# Manage Cloudflare caching with Cursor

> Managing Cloudflare with Cursor means asking its agent, from the editor where you change your WordPress theme, to verify the Cloudflare link, purge the edge cache or toggle development mode through xSpeed Hub.

Page: https://xspeedcache.com/agent/cursor/cloudflare/
Last updated: October 2026

You are editing a theme file in Cursor and checking the result in a logged-out browser tab. The server shows your change, but the tab keeps showing the old page, which points at Cloudflare. Without leaving the editor, you tell the agent the site name. It calls list_sites, runs cloudflare_verify to check the token and zone saved in xSpeed, and shows you the answer in the chat panel next to your code.

Then it can run purge_cloudflare for a one-off edge clear, or set_cloudflare_dev_mode to bypass the edge for about three hours while you keep editing. That second option suits Cursor well, because you will reload the page many times in a row. Both writes need Cloudflare connected in xSpeed on that site, and neither accepts site: "all", so one call covers one site.

When Cursor does ask, the approval card shows the tool's arguments, so you can see which site and which setting are about to be used. Read the site name before you accept, especially if your workspace has several. Whether it asks depends on your Run Mode, set under Settings, then Agents, then Approvals and Execution. Since Cursor 3.6 the recommended default is Auto-review, which sends calls that are not on the allowlist to a classifier instead of to you. In Allowlist mode, a call that is not listed asks you, and Run Everything asks nothing. When you are done editing, ask the agent to switch dev mode off, since a forgotten development mode leaves real visitors on a slower site until it expires.

## Set up Cursor once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to mcp.json

Add the server to ~/.cursor/mcp.json to have it in every project, or to .cursor/mcp.json inside a project to scope it there. The entry is just a name and a url.

File: `~/.cursor/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

### 3. Enable it and sign in

Open Customize in the sidebar, find xspeedhub and make sure it is switched on. When Cursor starts the OAuth sign-in, approve access on the xSpeed Hub page. There is no token to paste. If the server shows an error, open the Output panel with Cmd+Shift+U and pick MCP Logs.

```
Customize  >  xspeedhub  (on)
```

Full setup: https://xspeedcache.com/agent/cursor/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Cursor decides how to treat an MCP tool call by its Run Mode, and you can expand a call to see its arguments. MCP follows the same Run Modes as terminal commands, set under Settings > Agents > Approvals & Execution. The recommended default, Auto-review, runs allowlisted calls at once and sends the rest to a classifier, not to you. Allowlist runs only what you listed, and with an empty list it asks you every time. Run Everything runs every tool call without asking. xSpeed Hub has no confirmation step of its own, so a tool you allowlist, or any call under Run Everything, writes as soon as your connection allows writes. Auto-review is a model, and Cursor says it is not a security boundary.

## Prompts

- Use xSpeed Hub to check the Cloudflare connection on shop, then tell me whether I should purge or use dev mode.
- I changed the header partial. With xSpeed Hub, purge the Cloudflare edge cache on shop.
- Use xSpeed Hub to turn on Cloudflare development mode for blog while I work on this stylesheet, and turn it off when I say I am done.

## Example session

```
You: I keep reloading shop and the header never changes in a private window. Using xSpeed Hub, is it Cloudflare?
  → cloudflare_verify(site: shop) [read-only]: Credentials and zone resolve; Cloudflare connected
Agent: Cloudflare is connected, so the edge may hold the old header. Development mode would bypass it for about three hours while you edit. Turn it on for shop?
You: Yes, turn it on.
  → set_cloudflare_dev_mode(site: shop, enabled: true) [changes site]: Development mode on, bypassing the edge for about 3 hours
Agent: Dev mode is on for shop. Reload your private window. Tell me when you are done and I will switch it off.
```

## How it works

1. **Verify the connection**: cloudflare_verify calls Cloudflare's API with the credentials stored on the site and checks that the token and zone still resolve. It purges nothing and works on a read-only connection. If Cloudflare is not connected on that site, the call comes back as an error and the agent should tell you rather than retry.
2. **Purge the edge**: purge_cloudflare empties the Cloudflare edge cache for the site's zone. It does not touch the copies on your server. When Cloudflare is in front of a site, a content change usually needs both, so the agent runs purge_cache first and purge_cloudflare after it, or one purge_cache of type all, which reaches the edge when Cloudflare is connected.
3. **Turn development mode on to see origin changes**: set_cloudflare_dev_mode with enabled true bypasses the edge for about three hours, so changes on the origin show immediately. It slows the site for real visitors the whole time. Your client's prompt is the gate here, because the Hub's instructions do not name this tool in their confirm list.
4. **Turn it off when you finish**: set_cloudflare_dev_mode with enabled false switches development mode off. Cloudflare also ends it on its own after about three hours. No Hub tool reads whether it is currently on, so note when you turned it on.
5. **Read a failure**: A rejected token, an empty zone ID or a refused call comes back as an error that names the action, the HTTP status and Cloudflare's message when it gave one. It is not reported as a success. The credentials themselves are set in the xSpeed Cache panel in wp-admin, not through the Hub.

## Reference

| | |
| --- | --- |
| Read tool | cloudflare_verify; purges nothing and works on a read-only connection |
| Write tools | purge_cloudflare and set_cloudflare_dev_mode (enabled true or false) |
| Needs | Cloudflare connected in xSpeed on that site: integration on, an API token (or the legacy key and email) and a Zone ID |
| Edge purge scope | Everything Cloudflare holds for the site's zone; the server copies stay |
| Development mode | Bypasses the edge for about 3 hours, then Cloudflare switches it off |
| Token permissions | Zone Cache Purge, and Zone Settings Edit for development mode |
| What verify proves | The token and zone resolve; a token without Zone Settings Edit still verifies |
| Through purge_cache | Type all also clears the edge when Cloudflare is connected; page, assets, object and rest do not |
| Every site at once | None of the three accept site: "all"; one site per call |
| Failure shape | An error with the action, the HTTP status and Cloudflare's message |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in; purge_cloudflare and set_cloudflare_dev_mode are refused and cloudflare_verify works. An OAuth sign-in gets the scopes the client asks for, so the switch does not make it read-only |
| Confirmation | None on the Hub; your client's prompt is the gate |

## Rules

- Run cloudflare_verify first, but do not read a pass as proof that every call will work. A token that lacks Zone Settings Edit verifies and purges fine, then fails the first time development mode is switched.
- Purge the server and the edge together after a content change. Purging only the site leaves visitors on the old page until the edge copy expires.
- Turn development mode off as soon as you are done. It slows the site for real visitors for up to about three hours, and no tool reports its state.
- Never paste a Cloudflare token or Global API Key into the chat. Connect Cloudflare in the xSpeed Cache panel in wp-admin, and use a scoped API token rather than the Global API Key.
- purge_cloudflare and set_cloudflare_dev_mode are write tools. The Hub runs them as soon as your connection allows writes, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer member's sign-in) are the gates that matter.

## Good to know with Cursor

Switch Run Mode to Allowlist (Settings, then Agents, then Approvals and Execution), put cloudflare_verify on the list and leave set_cloudflare_dev_mode and purge_cloudflare off it, so each one asks. Under the default Auto-review, unlisted calls go to a classifier, and Cursor says it is not a security boundary, so it can allow a call you would have blocked. Under Run Everything the approval card disappears and either write runs the moment the agent decides to call it. Cloud Agents never ask, so give one only the connection token with Read-only everywhere on. The Hub's instructions to the agent do not name set_cloudflare_dev_mode in their confirm list either, so Cursor's own approval setting is the check, and a development mode you did not mean to leave on stays on until you turn it off or about three hours pass.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to check that the Cloudflare connection on shop still works.
- With xSpeed Hub, purge the Cloudflare edge cache on blog.
- I changed the checkout page on shop. Use xSpeed Hub to purge the site cache and the Cloudflare edge.
- Use xSpeed Hub to turn Cloudflare development mode on for shop. I am editing the theme.
- With xSpeed Hub, turn Cloudflare development mode off on shop.
- Ask xSpeed Hub to verify Cloudflare on shop and tell me what is wrong if it fails.
- Using xSpeed Hub, which of my sites have a working Cloudflare connection? Check them one at a time.

## Frequently asked questions

### Will Cursor purge Cloudflare without asking me?

Not necessarily. Since Cursor 3.6 the recommended default Run Mode is Auto-review, where a classifier decides on calls that are not allowlisted, so you are not always asked. In Allowlist mode an unlisted call asks you, and Run Everything asks nothing. The Hub adds no prompt of its own, so purge_cloudflare runs straight away when a mode or an allowlist entry lets it through. In Allowlist mode keep it off the list, or use the connection token with Read-only everywhere on.

### Can Cursor use development mode while I edit a theme?

Yes. Ask the agent to run set_cloudflare_dev_mode with enabled true for that site. Cloudflare bypasses its edge for about three hours, so each reload shows origin output. Ask the agent to turn it off when you finish.

### What does a site need before the Cloudflare tools work?

Cloudflare has to be connected in xSpeed on that site: the integration switched on, an API token (or the legacy Global API Key with your Cloudflare email) and the Zone ID of the domain. You set these in the xSpeed Cache panel in wp-admin. Without them, the tools return an error instead of acting.

### Does purging the xSpeed cache also clear Cloudflare?

A purge_cache of type all does, when the site has Cloudflare connected, and it reports each step. A page, assets, object or rest purge stays on your server. purge_cloudflare clears only the edge, so use it when the server copy is already fresh.

### How long does development mode last?

About three hours. Cloudflare switches it off on its own after that. While it is on, the edge is bypassed, so origin changes show at once and real visitors get a slower site. Turn it off yourself with set_cloudflare_dev_mode set to false when you are done.

### Why did cloudflare_verify pass but development mode failed?

Verifying and purging do not need Zone Settings Edit on the token, so a token without it looks fine. Development mode writes a zone setting, so it is refused. Edit the token in Cloudflare so it has both Zone Cache Purge and Zone Settings Edit, then try again.

### Can I purge Cloudflare on all my sites with one prompt?

Not with purge_cloudflare, which takes one site per call. A purge_cache of type all with site set to all clears the edge on each site that has Cloudflare connected, and the result is reported per site. The Hub tells the agent to confirm a write across every site with you once first.

## Manage Cloudflare with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/cloudflare/) · [Claude](https://xspeedcache.com/agent/claude/cloudflare/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/cloudflare/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/cloudflare/) · [Codex](https://xspeedcache.com/agent/codex/cloudflare/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/cloudflare/) · [Windsurf](https://xspeedcache.com/agent/windsurf/cloudflare/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/cloudflare/) · [Antigravity](https://xspeedcache.com/agent/antigravity/cloudflare/) · [Zed](https://xspeedcache.com/agent/zed/cloudflare/) · [Kiro](https://xspeedcache.com/agent/kiro/cloudflare/) · [OpenCode](https://xspeedcache.com/agent/opencode/cloudflare/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/cloudflare/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/) · [Grok Build](https://xspeedcache.com/agent/grok-build/cloudflare/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/cloudflare/) · [Grok](https://xspeedcache.com/agent/grok/cloudflare/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/cloudflare/) · [Muse](https://xspeedcache.com/agent/muse/cloudflare/) · [Manus](https://xspeedcache.com/agent/manus/cloudflare/) · [Kimi Code](https://xspeedcache.com/agent/kimi/cloudflare/) · [Paperclip](https://xspeedcache.com/agent/paperclip/cloudflare/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/cloudflare/)

## More with Cursor

- [Purge the WordPress cache with Cursor](https://xspeedcache.com/agent/cursor/purge-cache/)
- [Find out why WordPress pages are not cached with Cursor](https://xspeedcache.com/agent/cursor/troubleshoot-cache/)
- [Scan a website for speed problems with Cursor](https://xspeedcache.com/agent/cursor/speed-scan/)
- [Run and track PageSpeed tests with Cursor](https://xspeedcache.com/agent/cursor/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with Cursor](https://xspeedcache.com/agent/cursor/optimize-site/)
- [Tune WordPress cache settings with Cursor](https://xspeedcache.com/agent/cursor/cache-settings/)
- [Warm the WordPress cache with Cursor](https://xspeedcache.com/agent/cursor/preload-cache/)
- [Set up the Redis object cache with Cursor](https://xspeedcache.com/agent/cursor/object-cache/)
- [Manage every WordPress site at once with Cursor](https://xspeedcache.com/agent/cursor/fleet/)

## Documentation

- How to connect Cloudflare: https://xspeedcache.com/docs/cloudflare/
- How to serve assets from a CDN: https://xspeedcache.com/docs/cdn/
- How to enable Page Cache: https://xspeedcache.com/docs/page-cache/
