parquet or CSV) rather than return a download link, run
the server locally:
{ "mcpServers": { "oceanum-datamesh": { "command": "uvx", "args": ["oceanum-mcp", "datamesh"], "env": { "DATAMESH_TOKEN": "your-token-here" } } }}This requires uv on your PATH.
Keep your token safe
Section titled “Keep your token safe”Your Datamesh token grants access to all of your organisation’s permissioned datasources — including the ability to modify or delete them. Treat it as a secret, and prefer the hosted read-only server for exploratory use.