How Grok Build handles this
You are in a Grok Build session in the terminal after a deploy, and a page still shows the old layout. You tell it the site and what you changed. It calls list_sites to match the name, then purge_cache with a type that fits, and start_preloader if you asked for a warm-up. Each call prints in the session with its result, so you can see what was sent.
The result is the plugin's report: purge type, site, entries cleared, and for all the object cache and a connected Cloudflare edge. Grok Build works in your repository, so it can read the diff and say why it chose assets over page. It also stores the credentials it receives from the sign-in on your machine, so treat that machine as holding access to your sites, and remove the server from Grok Build when you stop using it.
Grok Build starts in Ask mode, which prompts for anything a rule has not already allowed, so purge_cache prompts until you say otherwise. Auto lets a classifier approve tools it judges safe, and Always-approve skips prompts unless a deny rule or a hook stops the call. xSpeed Hub has no confirmation of its own, so a purge runs as soon as the connection allows writes and Grok Build lets the call through. For a purge across every site, the Hub also tells Grok Build to say it will touch all the sites and wait for your yes, but that is guidance to the model, not a lock.
Set up Grok Build once
Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Grok Build guide.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub with grok mcp add
Run this once. Add --scope project to write the server to .grok/config.toml in the current directory instead of your user config, which is only sensible if the repo never holds a token. Grok Build handles the OAuth flow for a remote server on its own.
grok mcp add --transport http xspeedhub https://app.xspeedcache.com/xspeed/mcp
3Sign in from the TUI
Start grok and open /mcps. Select xspeedhub and press i to authenticate, or just use a Hub tool and let the browser flow start on first use. Sign in to xSpeed Hub and approve access. There is no token to paste; Grok Build stores the credentials it receives in ~/.grok/mcp_credentials.json. If the connection fails, run grok mcp doctor xspeedhub.
/mcps
Full Grok Build setup, sign-in options and FAQ
Before you send a prompt that changes something
Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Grok Build starts in Ask mode, which prompts for anything a rule has not already allowed, so a Hub write tool prompts until you say otherwise. You can allow the reads with a rule such as MCPTool(xspeedhub__get_*) in the permission section of your config, and leave the writes unmatched. Evaluation runs deny, then ask, then allow. Two other modes remove the prompt: Always-approve, from /always-approve, Ctrl+O or --always-approve, approves tool calls unless a deny rule or a hook stops them, and Auto lets a classifier approve tools it judges safe. If a Hub write must never run unprompted, add a deny rule. The Hub itself has no confirmation step.
What do I ask?
Three prompts written for Grok Build. More for this job are below.
I shipped a new nav to docs. Use xSpeed Hub to purge everything there and tell me whether Cloudflare was cleared too.
With xSpeed Hub, purge the assets cache on shop and tell me how many files were cleared.
Use xSpeed Hub to purge every site in my workspace and list any that failed and why.
What happens, step by step
A purge throws away stored copies so the next visitor gets a fresh page. Through xSpeed Hub an agent can purge everything, only pages, only CSS and JavaScript assets, the object cache or the REST cache, on one site or across every site in a workspace. A full purge also clears the Cloudflare edge when the site has Cloudflare connected.
01
Find the site
The agent calls list_sites when you have more than one site, then matches the name you used to a site handle. If the name could mean two sites, the Hub tells it to ask you rather than guess.
02
Pick the purge type
purge_cache takes a type: all, page, assets, object or rest. all clears the page cache, the object cache and, when they are connected, the Cloudflare edge and CDN. After a theme or CSS change, assets is enough; after a content edit, page; after a deploy, all.
03
Purge
The call runs straight away on that site once your connection allows writes. For every site at once the agent passes site: "all", and the Hub runs the sites one after another with a one-second pause.
04
Clear only the edge if that is all you need
purge_cloudflare empties the Cloudflare edge cache on its own, without touching the copies on your server. A page or assets purge does not reach Cloudflare; a purge of type all does when Cloudflare is connected.
05
Warm it again
start_preloader rebuilds the cache in the background so the first visitors after the purge are not the ones paying for it.
Reference
| Tool | purge_cache (write) |
|---|---|
| Purge types | all, page, assets, object, rest |
| What all covers | Page cache, object cache, plus the Cloudflare edge and CDN when connected |
| Every site at once | site: "all" or a list of handles, one result per site |
| Fan-out pacing | Sites run one after another with a 1 second pause |
| Edge only | purge_cloudflare, a separate write tool |
| Re-warm | start_preloader after the purge |
| Read-only access | purge_cache is refused on a connection token with Read-only everywhere on, and for a Viewer sign-in |
| Confirmation | None on the Hub; your client's prompt is the gate |
Rules worth keeping
- Name the site. With several sites, an unclear name should make the agent ask, and the Hub tells it to.
- A purge of every site is one call with site: "all". The Hub tells the agent to confirm it with you once before it runs.
- Purge the narrowest type that fixes the problem, then warm the cache, so visitors do not all hit uncached pages at once.
- A fan-out result is reported per site. Treat some sites failing as a partial result, not a failure of the whole call.
Good to know with Grok Build
The sign-in credentials sit on the machine where Grok Build runs, so anyone or anything with access to your user account there can use them to purge your sites. Do not share that login on a shared server, and remove the server from Grok Build when you stop using it. Signing in as a Viewer member limits the damage if the machine is ever compromised, but it also means purges are refused, so keep it for sessions that only inspect. The Hub's Read-only everywhere switch cannot do this job, because it applies only to the connection token. Allow the reads with an MCPTool rule on xspeedhub__get_*, and add a deny rule for xspeedhub__purge_cache wherever a purge must never run unprompted, because deny rules still apply under Always-approve.
More prompts for this job
They work in any client connected to xSpeed Hub.
Use xSpeed Hub to purge the page cache on blog.
I just changed the theme CSS on shop. Use xSpeed Hub to purge only the assets cache there.
With xSpeed Hub, purge every site in my workspace and tell me which ones failed.
Use xSpeed Hub to purge shop, then purge its Cloudflare edge cache too.
With xSpeed Hub, purge the docs site and start the preloader so it is warm again.
Using xSpeed Hub, what purge type should I use after updating a plugin that changes the checkout page?
Frequently asked questions
Keep going
Purge the cache with other agents
More with Grok Build
Documentation
- How to enable Page Cache
- How to warm your cache ahead of visitors
- Managing your fleet with xSpeed Hub
- How to write prompts for xSpeed Hub
- Grok Build + xSpeed
- Every AI agent that works with xSpeed
From the blog