Skip to content

Windsurf SQLGuard — Execution Certificate Firewall Resource/Why agents NEED SQLGuard

How to: Windsurf SQLGuard — Execution Certificate Firewall Why agents NEED SQLGuard

client:Windsurf transport:streamable-http resource:Why agents NEED SQLGuard

Add SQLGuard — Execution Certificate Firewall to Windsurf

  1. 01

    Open ~/.codeium/windsurf/mcp_config.json and merge this in. Keep any servers already there.

{
  "mcpServers": {
    "sqlguard": {
      "serverUrl": "https://sqlguard.io/mcp"
    }
  }
}
  1. 02

    Save the file and restart Windsurf.

  2. 03

    Why agents NEED SQLGuard is surfaced wherever your client lets you attach context. It is context to attach, not an action to run.

  3. 04

    If it does not appear, check that SQLGuard — Execution Certificate Firewall is connected and that you are looking at its resources rather than its tools.

Global only — Windsurf has no per-project MCP config. Refresh Cascade after saving. Windsurf docs

Same resource, other clients

Read from the server itself, by connecting to it and calling resources/list on 24 September 2026. A listing does not declare its resources, so asking is the only way to know them, and this is what the server actually offers rather than what its listing claims. Names only are stored; connect the server for each resource's type and contents.