Devin Desktop (formerly Windsurf - Cognition renamed it in mid-2026) reads MCP servers from a JSON config, same as its Cascade agent did before the rebrand.
Mint a free key first (no account, no card):
curl -X POST https://otpbox.io/api/v1/keys/free -H "content-type: application/json" -d '{}'
→ { "id": "lic_...", "key": "...", "plan": "free", "quotaLimit": 200 }
Add to ~/.config/devin/mcp_config.json (Windows: %APPDATA%\devin\mcp_config.json):
{
"mcpServers": {
"otpbox": {
"serverUrl": "https://otpbox.io/mcp",
"headers": { "Authorization": "Bearer <your-otpbox-key>" }
}
}
}
serverUrl, not command/args - that shape is reserved for locally-launched servers.Once connected, Devin Desktop can call OTPBox's 13 MCP tools directly. For example:
"Create a disposable inbox with otpbox, sign up for this app, and finish the OTP verification step."
Every code and link comes from a real delivered email, not a stub - so the test proves the actual signup flow works.
OTP codes and verification links are parsed out automatically. No regex against raw email bodies.
200 requests/month with a key minted in one call - no account, no payment info, no waiting.
create_test_inbox, wait_for_email, get_otp, get_verification_link, create_test_identity, and more - the full loop is agent-callable.
For Devin Desktop's own MCP setup UI/flags beyond the snippet above, see Devin Desktop's MCP documentation.