npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

windsurf-search-mcp

v0.1.1

Published

MCP server + CLI for Windsurf/Devin server-side web search (GetWebSearchResults)

Readme

windsurf-search-mcp

MCP server and CLI for Windsurf/Devin server-side web search (GetWebSearchResults).

Zero runtime dependencies. Node.js >= 20.

This talks to Windsurf/Devin cloud endpoints with a personal session token. Use at your own risk; tokens expire and may violate the provider's terms if used outside the official client.

Install

npm i -g windsurf-search-mcp
# or without install:
npx -y -p windsurf-search-mcp windsurf-search --help

Auth (no secrets in config files)

Resolve order:

  1. --api-key <token>
  2. WINDSURF_API_KEY (or legacy WINDSURFAPI_CODEIUM_API_KEY)
  3. first existing key file:
    • ~/.config/windsurf-search/api-key
    • ~/.windsurf-search/api-key
    • ~/.piwin/windsurf-api-key (compat)

Expected token shape: devin-session-token$...

# interactive (masked)
windsurf-search config set

# or non-interactive
windsurf-search config set 'devin-session-token$...'

windsurf-search config show
windsurf-search config test

Email/password login is also available (windsurf-search --login), but many accounts are OAuth-only and will reject password login.

CLI

windsurf-search "tauri window drag region" --limit 5
# stdout JSON:
# { "hits": [ { "title", "url", "snippet", "source": "windsurf" } ] }

Useful for agent hosts that spawn a custom CLI search source and parse JSON hits.

MCP server

Cursor / Claude Desktop / generic MCP host

{
  "mcpServers": {
    "windsurf-search": {
      "command": "npx",
      "args": ["-y", "windsurf-search-mcp"],
      "env": {
        "WINDSURF_API_KEY": "devin-session-token$..."
      }
    }
  }
}

Prefer putting the token in a key file and omitting env entirely:

{
  "mcpServers": {
    "windsurf-search": {
      "command": "npx",
      "args": ["-y", "windsurf-search-mcp"]
    }
  }
}

Then:

windsurf-search config set

Exposed tool

web_search

| arg | type | required | notes | |-----|------|----------|-------| | query | string | yes | search query | | limit | number | no | 1–10, default 5 | | domain | string | no | optional domain filter | | mode | number | no | optional upstream mode |

Returns MCP text content with JSON:

{ "hits": [ { "title": "...", "url": "...", "snippet": "...", "source": "windsurf" } ] }

Development

node --test test/*.mjs          # offline unit + protocol tests
RUN_LIVE_SEARCH=1 npm test      # also hit live API if key is configured

Security notes

  • Never commit real tokens.
  • Session tokens expire; re-run config set when searches return 401.
  • config show only prints a masked key.
  • This is not an official Windsurf/Devin product.

License

MIT