Windsurf and Devin Desktop MCP client setup ​
Use remote Streamable HTTP with OAuth for interactive desktop sessions. Use a bearer header only when the host path cannot complete OAuth.
OAuth config ​
json
{
"mcpServers": {
"orkestia-workflow": {
"serverUrl": "https://mcp.orkestia.dev/mcp"
}
}
}Some host versions use url instead of serverUrl; keep the endpoint value the same.
Header-token fallback ​
json
{
"mcpServers": {
"orkestia-workflow": {
"serverUrl": "https://mcp.orkestia.dev/mcp",
"headers": {
"Authorization": "Bearer ${ORKESTIA_AGENT_TOKEN}"
}
}
}
}Do not put long-lived user tokens in shared config. Prefer per-agent tokens for unattended use.
Smoke test ​
Verify whoami, list_workflow_types, and get_workflow_schema. Then start only a harmless or dry-run workflow until approval behavior is confirmed.
