Connect Windsurf to Guard.ch
Set up browser access once. Then ask Windsurf to work in a browser or continue a session you already opened.
What you need
A Guard.ch account with MCP access enabled and an app key from that account. Your agent can access your own sessions.
Install Windsurf and sign in to use Cascade.
1. Create an app key
Open the Agents page in your dashboard and choose Create a key. Give it a name, such as your agent name. Copy the key before closing the window. It is only shown once.
Create a key2. Add Guard.ch to Windsurf
Open the MCP settings in Cascade and edit the raw configuration at ~/.codeium/windsurf/mcp_config.json. Add this entry and save.
{
"mcpServers": {
"guardch": {
"serverUrl": "https://api.guard.ch/mcp",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}Swap YOUR_API_KEY for your own key before you save this.
For JSON configuration: if you already use other MCP servers, only add the guardch entry inside mcpServers. Keep your other entries.
3. Check the connection
Refresh the MCP servers in Cascade and enable the Guard.ch tools. Open a chat and send the task below.
Open example.com in a Guard.ch browser and tell me what the page says.The connection works when your agent opens a Guard.ch browser and returns the page content. Find the session under Agents in your dashboard to watch it live.
Continue an open session
In your Guard.ch viewer, choose Hand to an agent. Copy the prepared prompt into your connected agent chat. It includes the session ID so your agent continues in that exact browser. Use a key from the same account.
If something goes wrong
If Guard.ch does not appear, check the JSON syntax and refresh the server list. Your team administrator may need to allow the guardch server.
For an authentication error, check that your app key is still valid. For an access error, check MCP access in your dashboard. Verify the connection in your agent; Guard.ch cannot automatically detect its configuration.
Your app key grants access to your sessions. Only add it to your agent settings, never to a chat or shared file. You can revoke it under Apps.