Windsurf SQLGuard — permission before production writes Prompt/authorize_sql_write
How to: Windsurf SQLGuard — permission before production writes authorize_sql_write
Add SQLGuard — permission before production writes to Windsurf
-
01
Open ~/.codeium/windsurf/mcp_config.json and merge this in. Keep any servers already there.
{
"mcpServers": {
"sqlguard": {
"serverUrl": "https://sqlguard.io/mcp/stream"
}
}
}
-
02
Save the file and restart Windsurf.
-
03
authorize_sql_write is surfaced in the client's prompt or command menu. Unlike a tool, you invoke it deliberately — Windsurf will not call it for you.
-
04
If it does not appear, check that SQLGuard — permission before production writes is connected and that you are looking at its prompts rather than its tools.
Global only — Windsurf has no per-project MCP config. Refresh Cascade after saving. Windsurf docs
Same prompt, other clients
Read from the server itself, by connecting to it and calling prompts/list on 24 September 2026.
A listing does not declare its prompts, so asking is the only way to know them, and this
is what the server actually offers rather than what its listing claims. Names only are
stored; connect the server for each prompt's arguments.