30 days free. No credit card. Full access from the moment you connect your site.

Start free trial

Connect Windsurf to WordPress

Connect Windsurf to WordPress — AcrossAI setup guide

Connect Windsurf to your own WordPress site over the Model Context Protocol. Windsurf talks to your site directly — there is no relay in between, no account to create, and your credentials never leave your machine. Setup takes about a minute once MCP Manager is installed.

Free plugin · No account · Runs on your own server · Any WordPress host

Config file

~/.codeium/windsurf/mcp_config.json

Top-level key

mcpServers

Transport

npx bridge over HTTP

Before you start

You need AcrossAI MCP Manager installed and active on the WordPress site you want Windsurf to reach, plus an administrator account on that site. If you have not installed it yet, follow the Get Started guide first — it takes about a minute, and the MCP server ships bundled with the plugin.

You also need Node.js available on the machine running Windsurf, because the connection runs through an npx bridge. Nothing is installed permanently — npx fetches the bridge on demand. Windsurf is built by Codeium, and its configuration lives under ~/.codeium/ rather than a folder named after the editor.

How to connect Windsurf to WordPress

Step 1

Open Quick Connect and choose Windsurf

In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. Pick Windsurf from the client list. Everything below is generated for you with your real site URL and username already filled in — the snippets here are only so you know what to expect.

Step 2

Generate an Application Password

Click Generate password in the wizard. This creates a standard WordPress Application Password — not your login password — scoped to this connection and revocable at any time from your user profile.

The password is shown once, at creation. Copy it whole, including the spaces — WordPress accepts them. If you lose it, generate a new one rather than trying to recover it.

Step 3

Paste the config into ~/.codeium/windsurf/mcp_config.json

Copy the JSON from the wizard, open ~/.codeium/windsurf/mcp_config.json — create the file, and the ~/.codeium/windsurf/ folder, if they do not exist — and paste the entry under the mcpServers key. If you already have other MCP servers configured, add this one alongside them rather than replacing the file.

You can reach the same file from inside the editor: open the Cascade panel, then the plugin or MCP settings, and choose the option to edit the raw configuration. The generated config looks like this, with your own values in place of the placeholders:

{
  "mcpServers": {
    "your-site-mcp-adapter-default-server": {
      "command": "npx",
      "args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
      "env": {
        "WP_API_URL": "https://example.com/wp-json/acrossai/mcp",
        "WP_API_USERNAME": "your-wp-username",
        "WP_API_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx"
      }
    }
  }
}

Note the directory: ~/.codeium/, named after Codeium, who build Windsurf. A file at ~/.windsurf/mcp_config.json is never read.

Step 4

Restart Windsurf and open Cascade

Quit Windsurf completely and start it again so it reads the new configuration. Open Cascade, the agent panel — that is where MCP tools appear and where you talk to your site. Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.

Reloading the window is not the same as restarting. Windsurf reads mcp_config.json when the application starts, so a reload can leave you looking at the old tool list.

What Windsurf can do once it is connected

With Abilities Manager installed alongside it, Windsurf reaches 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. From Cascade, without switching to a browser tab, it can:

  • Read and edit content — posts, pages and any custom post type with their meta and revisions, and surgically edit a page’s block tree without rewriting the page.
  • Debug a broken site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
  • Inspect the database — schema and table sizes, index health, bloated autoloaded options, or EXPLAIN on a slow query.
  • Manage plugins, themes and core — search WordPress.org, install, update, roll back, and verify files against official checksums.
  • Work with files — inside an allowlist you define, with a dangerous-extension blocklist and optional pre-image backups of everything it touches.
  • Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.

Every ability runs WordPress’s own capability check for the calling user, so Windsurf can never do anything your account could not already do. See the full platform overview for the complete catalogue.

Frequently asked questions

Is connecting Windsurf to WordPress free?

Yes. AcrossAI MCP Manager and Abilities Manager are both free and GPL on WordPress.org, and there is no AcrossAI account to create. You use the Windsurf plan you already have — AcrossAI never charges for AI inference, because none of it runs here.

Does my site data pass through AcrossAI servers?

No. Windsurf connects straight to your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry. Whatever Cascade reads is still processed by your AI provider, so treat it as you would any other prompt.

Does it work on any WordPress host?

Yes, provided you can reach wp-admin. Shared hosting, VPS and managed WordPress all work, because everything runs inside your own install. MCP Manager needs WordPress 7.0 or later and PHP 8.1 or later; Abilities Manager needs WordPress 6.9 or later.

Can Windsurf break my site?

Every ability runs WordPress’s own capability check for the calling user, so Windsurf can never exceed what your account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, search-and-replace is a dry run by default, and any ability can be disallowed site-wide.

How do I disconnect Windsurf again?

Revoke the Application Password from your WordPress user profile, or remove the entry from ~/.codeium/windsurf/mcp_config.json. Access is re-checked on every request, so revoking takes effect immediately even if the config is still on the machine.

Troubleshooting

Windsurf does not list the server at all

Nine times out of ten the file is in the wrong place. Windsurf reads ~/.codeium/windsurf/mcp_config.json — the folder is named after Codeium, who build the editor, so a file saved at ~/.windsurf/mcp_config.json is simply ignored, with no error to tell you so. Check the path first, then check the file is valid JSON: a trailing comma or a missing brace makes Windsurf skip the whole file silently. Confirm your entry sits under mcpServers and not at the root.

Cascade shows no new tools after I edited the config

Windsurf loads mcp_config.json when the application starts. Reloading the window, or closing and reopening the Cascade panel, does not re-read it — quit Windsurf entirely and launch it again. If the MCP settings screen offers a refresh control, use that, but treat a full restart as the reliable answer after any config change.

The server appears but has no tools

That is the connection working and the catalogue being empty. Either Abilities Manager is not installed — MCP Manager will serve an empty catalogue quite happily — or the abilities exist but are not exposed to this particular server. Open AcrossAI → MCP, select the server, and check its Tools and Abilities tabs. After changing what a server exposes, restart Windsurf: MCP clients receive their tool list once, at connection time.

Authentication fails

Application Passwords are shown once and are not your login password. Generate a fresh one from Quick Connect rather than retyping an old one, and copy it complete with spaces. If the request is being refused rather than failing, check the server’s access rules — a new server requires manage_options until you add a rule, and the gate fails closed. Access is re-checked on every request, so a role change takes effect straight away.

npx is not found

The bridge runs through npx, which ships with Node.js. Install Node.js on the machine running Windsurf and restart it. If Node is installed through a version manager such as nvm, Windsurf launched from the desktop may not inherit your shell’s PATH — in that case point command at the absolute path to npx. On a local development site with a self-signed certificate, add "NODE_TLS_REJECT_UNAUTHORIZED": "0" to the env block; never do this against a production site.

Connect a different AI client

The same server works with every MCP client — only the config file and top-level key change. See the guides for Claude Desktop, Claude Code, Cursor, VS Code, GitHub Copilot, Zed, Codex and every other client.

Not installed yet?

Install MCP Manager on your site, then come back and run Quick Connect.


Keep reading