Skip to content

Connect Elaichi to VS Code and Windsurf

To connect Elaichi to VS Code and Windsurf, add one URL to each editor's MCP config and sign in with OAuth. No personal API keys on any laptop.

Nachi Raman 6 min read
Diagram of VS Code with GitHub Copilot and Windsurf both pointed at one organization-wide MCP endpoint, each engineer signing in through OAuth, with restrictions between the editors and the connected SaaS accounts

A platform team rarely gets to pick one editor. Half the engineers run GitHub Copilot in agent mode inside VS Code, and the other half run Windsurf. Both agents want Jira, Slack and Sentry. The vendor examples show the usual answer. Windsurf's MCP docs configure a Slack server with a SLACK_BOT_TOKEN in its env block. VS Code's reference shows an Authorization header. Forty engineers and four apps means a lot of tokens in a lot of dotfiles.

How do you connect Elaichi to VS Code and Windsurf without personal API keys?

To connect Elaichi to VS Code and Windsurf, point both editors at one URL, https://api.elaichi.ai/mcp, and have each engineer sign in with OAuth. The config entry holds no key, no header and no client ID. That is how Windsurf and VS Code Copilot reach internal tools without a personal API key on any laptop.

MCP (Model Context Protocol) is the standard way an AI assistant calls tools in other apps. Elaichi serves every connected SaaS account through one organization-wide endpoint, POST /mcp, behind OAuth (a sign-in standard that issues each person a grant instead of a shared password). VS Code Copilot and Windsurf (Devin Desktop) both connect to it.

Sign-in needs a browser. An editor agent or CLI running headless in CI cannot complete it, so plan on interactive use only.

How do you add Elaichi to VS Code?

Run MCP: Add Server from the Command Palette, or add one entry by hand. The guided flow offers .mcp.json, a portable file at the workspace root, or Copilot Global, saved in ~/.copilot/mcp-config.json by default. VS Code's docs say to prefer those portable destinations for new servers (VS Code MCP servers, checked October 2026).

The portable format keeps servers under mcpServers, and the configuration reference lists two required fields for a remote server, type and url:

{
  "mcpServers": {
    "elaichi": {
      "type": "http",
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The older .vscode/mcp.json file uses a top-level servers key instead. Leave out headers, and leave out the oauth block too. That block exists to supply a client ID, and Elaichi needs none, because clients register themselves through dynamic client registration (RFC 7591).

Copy the URL exactly. With a trailing slash the endpoint returns 404, and on app.elaichi.ai it returns 405. Neither starts sign-in. A workspace .mcp.json inherits Workspace Trust, so the server starts once the engineer trusts the repository.

What does a VS Code engineer see at sign-in?

A browser window opens on Elaichi's sign-in, then its consent screen. VS Code's security page says it "implements the MCP authorization specification" for OAuth between VS Code and outside services (VS Code security).

On Elaichi's consent screen, the engineer picks one organization. Then come up to four checkboxes: read data, create and change data, run connected tools, and delete data. Everything requested starts ticked except delete, which never does. Keep Run your connected tools ticked, or the agent reaches no connected app. The request lasts 30 minutes and works once.

To confirm, select Configure Tools in the chat input. If the server fails to start, run MCP: List Servers, pick it and choose Show Output for its logs. Expect a short list. In Elaichi, connected tools are never listed one by one, however few there are. Copilot calls search_tools to find a Jira or Slack tool, then execute_tool to run it.

That shape matters for one VS Code limit. A chat request can have at most 128 tools enabled (VS Code tools), and connected apps add nothing to that count. VS Code may also ask the engineer to confirm tool calls. Every connected app runs through execute_tool, so a prompt on it covers every app. Keep the per-tool decisions in Elaichi's restrictions.

How do you add Elaichi to Windsurf?

Add one entry with url to the MCP config file. Windsurf is named Devin Desktop (Devin Desktop), and it has two agents. Devin Local is the default for new tabs, and Cascade is the legacy agent.

Both agents' docs put the user file at ~/.config/devin/mcp_config.json, or %APPDATA%\devin\mcp_config.json on Windows. Cascade accepts serverUrl or url for a remote server (Cascade MCP docs). Devin Local reads the Devin CLI files, where url is the required field (Devin CLI MCP configuration). So this entry fits both:

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

In Cascade, open the file from the ... menu at the top right of the Cascade panel, then Open MCP config file. For Devin Local, a project's .devin/mcp_config.json is shared through version control. With Devin CLI installed, devin mcp add -s user elaichi https://api.elaichi.ai/mcp writes the user entry for you.

What does a Windsurf engineer see at sign-in?

The same Elaichi consent screen, opened in the browser. Devin's docs say an OAuth server prompts for sign-in the first time it is used, and devin mcp login elaichi starts it directly. Devin's CLI docs say it registers itself through dynamic client registration, so nobody enters a client ID.

Each editor registers itself and signs in on its own, so an engineer signs in once per editor.

To confirm, open the MCPs section of Cascade's ... menu, which shows each server and its enabled tool count. With Devin CLI, devin mcp list shows the configured servers. When stored sign-in credentials expire, the Devin Local MCP list shows Needs auth, and Authenticate runs the browser flow again.

Two Windsurf limits apply. Cascade has a limit of 100 total tools at a time, and Elaichi's connected apps add nothing to it. Devin Local asks for approval before any MCP tool call by default. A permission rule on mcp__elaichi__* covers every connected app at once, because every app runs through execute_tool.

How do you stop engineers pasting personal API keys into editors?

Give them a config with nothing to paste, then close the side door. A committed .mcp.json and .devin/mcp_config.json each hold a public URL and no secret. Every clone carries the same entry, and each engineer still signs in as themselves.

The app credentials live in Elaichi, not on laptops. A member connects each SaaS account once, from a catalog of 500+ connectors that Elaichi authors and serves. A separate credential service holds each account's secrets, encrypted at rest.

Then use each editor's policy so personal servers stop running:

  • VS Code. The ChatMCP policy can limit MCP servers to a curated registry or turn MCP off. Copilot Business and Enterprise organizations can also set MCP access in GitHub organization settings (VS Code AI settings).
  • Windsurf. Once a team admin allowlists one server, every server not on the list is blocked. The allowlist's Server ID must match the entry's key, so name the entry elaichi in every file.

Editor policy decides which servers may run. It cannot see inside Elaichi, so it cannot tell a Jira read from a Jira delete. OAuth versus API keys for AI agents covers the wider case against long-lived keys, and replacing personal MCP servers on laptops covers the cleanup.

Which admin controls cover Claude, ChatGPT, Cursor and both editors?

Elaichi's, because they sit at the endpoint every client shares. Claude, ChatGPT, Cursor, VS Code and Windsurf all reach the same address, so one set of rules governs them.

  • Roles. Each member holds exactly one role, and a role without tool:execute reaches no connected tool.
  • Restrictions. They decide which connectors and which individual tools a target may reach. In Elaichi, restriction targets are role or user only; the organization default is the absence of a rule, which means allow everything. A change takes about two minutes to apply.
  • Audit log. Elaichi writes one entry per tool-call attempt, succeeded or failed, naming the engineer and the account the call reached. Each entry records the surface and the OAuth client. VS Code's vscode.dev redirect forwards the code to whatever the request names, so Elaichi cannot verify the client name. Its calls show the name VS Code registered with, marked unverified.
  • Revocation. In Elaichi, removing or suspending a member revokes every live grant in the same transaction as the membership change, so that engineer's next call from either editor fails.

MCP for coding agents across an engineering org goes further into frozen arguments and team rollouts.

Which errors come up most in VS Code and Windsurf?

Most failures are the URL, an expired request or a missing checkbox. Each has a quick fix:

  • Sign-in never opens. Check for a trailing slash or the app host. Devin CLI retries over SSE after a 404 or 405, so a wrong URL there can surface as an SSE error.
  • The consent screen says the request is no longer valid. It expired or was used. Start the sign-in again from the editor.
  • A tool error names a checkbox. Reconnect and tick it. In Windsurf, run devin mcp logout elaichi, then devin mcp login elaichi.
  • The list is empty for a whole role. The role may lack tool:execute, which an admin fixes.
  • A 429 mid-task. Elaichi allows 120 MCP requests a minute per token. Wait a minute.

What each OAuth error means lists who fixes each one, and the missing-tools checklist walks an empty list in order.

When is Elaichi more than an editor team needs?

When one engineer uses one app that runs its own OAuth MCP server. That server is enough until a second app, a contractor or an audit question arrives. When you don't need an MCP gateway yet lists the signals.

GitHub is not in Elaichi's connector catalog. VS Code's own docs use GitHub's server as their example, and that server sits beside Elaichi, outside its restrictions and audit log.

Gold lists at $15 per user per month in USD, and the pricing page shows your region's price. Gold starts with a 14-day trial, no credit card to start. Checkout does collect a card, and it sets the paid trial to the remaining days rather than granting a fresh 14, so it is one continuous trial rather than two. The same address works in the Cursor setup, the Claude Code setup and the Codex setup. For the wider picture, read what an MCP control plane is, or start from the Jira connector and the Slack connector.

FAQ

Frequently asked questions

How do you give Windsurf and VS Code Copilot access to internal tools without personal API keys?

Connect each app once in Elaichi, then point both editors at Elaichi's endpoint, https://api.elaichi.ai/mcp. Each engineer signs in with OAuth in the browser, so the config file holds only a URL. The app credentials stay in Elaichi's credential service, encrypted at rest, and never reach a laptop.

What admin controls does IT get for MCP connectors across Claude, ChatGPT and Cursor?

With Elaichi, one set: roles decide what each person may do, restrictions decide which connectors and individual tools a role or user may reach, and the audit log records every tool call with the person and the account it reached. All of it applies at the one endpoint every client uses, so Claude, ChatGPT, Cursor, VS Code and Windsurf share the same rules.

How do you stop employees from sharing personal API keys with AI tools?

Remove the reason to have one. Give each AI client a config that holds only an OAuth-protected URL, connect the apps once in a control plane such as Elaichi, and use the client's own policy to stop other servers from running. VS Code has an MCP access policy, and Windsurf has a team allowlist that blocks every server not on it.

Can VS Code or Windsurf use Elaichi in CI?

No. Elaichi's sign-in needs a browser, so an editor agent or CLI running headless in CI cannot complete it. Each engineer signs in from a machine where they can open the browser.

Why do VS Code and Windsurf show only a few Elaichi tools?

In Elaichi, connected tools are never listed one by one, however few there are. The agent finds a connected tool with search_tools and runs it with execute_tool, so a short list is expected. It also means adding Jira, Slack or Sentry adds no tools to the editor's tool count.

Put agents to work on your own systems

14 days on Gold, no credit card. Start with one app and one team.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.