# Codex + xSpeed: Manage WordPress Caching

> Codex is OpenAI's coding agent, and from the terminal with xSpeed Hub added it can read cache status, purge, change settings and run speed tests on every WordPress site in your workspace. You add one MCP server, sign in once, and ask in plain language next to your code.

Page: https://xspeedcache.com/agent/codex/
Last updated: October 2026

- Two commands: codex mcp add with the URL, then codex mcp login
- The same config.toml entry is shared by the CLI, the IDE extension and the ChatGPT desktop app
- Per-server and per-tool approval modes, so reads can run and writes can stay on a prompt

## How do I connect Codex to xSpeed?

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub and sign in

Add the server with its URL, then log in. The login opens an xSpeed Hub page in your browser; approve access there. There is no token to paste, and Codex keeps the credentials it receives. Start Codex and type /mcp to see the server.

```bash
codex mcp add xspeedhub --url https://app.xspeedcache.com/xspeed/mcp
codex mcp login xspeedhub
```

### 3. Keep the Hub's tools on a prompt

Open ~/.codex/config.toml. Set the server to prompt for every tool, then let one read tool run without a question. The tool timeout defaults to 60 seconds, and a PageSpeed test can take up to about two minutes, so raise it.

File: `~/.codex/config.toml`

```toml
[mcp_servers.xspeedhub]
url = "https://app.xspeedcache.com/xspeed/mcp"
default_tools_approval_mode = "prompt"
tool_timeout_sec = 150

[mcp_servers.xspeedhub.tools.get_cache_status]
approval_mode = "approve"
```

### 4. Or use a connection token (alternative)

If you prefer a header to a browser sign-in, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), export it in your shell as XSPEED_HUB_TOKEN and name that variable in config.toml. Codex sends it as a bearer token. Skip codex mcp login in this case.

File: `~/.codex/config.toml`

```toml
[mcp_servers.xspeedhub]
url = "https://app.xspeedcache.com/xspeed/mcp"
bearer_token_env_var = "XSPEED_HUB_TOKEN"
```

**Authentication:** OAuth sign-in or connection token. Run codex mcp login and approve access in the browser; Codex registers itself with the Hub and keeps the credentials it receives. To use the connection token instead, put it in an environment variable and point bearer_token_env_var at it in config.toml.

**Check it worked:** ask "Use xSpeed Hub to list my sites and tell me which ones have page caching turned off."

## Does Codex ask before it changes my site?

Codex has two layers for shell work: the sandbox mode limits what commands can touch, and the approval policy sets when Codex stops to ask. MCP tools have their own settings. Each server takes default_tools_approval_mode (auto, prompt, writes or approve) and each tool can override it with approval_mode. Codex also asks about MCP calls that advertise side effects or a destructive annotation, but xSpeed Hub's tool definitions do not declare either, so do not rely on that default for the Hub; set the server to prompt. approval_policy never, --yolo and an auto_review reviewer take the human out of the loop. xSpeed Hub has no confirmation step of its own, so an approved or auto-approved write runs as soon as your connection allows writes.

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

## Example session

```
You: I pushed new theme CSS to staging this morning. Using xSpeed Hub, did the mobile PageSpeed score move since the last stored run?
  → get_score_history(site: staging) [read-only]: 3 stored runs; latest mobile 58, 8 days ago
  → run_speed_test(site: staging, strategy: mobile) [uses quota]: mobile 61 after about 90 s
Agent: Mobile went from 58 to 61 since the last stored run. That is inside normal run-to-run variation, so I would not call it an improvement yet. A second run would tell us more. Want me to run one?
You: Not now. Just put the numbers in the commit message.
Agent: Added to the commit message: mobile 58 stored, 61 on a new single run, no claim of improvement.
```

## What is Codex?

Codex is OpenAI's coding agent. It runs in your terminal as the Codex CLI, in an IDE extension and in the ChatGPT desktop app, reads and edits code, runs commands in a sandbox, and calls tools on MCP servers you add to its config.

MCP, the Model Context Protocol, is how Codex reaches services outside your machine. Adding xSpeed Hub as a streamable HTTP server gives it the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace. The sandbox's network rules apply to commands Codex runs, not to its connection to an MCP server.

## Why use Codex with xSpeed?

- **Next to the diff**: You already review changes in this terminal. Ask Codex to check a site after a push, and put the answer in the commit message or the PR description in the same session.
- **Approval per server and per tool**: One setting puts every Hub tool on a prompt. Per-tool overrides let the read tools run quietly while the writes stay in front of you.
- **Same setup in three places**: The CLI, the IDE extension and the ChatGPT desktop app read one MCP configuration, so you add the Hub once.

## Good to know

- tool_timeout_sec defaults to 60. run_speed_test can take up to about two minutes and run_speed_scan waits about 50 seconds, so raise the timeout or the call can end early.
- A project-level .codex/config.toml applies to trusted projects only. Put the Hub in ~/.codex/config.toml if you want it everywhere.
- approval_policy never and --yolo remove prompts for everything, MCP calls included. For any run you start that way, and for codex exec in scripts or CI, send the connection token with Read-only everywhere on, or sign in as a Viewer member.
- codex mcp login and codex mcp logout work only for streamable HTTP servers that support OAuth. Use the connection token route if you would rather not sign in through a browser.

## Prompts to try

- Use xSpeed Hub to show the cache hit ratio for every site and flag anything under 70%.
- I just deployed to shop. Use xSpeed Hub to purge its assets cache only, then check the hit ratio.
- With xSpeed Hub, run a mobile PageSpeed test on staging and compare it with the stored score history.
- Ask xSpeed Hub to preview what optimize_site would change on docs with a safe pass. Do not apply it.
- Using xSpeed Hub, check whether Redis is reachable on shop before you turn on the object cache.

## What can Codex do with xSpeed?

- [Purge the WordPress cache with Codex](https://xspeedcache.com/agent/codex/purge-cache/): Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
- [Find out why WordPress pages are not cached with Codex](https://xspeedcache.com/agent/codex/troubleshoot-cache/): Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
- [Scan a website for speed problems with Codex](https://xspeedcache.com/agent/codex/speed-scan/): Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
- [Run and track PageSpeed tests with Codex](https://xspeedcache.com/agent/codex/pagespeed-tests/): Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
- [Raise a WordPress site's PageSpeed score with Codex](https://xspeedcache.com/agent/codex/optimize-site/): Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
- [Tune WordPress cache settings with Codex](https://xspeedcache.com/agent/codex/cache-settings/): See which modules a site has, read their current settings, change them, and turn page caching on or off.
- [Warm the WordPress cache with Codex](https://xspeedcache.com/agent/codex/preload-cache/): Fill the page cache before visitors arrive, for example right after a purge or a deploy.
- [Set up the Redis object cache with Codex](https://xspeedcache.com/agent/codex/object-cache/): Connect a site to Redis or Memcached so database results survive between requests.
- [Manage Cloudflare caching with Codex](https://xspeedcache.com/agent/codex/cloudflare/): Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
- [Manage every WordPress site at once with Codex](https://xspeedcache.com/agent/codex/fleet/): Run one action across all of your sites, or a chosen few, and read the result site by site.

## Which way should I connect?

| Surface | Endpoint | Reaches | Auth | Tools |
| --- | --- | --- | --- | --- |
| [xSpeed Hub MCP](https://xspeedcache.com/docs/hub-mcp/) | `https://app.xspeedcache.com/xspeed/mcp` | Every site in your workspace, one connection | OAuth sign-in in the browser, or a connection token in an Authorization header | 29 tools (16 read, 13 write), seven of them can act on every site at once |
| [xSpeed Cache Site MCP](https://xspeedcache.com/docs/mcp-server/) | `https://your-site.com/xspeed/mcp` | One WordPress site | OAuth sign-in by a site admin, or the site's own token in an Authorization header | The full per-site tool set plus run_command for the WP-CLI surface |
| [xSpeed Scan MCP](https://xspeedcache.com/docs/scan-mcp/) | `https://xspeedcache.com/scan/mcp` | Any public URL, read-only | None. No account. | 5 tools: run_speed_scan, get_speed_scan and three product-info tools |
| [WP-CLI](https://xspeedcache.com/docs/wp-cli-commands/) | `wp xspeed …` | The site whose server the agent has a shell on | Your server login | Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more |

## Frequently asked questions

### How do I add xSpeed Hub to Codex?

Run codex mcp add xspeedhub --url https://app.xspeedcache.com/xspeed/mcp, then codex mcp login xspeedhub and approve access in your browser. Start Codex and type /mcp to confirm the server is listed. The entry lives in your config.toml.

### Do I need an API key?

No. Codex signs in to the Hub with OAuth, registering itself through dynamic client registration, and keeps the credentials it receives. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page, and you point bearer_token_env_var in config.toml at an environment variable that holds it.

### Will Codex change my site without asking?

Not if you set it up that way. Set default_tools_approval_mode to prompt for the server and Codex asks before each Hub tool. The Hub has no confirmation step of its own, so approval_policy never, the yolo flag, an auto-approving reviewer or a per-tool approve setting lets a write run as soon as your connection allows writes. For a hard stop, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

### Why does Codex not prompt for a Hub tool by default?

Codex asks by default about MCP calls that advertise side effects or a destructive annotation. The Hub's tool definitions do not declare those annotations today, so the default prompt does not cover them. Setting default_tools_approval_mode to prompt for the server fixes that.

### Does it work in the IDE extension and the desktop app?

Yes. OpenAI says the ChatGPT desktop app, the Codex CLI and the IDE extension share MCP configuration for the same Codex host, so a server you add once appears in all three. OAuth servers show an Authenticate button in the app and the extension.

### Can Codex use WP-CLI instead?

If Codex has a shell on the server, it can run wp xspeed commands directly, for example wp xspeed purge. That works without the Hub, but only for the site on that server. The Hub covers every site you connected.

### Can I run it in scripts or CI?

Codex has a non-interactive mode, codex exec, but nobody is there to answer an approval prompt, so for any scripted run send the connection token with Read-only everywhere on, or sign in as a Viewer member. The Hub has no scheduler for agent prompts; it runs its own daily checks and sends its own alerts.

### How do I disconnect Codex?

Run codex mcp logout xspeedhub to drop the credentials and codex mcp remove xspeedhub to delete the entry. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in Codex.

## Also works with

[Claude Code](https://xspeedcache.com/agent/claude-code/) · [Claude](https://xspeedcache.com/agent/claude/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/) · [Cursor](https://xspeedcache.com/agent/cursor/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/) · [Windsurf](https://xspeedcache.com/agent/windsurf/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/) · [Antigravity](https://xspeedcache.com/agent/antigravity/) · [Zed](https://xspeedcache.com/agent/zed/) · [Kiro](https://xspeedcache.com/agent/kiro/) · [OpenCode](https://xspeedcache.com/agent/opencode/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/) · [Grok Build](https://xspeedcache.com/agent/grok-build/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/) · [Grok](https://xspeedcache.com/agent/grok/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/) · [Muse](https://xspeedcache.com/agent/muse/) · [Manus](https://xspeedcache.com/agent/manus/) · [Kimi Code](https://xspeedcache.com/agent/kimi/) · [Paperclip](https://xspeedcache.com/agent/paperclip/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/)

## Sources

- OpenAI: Model Context Protocol in Codex: https://learn.chatgpt.com/docs/extend/mcp
- OpenAI: Agent approvals and security: https://learn.chatgpt.com/docs/agent-approvals-security
- OpenAI: Configuration reference: https://learn.chatgpt.com/docs/config-file/config-reference
- OpenAI: Codex CLI commands: https://learn.chatgpt.com/docs/developer-commands
