Skip to content
Windsurf

policy gate for Windsurf

dev.workers.3labsio.policy-gate/policy-gate

Deterministic allow/require_approval/deny verdicts for agent actions, before they happen.

client:Windsurf transport:streamable-http tools:4

Install policy gate in Windsurf

~/.codeium/windsurf/mcp_config.json · windows: %USERPROFILE%\.codeium\windsurf\mcp_config.json

{
  "mcpServers": {
    "policy-gate": {
      "serverUrl": "https://policy-gate.3labsio.workers.dev/mcp"
    }
  }
}

Global only — Windsurf has no per-project MCP config. Refresh Cascade after saving. Windsurf docs

What Windsurf can do once it is connected

policy gate in other clients