# Cursor + xSpeed: Manage WordPress Caching

> Cursor is an AI code editor, and with xSpeed Hub added to mcp.json its agent can read cache status, purge, change settings and run speed tests on every WordPress site in your workspace without leaving the editor. You add one entry, sign in once, and ask in the chat beside the theme or plugin you are editing.

Page: https://xspeedcache.com/agent/cursor/
Last updated: October 2026

- One url in mcp.json, every site you connected to the Hub
- Run Modes decide who reviews each MCP call: you, a classifier or nobody
- Use ~/.cursor/mcp.json for every project or .cursor/mcp.json for one

## How do I connect Cursor to xSpeed?

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to mcp.json

Add the server to ~/.cursor/mcp.json to have it in every project, or to .cursor/mcp.json inside a project to scope it there. The entry is just a name and a url.

File: `~/.cursor/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

### 3. Enable it and sign in

Open Customize in the sidebar, find xspeedhub and make sure it is switched on. When Cursor starts the OAuth sign-in, approve access on the xSpeed Hub page. There is no token to paste. If the server shows an error, open the Output panel with Cmd+Shift+U and pick MCP Logs.

```
Customize  >  xspeedhub  (on)
```

### 4. Or send the connection token in a header (alternative)

If you prefer a header to a browser sign-in, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), export it as XSPEED_HUB_TOKEN in your shell profile and reference it with ${env:...}. Do not paste the token itself into a mcp.json that you commit.

File: `~/.cursor/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp",
      "headers": {
        "Authorization": "Bearer ${env:XSPEED_HUB_TOKEN}"
      }
    }
  }
}
```

**Authentication:** OAuth sign-in or connection token. Cursor supports OAuth for remote servers: approve access on an xSpeed Hub page, with no token to paste. If you prefer a header, send the connection token from the Hub's Connect AI page through the headers field, read from an environment variable.

**Check it worked:** ask "Use xSpeed Hub to list my sites and tell me which ones have page caching turned off."

## Does Cursor ask before it changes my site?

Cursor decides how to treat an MCP tool call by its Run Mode, and you can expand a call to see its arguments. MCP follows the same Run Modes as terminal commands, set under Settings > Agents > Approvals & Execution. The recommended default, Auto-review, runs allowlisted calls at once and sends the rest to a classifier, not to you. Allowlist runs only what you listed, and with an empty list it asks you every time. Run Everything runs every tool call without asking. xSpeed Hub has no confirmation step of its own, so a tool you allowlist, or any call under Run Everything, writes as soon as your connection allows writes. Auto-review is a model, and Cursor says it is not a security boundary.

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

## Example session

```
You: I am editing the shop theme's CSS. Use xSpeed Hub to preview what a safe optimize pass would change on shop. Do not apply anything.
  → list_sites [read-only]: 6 sites; shop is shop.example.com
  → optimize_site(site: shop, aggressiveness: safe, dry_run: true) [dry run]: preview only: 4 settings would change (minify, JavaScript defer, lazy-load images, browser cache); nothing applied
Agent: Four settings would change. Because you are editing CSS, I would check the minify change on the cart page first. Want me to apply the safe pass?
You: Not yet. I will test the cart page locally first.
Agent: Understood. Nothing was applied. Tell me when you want the real run.
```

## What is Cursor?

Cursor is an AI code editor. Its agent reads and edits your code, runs terminal commands, and calls tools on MCP servers that you configure in mcp.json or install from the Customize page.

MCP, the Model Context Protocol, is how Cursor reaches services outside your project. Adding xSpeed Hub as a remote server gives the agent the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace, in the same chat where you edit the theme or plugin.

## Why use Cursor with xSpeed?

- **In the editor where the site lives**: Ask about a site while its theme or plugin code is open. Cursor already has the context, so "check the shop site after this change" needs no switching of windows.
- **Run Modes you choose**: Auto-review, Allowlist and Run Everything set how often the agent stops. Allowlist a few read tools and keep each write on a prompt.
- **Global or per project**: Put the Hub in ~/.cursor/mcp.json for every project, or in .cursor/mcp.json when only one repository should see it.

## Good to know

- Run Modes apply to local agents. Cursor says Cloud Agents never ask for approval, so do not give a Cloud Agent a write-capable Hub connection. If one must connect, send the connection token with Read-only everywhere on, or sign in as a Viewer member.
- Auto-review is a classifier model. Cursor says it can allow a call you would have blocked, so it is not a substitute for read-only access. Read-only means the connection token with Read-only everywhere on, or a Viewer member's sign-in.
- A .cursor/mcp.json that you commit is shared with your team. The URL is safe to share. A connection token is not, so keep it in an environment variable.
- Cursor's Ask Every Time mode was deprecated in version 3.5. Allowlist with an empty allowlist gives the same behavior.

## Prompts to try

- Use xSpeed Hub to show the cache hit ratio for every site and flag anything under 70%.
- I just changed the shop theme. Use xSpeed Hub to purge its assets cache only, then check the hit ratio.
- With xSpeed Hub, run a mobile PageSpeed test on shop and compare it with the stored score history.
- Ask xSpeed Hub to preview what optimize_site would change on docs with a safe pass. Do not apply it.
- Using xSpeed Hub, check whether Redis is reachable on shop before you turn on the object cache.

## What can Cursor do with xSpeed?

- [Purge the WordPress cache with Cursor](https://xspeedcache.com/agent/cursor/purge-cache/): Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
- [Find out why WordPress pages are not cached with Cursor](https://xspeedcache.com/agent/cursor/troubleshoot-cache/): Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
- [Scan a website for speed problems with Cursor](https://xspeedcache.com/agent/cursor/speed-scan/): Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
- [Run and track PageSpeed tests with Cursor](https://xspeedcache.com/agent/cursor/pagespeed-tests/): Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
- [Raise a WordPress site's PageSpeed score with Cursor](https://xspeedcache.com/agent/cursor/optimize-site/): Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
- [Tune WordPress cache settings with Cursor](https://xspeedcache.com/agent/cursor/cache-settings/): See which modules a site has, read their current settings, change them, and turn page caching on or off.
- [Warm the WordPress cache with Cursor](https://xspeedcache.com/agent/cursor/preload-cache/): Fill the page cache before visitors arrive, for example right after a purge or a deploy.
- [Set up the Redis object cache with Cursor](https://xspeedcache.com/agent/cursor/object-cache/): Connect a site to Redis or Memcached so database results survive between requests.
- [Manage Cloudflare caching with Cursor](https://xspeedcache.com/agent/cursor/cloudflare/): Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
- [Manage every WordPress site at once with Cursor](https://xspeedcache.com/agent/cursor/fleet/): Run one action across all of your sites, or a chosen few, and read the result site by site.

## Which way should I connect?

| Surface | Endpoint | Reaches | Auth | Tools |
| --- | --- | --- | --- | --- |
| [xSpeed Hub MCP](https://xspeedcache.com/docs/hub-mcp/) | `https://app.xspeedcache.com/xspeed/mcp` | Every site in your workspace, one connection | OAuth sign-in in the browser, or a connection token in an Authorization header | 29 tools (16 read, 13 write), seven of them can act on every site at once |
| [xSpeed Cache Site MCP](https://xspeedcache.com/docs/mcp-server/) | `https://your-site.com/xspeed/mcp` | One WordPress site | OAuth sign-in by a site admin, or the site's own token in an Authorization header | The full per-site tool set plus run_command for the WP-CLI surface |
| [xSpeed Scan MCP](https://xspeedcache.com/docs/scan-mcp/) | `https://xspeedcache.com/scan/mcp` | Any public URL, read-only | None. No account. | 5 tools: run_speed_scan, get_speed_scan and three product-info tools |
| [WP-CLI](https://xspeedcache.com/docs/wp-cli-commands/) | `wp xspeed …` | The site whose server the agent has a shell on | Your server login | Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more |

## Frequently asked questions

### How do I add xSpeed Hub to Cursor?

Add an entry named xspeedhub with the url https://app.xspeedcache.com/xspeed/mcp under mcpServers in ~/.cursor/mcp.json, or in .cursor/mcp.json for one project. Open Customize, make sure the server is on, and approve access on the xSpeed Hub page when Cursor starts the OAuth sign-in.

### Do I need an API key?

No. Cursor supports OAuth for remote servers, so you approve access on an xSpeed Hub page and nothing is pasted. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page, and you send it in the headers field from an environment variable.

### Will Cursor change my site without asking?

It can. Cursor's recommended default Run Mode, Auto-review, sends calls that are not allowlisted to a classifier, not to you, and Run Everything asks nothing. Only Allowlist mode asks you about unlisted tools. The Hub has no confirmation step of its own, so an allowed write runs as soon as your connection allows writes. Use Allowlist for writes you want to approve yourself. For read-only access, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

### Which Run Mode should I use with the Hub?

Allowlist is the most predictable. Switch Run Mode to Allowlist under Settings, Agents, Approvals and Execution, list the Hub's read tools you trust, such as get_cache_status, and leave the write tools off the list so each one asks. Under the default Auto-review, unlisted calls go to a classifier. Auto-review is Cursor's recommended mode, but a classifier decides there, and Cursor says it is not a security boundary.

### Where do I change Run Modes?

In the desktop app, open Settings, then Agents, then Approvals and Execution. Team admins can override which modes are available, and team settings take precedence over yours.

### Can I use Cursor with one site and no Hub?

Yes. The xSpeed Cache plugin has its own MCP server at your-site.com/xspeed/mcp, and its MCP panel in wp-admin generates a ready JSON block for that site. The Hub is the better fit once you have more than one site.

### The server shows an error. Where do I look?

Open the Output panel with Cmd+Shift+U and pick MCP Logs. It shows connection errors and authentication problems. Check that the URL is exactly the Hub endpoint, and that the server is switched on in Customize.

### How do I disconnect Cursor?

Switch xspeedhub off in Customize, or delete its entry from mcp.json. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in Cursor.

## Also works with

[Claude Code](https://xspeedcache.com/agent/claude-code/) · [Claude](https://xspeedcache.com/agent/claude/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/) · [Codex](https://xspeedcache.com/agent/codex/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/) · [Windsurf](https://xspeedcache.com/agent/windsurf/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/) · [Antigravity](https://xspeedcache.com/agent/antigravity/) · [Zed](https://xspeedcache.com/agent/zed/) · [Kiro](https://xspeedcache.com/agent/kiro/) · [OpenCode](https://xspeedcache.com/agent/opencode/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/) · [Grok Build](https://xspeedcache.com/agent/grok-build/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/) · [Grok](https://xspeedcache.com/agent/grok/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/) · [Muse](https://xspeedcache.com/agent/muse/) · [Manus](https://xspeedcache.com/agent/manus/) · [Kimi Code](https://xspeedcache.com/agent/kimi/) · [Paperclip](https://xspeedcache.com/agent/paperclip/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/)

## Sources

- Cursor Docs: Model Context Protocol: https://cursor.com/docs/mcp
- Cursor Docs: Run Modes: https://cursor.com/docs/agent/security/run-modes
