Windsurf now redirects to Devin Desktop: where Sume MCP setup lives

Windsurf redirects to Devin Desktop, and Cascade was removed in v3.9.19. Re-add Sume's hosted MCP URL there and verify it with mcp_health and tools_list.

4 min readSume
All posts

Windsurf now redirects to Devin Desktop, so a Sume MCP setup that lived in Windsurf should be added again in Devin Desktop with the same URL, https://mcp.sume.com/mcp, and then verified with mcp_health and tools_list.

The Devin Desktop changelog is the source for what changed.

What the changelog says

The changelog entries listed above are the full extent of what this post relies on. For the exact settings screen, use the in-app documentation.

Devin Desktop changelog entries (read 2026-10-03)
EntryWhat it says
RedirectWindsurf now redirects to Devin Desktop.
v3.10.48 (Sep 29)Adds ChatGPT sign-in.
v3.9.19Removed Cascade, making Devin Local the only agent.
MCPMCP from plugins and projects is supported.

Add Sume again

Sume exposes a hosted remote MCP endpoint, and the quickstart's guidance for generic HTTP clients applies. Point a streamable HTTP MCP server at the production URL, then run that client's OAuth login for the configured server name.

The client should discover Sume's protected-resource metadata from the endpoint and send you to https://mcp.sume.com/oauth/authorize, which continues to the consent page on the MCP host.

https://mcp.sume.com/mcp

Verify before you trust it

With Cascade gone and Devin Local as the only agent, check that the agent you will actually use can see Sume's tools.

  • Ask it to call mcp_health and check the auth source.
  • Ask it to call tools_list and summarize the tools it sees.
  • If only read tools appear, Write was off at consent; grant mcp:write for paid tools.
  • Run one paid tool with dry_run=true before any real generation.

Credentials still follow the same rules

Changing editors does not change how Sume treats credentials. OAuth tokens and API keys are different things, and sume login does not broker hosted MCP tokens. An API key works for automation and sees the full tool set, but it should not be pasted into chat.

Paid and write calls need an idempotency_key whichever agent makes them. Keep the key stable across a retry of the same request.

Jobs you started earlier

A move between tools does not affect jobs already submitted. They are durable on Sume's side. Read jobs_list and jobs_status with the ids you saved, and do not resubmit a paid request because the editor changed.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume