xSpeed Cache is officially live! Get 50% OFF during Launch Week — Lifetime starts at just $79Lifetime from $79 — 50% OFF, Launch Week! See Plans →

See Plans →
Features
xSpeed Hub Pricing Docs Blog Scan
Appearance
Get Plugin

Manage Cloudflare caching with Antigravity

Managing Cloudflare with Antigravity means asking its agent, in the editor where you build, to verify a WordPress site's Cloudflare link, purge the edge cache or toggle development mode through xSpeed Hub.

cloudflare_verifypurge_cloudflareset_cloudflare_dev_modepurge_cacheget_settings

Last updated: October 2026

Example session · Antigravity

You: The deploy to shop went out but visitors still see the old checkout page. Use xSpeed Hub to look at Cloudflare.

cloudflare_verify(site: shop) read-only
→ Credentials and zone resolve; Cloudflare connected

Antigravity: Cloudflare is connected on shop. The old checkout page can sit in the edge and in xSpeed's page cache on the server. Purge the page cache on shop first, then run purge_cloudflare?

You: Yes, purge both.

purge_cache(site: shop, type: page) changes site
→ page cache purged (33 entries)

purge_cloudflare(site: shop) changes site
→ Cloudflare edge cache purged

Antigravity: The server page cache and the Cloudflare edge are both purged for shop. Load the checkout page logged out to confirm the new version.

01

How Antigravity handles this

You are building in Antigravity and the site you deployed to still serves the old page to visitors. Rather than leave the editor to dig through Cloudflare, you name the site and ask the agent to find out what Cloudflare is doing. It calls list_sites, then cloudflare_verify, which asks Cloudflare whether the credentials and zone stored in xSpeed still resolve. That check is a read and purges nothing.

The agent can follow with purge_cloudflare, which empties only the Cloudflare edge copy, or set_cloudflare_dev_mode, which bypasses the edge for about three hours so origin output shows right away. Both writes need Cloudflare connected in xSpeed on that site, and neither accepts site: "all", so a change across several sites is several calls.

Antigravity signs in to xSpeed Hub using OAuth: the Hub's page opens in your browser, you approve access, and you paste the authorization code it shows back into Agent settings. You never paste a connection token. For approval, Antigravity runs unconfigured MCP tools in Ask mode, so each call waits in a card for your approval. When you approve a card you can edit its target to widen the grant, so leave it as it is for a write. An allow rule such as mcp(xspeedhub/cloudflare_verify) lets one tool through without a prompt. Ask and Deny rules take precedence over Allow, and the Turbo permission preset allows MCP actions without asking. Name the site in your request, so the card shows the target you meant.

02

Set up Antigravity once

Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Antigravity guide.

1Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

2Add xSpeed Hub to mcp_config.json

Antigravity reads ~/.gemini/config/mcp_config.json for every project, or .agents/mcp_config.json inside one workspace. In the IDE, open the ... menu at the top of the agent side panel, choose MCP Servers, then Manage MCP Servers and View raw config. Remote servers must use the serverUrl field; the older url and httpUrl fields are not supported.

~/.gemini/config/mcp_config.json
{
  "mcpServers": {
    "xspeedhub": {
      "serverUrl": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}

3Authenticate

Open Agent settings with Cmd+, on macOS or Ctrl+, on Windows and Linux, go to the Customizations tab and click Authenticate next to xspeedhub. Sign in to xSpeed Hub in the browser and approve access, copy the authorization code the page shows, paste it into the settings panel and click Submit. Antigravity keeps the credentials it receives and refreshes them. In the CLI, type /mcp to open the MCP manager and check the server status.

Text
Settings → Customizations → Authenticate
1 / 3

Full Antigravity setup, sign-in options and FAQ

Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Antigravity runs unconfigured MCP tools in Ask mode, so each call waits for your approval in a card before it executes. Allow rules such as mcp(xspeedhub/get_cache_status) or mcp(xspeedhub/*) let calls through without a prompt, Ask and Deny rules take precedence over Allow, and the Turbo permission preset allows MCP and web actions without asking. When you approve a card you can also edit its target to widen the grant. With Turbo or a broad allow rule, a write reaches the Hub as soon as your connection allows writes. xSpeed Hub has no confirmation step of its own.

03

What do I ask?

Three prompts written for Antigravity. More for this job are below.

Prompt for Antigravity
Use xSpeed Hub to verify Cloudflare on shop and report the result. Change nothing.
Prompt for Antigravity
With xSpeed Hub, purge the Cloudflare edge cache for blog now that the deploy is out.
Prompt for Antigravity
Use xSpeed Hub to turn Cloudflare development mode on for shop while we test, and remind me to turn it off when we finish.
04

What happens, step by step

When Cloudflare sits in front of a WordPress site, it keeps its own copy of your files at the edge. Through xSpeed Hub an agent can check that the site's Cloudflare credentials still work, purge the edge cache, and turn development mode on or off. All three need Cloudflare connected in xSpeed on that site, and each works on one site at a time.

01

Verify the connection

cloudflare_verify calls Cloudflare's API with the credentials stored on the site and checks that the token and zone still resolve. It purges nothing and works on a read-only connection. If Cloudflare is not connected on that site, the call comes back as an error and the agent should tell you rather than retry.

02

Purge the edge

purge_cloudflare empties the Cloudflare edge cache for the site's zone. It does not touch the copies on your server. When Cloudflare is in front of a site, a content change usually needs both, so the agent runs purge_cache first and purge_cloudflare after it, or one purge_cache of type all, which reaches the edge when Cloudflare is connected.

03

Turn development mode on to see origin changes

set_cloudflare_dev_mode with enabled true bypasses the edge for about three hours, so changes on the origin show immediately. It slows the site for real visitors the whole time. Your client's prompt is the gate here, because the Hub's instructions do not name this tool in their confirm list.

04

Turn it off when you finish

set_cloudflare_dev_mode with enabled false switches development mode off. Cloudflare also ends it on its own after about three hours. No Hub tool reads whether it is currently on, so note when you turned it on.

05

Read a failure

A rejected token, an empty zone ID or a refused call comes back as an error that names the action, the HTTP status and Cloudflare's message when it gave one. It is not reported as a success. The credentials themselves are set in the xSpeed Cache panel in wp-admin, not through the Hub.

05

Reference

Read toolcloudflare_verify; purges nothing and works on a read-only connection
Write toolspurge_cloudflare and set_cloudflare_dev_mode (enabled true or false)
NeedsCloudflare connected in xSpeed on that site: integration on, an API token (or the legacy key and email) and a Zone ID
Edge purge scopeEverything Cloudflare holds for the site's zone; the server copies stay
Development modeBypasses the edge for about 3 hours, then Cloudflare switches it off
Token permissionsZone Cache Purge, and Zone Settings Edit for development mode
What verify provesThe token and zone resolve; a token without Zone Settings Edit still verifies
Through purge_cacheType all also clears the edge when Cloudflare is connected; page, assets, object and rest do not
Every site at onceNone of the three accept site: "all"; one site per call
Failure shapeAn error with the action, the HTTP status and Cloudflare's message
Read-only connectionThe connection token with Read-only everywhere on, or a Viewer member's sign-in; purge_cloudflare and set_cloudflare_dev_mode are refused and cloudflare_verify works. An OAuth sign-in gets the scopes the client asks for, so the switch does not make it read-only
ConfirmationNone on the Hub; your client's prompt is the gate
06

Rules worth keeping

  • Run cloudflare_verify first, but do not read a pass as proof that every call will work. A token that lacks Zone Settings Edit verifies and purges fine, then fails the first time development mode is switched.
  • Purge the server and the edge together after a content change. Purging only the site leaves visitors on the old page until the edge copy expires.
  • Turn development mode off as soon as you are done. It slows the site for real visitors for up to about three hours, and no tool reports its state.
  • Never paste a Cloudflare token or Global API Key into the chat. Connect Cloudflare in the xSpeed Cache panel in wp-admin, and use a scoped API token rather than the Global API Key.
  • purge_cloudflare and set_cloudflare_dev_mode are write tools. The Hub runs them as soon as your connection allows writes, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer member's sign-in) are the gates that matter.

Good to know with Antigravity

Allow cloudflare_verify with mcp(xspeedhub/cloudflare_verify) and leave the two write tools unmatched, so each one asks. A broad rule such as mcp(xspeedhub/*) or the Turbo preset lets set_cloudflare_dev_mode run without a prompt, and the Hub adds none, so a vague request can leave a live site in development mode, slower for real visitors, for about three hours. Add an Ask or Deny rule for the writes if you use Turbo. A read-only connection is the other gate, either the connection token in the entry's headers with Read-only everywhere on or a Viewer member's sign-in; Antigravity's own OAuth sign-in gets the scopes it asks for, and the switch does not change that. On a read-only connection cloudflare_verify still works, and purge_cloudflare and set_cloudflare_dev_mode are refused. No Hub tool reports whether dev mode is on, so note when you switched it on.

07

More prompts for this job

They work in any client connected to xSpeed Hub.

Prompt
Use xSpeed Hub to check that the Cloudflare connection on shop still works.
Prompt
With xSpeed Hub, purge the Cloudflare edge cache on blog.
Prompt
I changed the checkout page on shop. Use xSpeed Hub to purge the site cache and the Cloudflare edge.
Prompt
Use xSpeed Hub to turn Cloudflare development mode on for shop. I am editing the theme.
Prompt
With xSpeed Hub, turn Cloudflare development mode off on shop.
Prompt
Ask xSpeed Hub to verify Cloudflare on shop and tell me what is wrong if it fails.
Prompt
Using xSpeed Hub, which of my sites have a working Cloudflare connection? Check them one at a time.
08

Frequently asked questions

It uses OAuth with dynamic client registration. Antigravity opens a Hub page in your browser, you approve access, copy the authorization code the page shows and paste it into Agent settings. The client keeps the credentials it receives, so there is no connection token to paste.

By default, the Ask mode card: unconfigured MCP tools wait for your approval before they run. An allow rule for set_cloudflare_dev_mode, a broad allow rule for the whole xspeedhub server or the Turbo preset removes that stop. A read-only connection stops it for good, because it refuses set_cloudflare_dev_mode. Sign in as a Viewer member, or send the connection token with Read-only everywhere on in the entry's headers; the default OAuth sign-in gets the scopes Antigravity asks for.

Cloudflare has to be connected in xSpeed on that site: the integration switched on, an API token (or the legacy Global API Key with your Cloudflare email) and the Zone ID of the domain. You set these in the xSpeed Cache panel in wp-admin. Without them, the tools return an error instead of acting.

A purge_cache of type all does, when the site has Cloudflare connected, and it reports each step. A page, assets, object or rest purge stays on your server. purge_cloudflare clears only the edge, so use it when the server copy is already fresh.

About three hours. Cloudflare switches it off on its own after that. While it is on, the edge is bypassed, so origin changes show at once and real visitors get a slower site. Turn it off yourself with set_cloudflare_dev_mode set to false when you are done.

Verifying and purging do not need Zone Settings Edit on the token, so a token without it looks fine. Development mode writes a zone setting, so it is refused. Edit the token in Cloudflare so it has both Zone Cache Purge and Zone Settings Edit, then try again.

Not with purge_cloudflare, which takes one site per call. A purge_cache of type all with site set to all clears the edge on each site that has Cloudflare connected, and the result is reported per site. The Hub tells the agent to confirm a write across every site with you once first.

09

Keep going

Manage Cloudflare with other agents

More with Antigravity

Documentation

From the blog

Manage Cloudflare, from Antigravity.

xSpeed Hub is free and has no site cap. Connect your sites once and ask from the agent you already use.