# Tune WordPress cache settings with Grok Build

> Tuning cache settings with Grok Build means asking it, in the terminal, to check whether xSpeed page caching is on for a WordPress site, and to switch it or change a setting through xSpeed Hub once you agree.

Page: https://xspeedcache.com/agent/grok-build/cache-settings/
Last updated: October 2026

You are in Grok Build in a terminal, and you have just moved a site to a new host. Before anything else you want to know whether page caching survived the move. You ask, and name the site. Grok Build calls list_sites to match it, then get_cache_status to see whether page caching is on and how many pages are stored, and list_modules to see which modules came across. It reports what it finds in a few lines.

What comes back is the state and a proposal. If caching turned out to be off, the agent says it would call toggle_cache to turn it on, and the Hub tells it to briefly confirm intent first, so it asks you. After your yes it runs the call and reports the new state. If another caching plugin on the new host owns the cache drop-in, toggle_cache refuses to enable xSpeed and returns blocked: true with the reason, and Grok Build should tell you rather than retry. A finer change, such as the cache expiry, goes through get_settings and update_settings the same way. If any key or value is wrong, the whole call is refused and nothing is stored, Pro-only settings are refused without a licence, and credential fields are refused over the Hub.

What differs in Grok Build is its permission modes. It starts in Ask mode, which prompts for anything a rule has not allowed, so toggle_cache and update_settings prompt until you say otherwise. A rule such as MCPTool(xspeedhub__get_*) allows the reads, and evaluation runs deny, then ask, then allow. Always-approve approves tool calls unless a deny rule or a hook stops them, and Auto lets a classifier approve what it judges safe, so with either the Hub runs a write as soon as the connection allows it. Grok Build stores the credentials it receives on your machine, so treat that machine as a place that can reach your sites.

## Set up Grok Build once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub with grok mcp add

Run this once. Add --scope project to write the server to .grok/config.toml in the current directory instead of your user config, which is only sensible if the repo never holds a token. Grok Build handles the OAuth flow for a remote server on its own.

```bash
grok mcp add --transport http xspeedhub https://app.xspeedcache.com/xspeed/mcp
```

### 3. Sign in from the TUI

Start grok and open /mcps. Select xspeedhub and press i to authenticate, or just use a Hub tool and let the browser flow start on first use. Sign in to xSpeed Hub and approve access. There is no token to paste; Grok Build stores the credentials it receives in ~/.grok/mcp_credentials.json. If the connection fails, run grok mcp doctor xspeedhub.

```
/mcps
```

Full setup: https://xspeedcache.com/agent/grok-build/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Grok Build starts in Ask mode, which prompts for anything a rule has not already allowed, so a Hub write tool prompts until you say otherwise. You can allow the reads with a rule such as MCPTool(xspeedhub__get_*) in the permission section of your config, and leave the writes unmatched. Evaluation runs deny, then ask, then allow. Two other modes remove the prompt: Always-approve, from /always-approve, Ctrl+O or --always-approve, approves tool calls unless a deny rule or a hook stops them, and Auto lets a classifier approve tools it judges safe. If a Hub write must never run unprompted, add a deny rule. The Hub itself has no confirmation step.

## Prompts

- We moved shop to a new host. Using xSpeed Hub, is page caching still on, and how many pages are stored?
- Use xSpeed Hub to check page caching on shop. If it is off, show me what you would change, then wait for my yes before you turn it on.
- Ask xSpeed Hub for the cache expiry on shop and blog and tell me if they differ.

## Example session

```
You: We moved shop to a new host. Use xSpeed Hub to check whether page caching is still on.
  → get_cache_status(site: shop) [read-only]: page cache off, 0 cached pages
Agent: Page caching is off on shop after the move, so every request builds fresh. I would turn it on with toggle_cache. Turn it on?
You: Yes, turn it on.
  → toggle_cache(site: shop, enabled: true) [changes site]: page cache turned on
Agent: Caching is on. Pages fill as visitors arrive; start the preloader if you want them warm first.
```

## How it works

1. **List the modules**: list_modules returns every Free and Pro module available on one site, with its settings schema and status. It tells the agent which module slugs exist, such as minify or gzip, and what each setting accepts.
2. **Read the current settings**: get_settings takes a module slug and returns its settings. Credential fields come back masked, so an agent cannot read a stored API token or password back in plain text.
3. **Change them**: update_settings takes the module and a values object of setting keys. The site checks the whole object first. If any key is unknown, any value is outside the schema, or a field is pinned by a constant in wp-config.php, it refuses the write, writes nothing and says which keys and why, sometimes with a "did you mean" hint.
4. **Turn page caching on or off**: Page caching has its own tool, toggle_cache, because it installs or removes the cache drop-in and the WP_CACHE constant. Asking update_settings to set cache_enabled does not work and is refused. If another caching plugin owns the drop-in, the site declines to enable xSpeed and returns blocked: true with the reason.
5. **Check the effect**: The result of a settings write is the stored settings. A module can add a warning when a setting is saved but has no effect on this server, for example Brotli on a server without the module for it, and the agent should pass that on. run_benchmark then times cached against uncached to see whether the change helped.
6. **Apply to many sites only after reading one**: update_settings and toggle_cache accept site: "all" or a list of handles. Each site validates against its own schema and answers in its own row, so a module missing on one site fails that row and the others still apply. Read one site first, then apply.

## Reference

| | |
| --- | --- |
| Discover | list_modules (read): Free and Pro modules, settings schema, status, per site |
| Read settings | get_settings (read): argument module; credential fields masked |
| Change settings | update_settings (write): arguments module and values; validated by the site |
| Bad input | The whole write is refused and nothing is written; the error names the keys and reasons |
| Page cache on or off | toggle_cache (write): argument enabled; cache_enabled in update_settings is refused |
| Blocked by another plugin | toggle_cache returns blocked: true with blocked_reason when another plugin owns the cache drop-in |
| Every site at once | update_settings and toggle_cache accept site: "all" or a list of handles, one result per site |
| Pro modules | A Pro module on a site without an active licence cannot be read or written; the site refuses |
| Credential fields | Refused by default over MCP; set them in the xSpeed dashboard, not through the agent |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in: update_settings and toggle_cache are refused; list_modules and get_settings still work. An OAuth sign-in gets the scopes the client asks for, read and write by default, clamped to the member's role |
| Confirmation | None on the Hub; the Hub tells the agent to briefly confirm intent for these two, and your client's prompt is the gate |

## Rules

- Read before you write. Ask for list_modules and get_settings first, so the agent changes real keys with valid values instead of guessing.
- update_settings and toggle_cache change how a live site behaves. They run as soon as your connection allows writes. The Hub tells the agent to briefly confirm intent first, which is guidance to the agent, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates. The switch does not limit an OAuth sign-in.
- For site: "all", the Hub tells the agent to confirm once with "this will touch all N sites", then make one call. The result is per site, and some sites failing is a partial result to report, not a blanket success or failure.
- Do not ask an agent to set credentials such as a Cloudflare token or Redis password. The site refuses those writes by default, and they belong in the xSpeed dashboard.
- If a settings result says a value is saved but inactive on this server, relay that. Do not tell the user the feature is enabled.

## Good to know with Grok Build

Always-approve skips prompts for Hub writes too, and Auto leaves the decision to a classifier. Add a deny rule for any tool that must never run unprompted, because deny rules still apply in Always-approve. The client keeps the credentials it receives in a file on your machine, so anyone who can read your home directory can use that connection. Use a read-only connection when you only want to look: the connection token with Read-only everywhere on, or a Viewer sign-in.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to list the modules on shop and tell me which ones are off.
- Ask xSpeed Hub for the current minify settings on blog.
- With xSpeed Hub, turn on HTML minification on blog, then benchmark the cache and tell me if it helped.
- Use xSpeed Hub to turn page caching off on staging while I debug, and tell me when it is off.
- Using xSpeed Hub, read the gzip settings on shop first, then enable the same options on every site.
- Use xSpeed Hub to set the page cache lifespan on docs to 30 days, and if the site refuses it, tell me why.

## Frequently asked questions

### Does Grok Build ask before it changes a setting?

In its default Ask mode it prompts for tool calls that no rule has allowed, so toggle_cache and update_settings stop for your approval. Always-approve and Auto remove that prompt. The Hub does not ask on its own, so add a deny rule for any write you never want to run, or connect read-only with the connection token and Read-only everywhere on, or a Viewer sign-in.

### Where does Grok Build keep my xSpeed credentials?

The client keeps the credentials it receives from the sign-in on your machine, so there is no token to paste. Anyone with access to your account on that machine can use them. If you lose a laptop, remove the sign-in in Grok Build. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in like this one.

### How does an agent know which settings exist?

It calls list_modules for the site, which returns every available module with its settings schema and status, then get_settings for the one module it wants to change. The schema says which keys exist and what values each accepts.

### What happens if the agent sends a wrong setting key?

The site refuses the whole update and writes nothing. The error names the keys it rejected and why, such as an unknown key, a value outside the allowed range, or a field fixed by a constant in wp-config.php, and it can suggest the nearest valid key.

### How do I turn page caching on or off with an agent?

Use toggle_cache with enabled set to true or false. It installs or removes the cache drop-in and the WP_CACHE constant. Setting cache_enabled through update_settings does not work. If another caching plugin already owns the drop-in, the site will not enable xSpeed and says why.

### Can one prompt change settings on all of my sites?

Yes. update_settings and toggle_cache accept site: "all", and the Hub runs the sites one after another with a one-second pause and returns a result per site. Each site checks the values against its own schema, so a site that lacks the module fails its own row while the others apply.

### Can the agent change my Cloudflare or Redis credentials?

Not by default. Writing credential fields over MCP is off unless the site owner allows it, and the site refuses the write and names the fields. Set credentials in the xSpeed dashboard. Credential values also come back masked when an agent reads settings.

## Tune cache settings with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/cache-settings/) · [Claude](https://xspeedcache.com/agent/claude/cache-settings/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/cache-settings/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/cache-settings/) · [Codex](https://xspeedcache.com/agent/codex/cache-settings/) · [Cursor](https://xspeedcache.com/agent/cursor/cache-settings/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/cache-settings/) · [Windsurf](https://xspeedcache.com/agent/windsurf/cache-settings/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/cache-settings/) · [Antigravity](https://xspeedcache.com/agent/antigravity/cache-settings/) · [Zed](https://xspeedcache.com/agent/zed/cache-settings/) · [Kiro](https://xspeedcache.com/agent/kiro/cache-settings/) · [OpenCode](https://xspeedcache.com/agent/opencode/cache-settings/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/cache-settings/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cache-settings/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/cache-settings/) · [Grok](https://xspeedcache.com/agent/grok/cache-settings/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/cache-settings/) · [Muse](https://xspeedcache.com/agent/muse/cache-settings/) · [Manus](https://xspeedcache.com/agent/manus/cache-settings/) · [Kimi Code](https://xspeedcache.com/agent/kimi/cache-settings/) · [Paperclip](https://xspeedcache.com/agent/paperclip/cache-settings/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/cache-settings/)

## More with Grok Build

- [Purge the WordPress cache with Grok Build](https://xspeedcache.com/agent/grok-build/purge-cache/)
- [Find out why WordPress pages are not cached with Grok Build](https://xspeedcache.com/agent/grok-build/troubleshoot-cache/)
- [Scan a website for speed problems with Grok Build](https://xspeedcache.com/agent/grok-build/speed-scan/)
- [Run and track PageSpeed tests with Grok Build](https://xspeedcache.com/agent/grok-build/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with Grok Build](https://xspeedcache.com/agent/grok-build/optimize-site/)
- [Warm the WordPress cache with Grok Build](https://xspeedcache.com/agent/grok-build/preload-cache/)
- [Set up the Redis object cache with Grok Build](https://xspeedcache.com/agent/grok-build/object-cache/)
- [Manage Cloudflare caching with Grok Build](https://xspeedcache.com/agent/grok-build/cloudflare/)
- [Manage every WordPress site at once with Grok Build](https://xspeedcache.com/agent/grok-build/fleet/)

## Documentation

- How to enable Page Cache: https://xspeedcache.com/docs/page-cache/
- How to minify CSS and JavaScript: https://xspeedcache.com/docs/minify/
- How to add cache rules and bypasses: https://xspeedcache.com/docs/rules-and-bypass/
- Site MCP tool reference: https://xspeedcache.com/docs/mcp-tool-reference/
