# Manage Cloudflare caching with Grok Bot

> Managing Cloudflare with Grok Bot means giving one of xAI's named Bots the xSpeed Hub plugin so it can verify each site's Cloudflare link on a routine, and purge the edge or switch development mode when you approve.

Page: https://xspeedcache.com/agent/grok-bot/cloudflare/
Last updated: October 2026

Picture a Bot whose job is looking after your sites. Twice a week its routine calls cloudflare_verify on each one through the xspeedhub plugin and posts which sites still resolve and which came back with an error. The routine runs on the Bot's cloud computer, so it happens with your laptop closed, and the check purges nothing. When a token has been revoked or a Zone ID changed, you hear about it from the Bot instead of from a failed purge during a launch.

The actions happen in a chat you take part in. Attach the plugin with @ and ask for one: purge_cloudflare clears the edge cache for one site's zone, and set_cloudflare_dev_mode with enabled true bypasses the edge for about three hours. Neither accepts site: "all", so several sites mean several calls. After a content change, ask for purge_cache on the server first and the edge purge after, so the edge does not refill from an old server copy. Because the Bot keeps context, it can tell you later in the thread when it turned development mode on, which helps because no Hub tool reports whether dev mode is on.

On a Team Bot, the owner adds the plugin from the Setup panel and each teammate signs in to xSpeed Hub with their own account, so whether a teammate's request can purge depends on that person's workspace role. Cloudflare credentials stay in the xSpeed Cache panel in wp-admin on each site; nobody should paste a token into a Bot chat.

## Set up Grok Bot once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Ask your Bot to add xSpeed Hub

In a chat with your Bot, ask it to add a custom remote HTTPS MCP server with this URL. xAI says a plugin you add from your own chat is personal and account-wide, so every Bot on your account can use it. When the browser opens, approve access on the xSpeed Hub page.

```
Add a custom remote HTTPS MCP server called xspeedhub with the URL https://app.xspeedcache.com/xspeed/mcp and sign me in.
```

### 3. Attach it and ask a first question

Type @ in a chat to attach the xspeedhub plugin to the task, then ask something that names xSpeed Hub. A list of your sites means the connection works.

```
Use @xspeedhub (xSpeed Hub) to list my sites and tell me which ones have page caching turned off.
```

Full setup: https://xspeedcache.com/agent/grok-bot/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. When an action needs approval, Grok Bot offers Allow once, Always allow or Deny. Always allow saves a rule, so the same kind of call no longer stops for you. Auto-review rules under Settings, General, Auto-review can force Ask first or allow matching actions automatically, and Ask first wins when both match. xSpeed Hub has no confirmation step of its own, so a Hub write tool you always allow runs as soon as your connection allows writes. Add Ask first rules for purge_cache, update_settings, toggle_cache, optimize_site and the other write tools. For read-only access, sign in as a Viewer member of the workspace.

## Prompts

- Create a routine: every Monday and Thursday, use @xspeedhub (xSpeed Hub) to verify Cloudflare on every site and post only the failures.
- Use @xspeedhub (xSpeed Hub) to purge shop's page cache and then its Cloudflare edge.
- With xSpeed Hub, switch Cloudflare development mode on for blog and tell me when you switched it.

## Example session

```
You: Use @xspeedhub (xSpeed Hub) to switch Cloudflare development mode on for blog. I am testing a new header.
  → cloudflare_verify(site: blog) [read-only]: Credentials and zone resolve; Cloudflare connected
Agent: The link on blog works. Development mode bypasses the edge for about three hours and slows blog for real visitors until it is off. Switch it on now?
You: Allow once.
  → set_cloudflare_dev_mode(site: blog, enabled: true) [changes site]: Development mode on, bypassing the edge for about 3 hours
Agent: Dev mode is on for blog as of now. Tell me when the header looks right and I will switch it off.
You: Header is fine. Turn it off.
  → set_cloudflare_dev_mode(site: blog, enabled: false) [changes site]: Development mode off
Agent: Development mode is off on blog, so visitors get the edge cache again.
```

## How it works

1. **Verify the connection**: cloudflare_verify calls Cloudflare's API with the credentials stored on the site and checks that the token and zone still resolve. It purges nothing and works on a read-only connection. If Cloudflare is not connected on that site, the call comes back as an error and the agent should tell you rather than retry.
2. **Purge the edge**: purge_cloudflare empties the Cloudflare edge cache for the site's zone. It does not touch the copies on your server. When Cloudflare is in front of a site, a content change usually needs both, so the agent runs purge_cache first and purge_cloudflare after it, or one purge_cache of type all, which reaches the edge when Cloudflare is connected.
3. **Turn development mode on to see origin changes**: set_cloudflare_dev_mode with enabled true bypasses the edge for about three hours, so changes on the origin show immediately. It slows the site for real visitors the whole time. Your client's prompt is the gate here, because the Hub's instructions do not name this tool in their confirm list.
4. **Turn it off when you finish**: set_cloudflare_dev_mode with enabled false switches development mode off. Cloudflare also ends it on its own after about three hours. No Hub tool reads whether it is currently on, so note when you turned it on.
5. **Read a failure**: A rejected token, an empty zone ID or a refused call comes back as an error that names the action, the HTTP status and Cloudflare's message when it gave one. It is not reported as a success. The credentials themselves are set in the xSpeed Cache panel in wp-admin, not through the Hub.

## Reference

| | |
| --- | --- |
| Read tool | cloudflare_verify; purges nothing and works on a read-only connection |
| Write tools | purge_cloudflare and set_cloudflare_dev_mode (enabled true or false) |
| Needs | Cloudflare connected in xSpeed on that site: integration on, an API token (or the legacy key and email) and a Zone ID |
| Edge purge scope | Everything Cloudflare holds for the site's zone; the server copies stay |
| Development mode | Bypasses the edge for about 3 hours, then Cloudflare switches it off |
| Token permissions | Zone Cache Purge, and Zone Settings Edit for development mode |
| What verify proves | The token and zone resolve; a token without Zone Settings Edit still verifies |
| Through purge_cache | Type all also clears the edge when Cloudflare is connected; page, assets, object and rest do not |
| Every site at once | None of the three accept site: "all"; one site per call |
| Failure shape | An error with the action, the HTTP status and Cloudflare's message |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in; purge_cloudflare and set_cloudflare_dev_mode are refused and cloudflare_verify works. An OAuth sign-in gets the scopes the client asks for, so the switch does not make it read-only |
| Confirmation | None on the Hub; your client's prompt is the gate |

## Rules

- Run cloudflare_verify first, but do not read a pass as proof that every call will work. A token that lacks Zone Settings Edit verifies and purges fine, then fails the first time development mode is switched.
- Purge the server and the edge together after a content change. Purging only the site leaves visitors on the old page until the edge copy expires.
- Turn development mode off as soon as you are done. It slows the site for real visitors for up to about three hours, and no tool reports its state.
- Never paste a Cloudflare token or Global API Key into the chat. Connect Cloudflare in the xSpeed Cache panel in wp-admin, and use a scoped API token rather than the Global API Key.
- purge_cloudflare and set_cloudflare_dev_mode are write tools. The Hub runs them as soon as your connection allows writes, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer member's sign-in) are the gates that matter.

## Good to know with Grok Bot

Grok Bot offers Allow once, Always allow or Deny when a call needs approval, and Always allow saves a rule. Do not choose it for set_cloudflare_dev_mode or purge_cloudflare: after that, a routine or a vague chat can switch development mode on with nobody asked, and the site is slower for real visitors for about three hours. The Hub has no confirmation step of its own, and its instructions to the agent do not list set_cloudflare_dev_mode among the tools to confirm. Add Ask first rules for both writes under Settings, General, Auto-review, because Ask first wins over an automatic allow. A routine's Test run performs real work, including calls to connected tools, so test with the verify-only prompt. For a Bot that can only verify, sign in as a Viewer member of the workspace; the Hub then refuses both writes.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to check that the Cloudflare connection on shop still works.
- With xSpeed Hub, purge the Cloudflare edge cache on blog.
- I changed the checkout page on shop. Use xSpeed Hub to purge the site cache and the Cloudflare edge.
- Use xSpeed Hub to turn Cloudflare development mode on for shop. I am editing the theme.
- With xSpeed Hub, turn Cloudflare development mode off on shop.
- Ask xSpeed Hub to verify Cloudflare on shop and tell me what is wrong if it fails.
- Using xSpeed Hub, which of my sites have a working Cloudflare connection? Check them one at a time.

## Frequently asked questions

### Can a Grok Bot routine check Cloudflare while I am away?

Yes. A routine runs on the Bot's cloud computer on a schedule and can call cloudflare_verify on each site, which only reads. Keep purges and development mode out of routines, because nobody is there to approve them.

### Does Grok Bot know whether development mode is still on?

Only from the conversation. No Hub tool reports the current dev mode state, so the Bot can tell you when it switched it on in that thread, and Cloudflare switches it off on its own after about three hours.

### What does a site need before the Cloudflare tools work?

Cloudflare has to be connected in xSpeed on that site: the integration switched on, an API token (or the legacy Global API Key with your Cloudflare email) and the Zone ID of the domain. You set these in the xSpeed Cache panel in wp-admin. Without them, the tools return an error instead of acting.

### Does purging the xSpeed cache also clear Cloudflare?

A purge_cache of type all does, when the site has Cloudflare connected, and it reports each step. A page, assets, object or rest purge stays on your server. purge_cloudflare clears only the edge, so use it when the server copy is already fresh.

### How long does development mode last?

About three hours. Cloudflare switches it off on its own after that. While it is on, the edge is bypassed, so origin changes show at once and real visitors get a slower site. Turn it off yourself with set_cloudflare_dev_mode set to false when you are done.

### Why did cloudflare_verify pass but development mode failed?

Verifying and purging do not need Zone Settings Edit on the token, so a token without it looks fine. Development mode writes a zone setting, so it is refused. Edit the token in Cloudflare so it has both Zone Cache Purge and Zone Settings Edit, then try again.

### Can I purge Cloudflare on all my sites with one prompt?

Not with purge_cloudflare, which takes one site per call. A purge_cache of type all with site set to all clears the edge on each site that has Cloudflare connected, and the result is reported per site. The Hub tells the agent to confirm a write across every site with you once first.

## Manage Cloudflare with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/cloudflare/) · [Claude](https://xspeedcache.com/agent/claude/cloudflare/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/cloudflare/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/cloudflare/) · [Codex](https://xspeedcache.com/agent/codex/cloudflare/) · [Cursor](https://xspeedcache.com/agent/cursor/cloudflare/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/cloudflare/) · [Windsurf](https://xspeedcache.com/agent/windsurf/cloudflare/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/cloudflare/) · [Antigravity](https://xspeedcache.com/agent/antigravity/cloudflare/) · [Zed](https://xspeedcache.com/agent/zed/cloudflare/) · [Kiro](https://xspeedcache.com/agent/kiro/cloudflare/) · [OpenCode](https://xspeedcache.com/agent/opencode/cloudflare/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/cloudflare/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/) · [Grok Build](https://xspeedcache.com/agent/grok-build/cloudflare/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/cloudflare/) · [Grok](https://xspeedcache.com/agent/grok/cloudflare/) · [Muse](https://xspeedcache.com/agent/muse/cloudflare/) · [Manus](https://xspeedcache.com/agent/manus/cloudflare/) · [Kimi Code](https://xspeedcache.com/agent/kimi/cloudflare/) · [Paperclip](https://xspeedcache.com/agent/paperclip/cloudflare/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/cloudflare/)

## More with Grok Bot

- [Purge the WordPress cache with Grok Bot](https://xspeedcache.com/agent/grok-bot/purge-cache/)
- [Find out why WordPress pages are not cached with Grok Bot](https://xspeedcache.com/agent/grok-bot/troubleshoot-cache/)
- [Scan a website for speed problems with Grok Bot](https://xspeedcache.com/agent/grok-bot/speed-scan/)
- [Run and track PageSpeed tests with Grok Bot](https://xspeedcache.com/agent/grok-bot/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with Grok Bot](https://xspeedcache.com/agent/grok-bot/optimize-site/)
- [Tune WordPress cache settings with Grok Bot](https://xspeedcache.com/agent/grok-bot/cache-settings/)
- [Warm the WordPress cache with Grok Bot](https://xspeedcache.com/agent/grok-bot/preload-cache/)
- [Set up the Redis object cache with Grok Bot](https://xspeedcache.com/agent/grok-bot/object-cache/)
- [Manage every WordPress site at once with Grok Bot](https://xspeedcache.com/agent/grok-bot/fleet/)

## Documentation

- How to connect Cloudflare: https://xspeedcache.com/docs/cloudflare/
- How to serve assets from a CDN: https://xspeedcache.com/docs/cdn/
- How to enable Page Cache: https://xspeedcache.com/docs/page-cache/
