# Tune WordPress cache settings with Hermes Agent

> Tuning cache settings with Hermes Agent means asking it to audit the xSpeed cache exclusions on your WordPress sites, point out URLs that should stay out of the cache, and write the fix through xSpeed Hub once you agree.

Page: https://xspeedcache.com/agent/hermes-agent/cache-settings/
Last updated: October 2026

You run Hermes Agent as a long-lived assistant, and a member of your team reports that a members-only page showed someone else's dashboard for a moment. That is a cache exclusion problem, and you want it looked at across every site, not just the one you noticed. You ask Hermes Agent to read the cache module on each site and list the excluded URLs and cookies. It calls list_sites, then get_settings for the cache module on each site, one by one.

What comes back is a table in the conversation: for each site, which URLs are excluded, whether login or account paths are among them, and where a path that probably belongs there is missing. Nothing is written at that point. When you point at a site and say add this path, Hermes Agent calls update_settings, and the Hub tells it to briefly confirm intent before it does. The result is the stored list for that site. If any key or value is wrong, the whole call is refused and nothing is stored, Pro-only modules are refused without a licence, and credential fields are refused over the Hub.

What differs in Hermes Agent is trust. A server entry's default, full, adds no approval prompt for that server's tools, so a Hub write runs as soon as your connection allows it. Set trust to untrusted on the xspeedhub entry and Hermes asks before every call to a tool that lacks a read-only hint. The Hub marks none of its tools that way, so every Hub call asks, reads included. Hermes also has a cron scheduler in the gateway, so the same audit can run on a timer and message you when an exclusion disappears. A scheduled run has nobody to answer a prompt, so keep that job to reads.

## Set up Hermes Agent once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to config.yaml

Add this entry under mcp_servers. auth: oauth tells Hermes to handle discovery, dynamic client registration, PKCE and token refresh itself. If you edit the file from inside a running session, Hermes reloads its MCP connections with a 30 second timeout, which is too short for a browser sign-in, so finish the entry and then run the login in the next step.

File: `~/.hermes/config.yaml`

```yaml
mcp_servers:
  xspeedhub:
    url: "https://app.xspeedcache.com/xspeed/mcp"
    auth: oauth
```

### 3. Sign in with hermes mcp login

Run this once. Hermes prints an authorization URL, opens your browser where it can, and waits for the callback on a local loopback port. Sign in to xSpeed Hub and approve. There is no token to paste; Hermes caches the credentials it receives under ~/.hermes/mcp-tokens. On a remote host, paste the redirect URL back into the terminal when Hermes asks, or forward the callback port over SSH.

```bash
hermes mcp login xspeedhub
hermes mcp test xspeedhub
```

Full setup: https://xspeedcache.com/agent/hermes-agent/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. A Hermes server entry has a trust setting. The default, full, adds no approval prompt for that server's tools, and the approvals setting covers dangerous shell commands, not MCP tools. Set trust: untrusted on the xspeedhub entry and Hermes asks before every call to a tool that lacks a readOnlyHint of true. The Hub does not mark its tools that way, so with untrusted every Hub call asks, reads included. To remove writes instead of prompting, set tools.include on the entry to the read tools; the filter takes globs and include wins over exclude. The Hub itself has no confirmation step.

## Prompts

- Use xSpeed Hub to read the excluded URLs and cookies on every site and tell me where /my-account/ or /members/ is missing.
- With xSpeed Hub, add /members/ to the cache exclusions on blog only, and show me the full list before and after.
- Set up a daily check that asks xSpeed Hub for the cache exclusions on all sites and messages me if one of them changes.

## Example session

```
You: Someone saw another member's dashboard on blog, and their browser showed x-xspeed-cache: HIT on /members/dashboard/. Use xSpeed Hub to check what is excluded from the cache.
  → get_settings(site: blog, module: cache) [read-only]: excluded URLs: /cart/, /checkout/; excluded cookies: the defaults, which catch the WordPress login cookie
Agent: A HIT means xSpeed served a stored copy. /members/ is not an excluded URL, and the cookie exclusions only catch the WordPress login cookie, so if your membership plugin signs members in with its own cookie, nothing stops their pages being cached. Adding /members/ to the excluded URLs stops it whatever cookie the plugin uses. I would add it and keep the two existing entries. Apply it?
You: Yes, add it now.
  → update_settings(site: blog, module: cache, values: { excluded_urls: [/cart/, /checkout/, /members/] }) [changes site]: stored, 3 excluded URLs
Agent: Added. Purge the blog page cache too, because a stored copy of a members page may still exist.
```

## How it works

1. **List the modules**: list_modules returns every Free and Pro module available on one site, with its settings schema and status. It tells the agent which module slugs exist, such as minify or gzip, and what each setting accepts.
2. **Read the current settings**: get_settings takes a module slug and returns its settings. Credential fields come back masked, so an agent cannot read a stored API token or password back in plain text.
3. **Change them**: update_settings takes the module and a values object of setting keys. The site checks the whole object first. If any key is unknown, any value is outside the schema, or a field is pinned by a constant in wp-config.php, it refuses the write, writes nothing and says which keys and why, sometimes with a "did you mean" hint.
4. **Turn page caching on or off**: Page caching has its own tool, toggle_cache, because it installs or removes the cache drop-in and the WP_CACHE constant. Asking update_settings to set cache_enabled does not work and is refused. If another caching plugin owns the drop-in, the site declines to enable xSpeed and returns blocked: true with the reason.
5. **Check the effect**: The result of a settings write is the stored settings. A module can add a warning when a setting is saved but has no effect on this server, for example Brotli on a server without the module for it, and the agent should pass that on. run_benchmark then times cached against uncached to see whether the change helped.
6. **Apply to many sites only after reading one**: update_settings and toggle_cache accept site: "all" or a list of handles. Each site validates against its own schema and answers in its own row, so a module missing on one site fails that row and the others still apply. Read one site first, then apply.

## Reference

| | |
| --- | --- |
| Discover | list_modules (read): Free and Pro modules, settings schema, status, per site |
| Read settings | get_settings (read): argument module; credential fields masked |
| Change settings | update_settings (write): arguments module and values; validated by the site |
| Bad input | The whole write is refused and nothing is written; the error names the keys and reasons |
| Page cache on or off | toggle_cache (write): argument enabled; cache_enabled in update_settings is refused |
| Blocked by another plugin | toggle_cache returns blocked: true with blocked_reason when another plugin owns the cache drop-in |
| Every site at once | update_settings and toggle_cache accept site: "all" or a list of handles, one result per site |
| Pro modules | A Pro module on a site without an active licence cannot be read or written; the site refuses |
| Credential fields | Refused by default over MCP; set them in the xSpeed dashboard, not through the agent |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in: update_settings and toggle_cache are refused; list_modules and get_settings still work. An OAuth sign-in gets the scopes the client asks for, read and write by default, clamped to the member's role |
| Confirmation | None on the Hub; the Hub tells the agent to briefly confirm intent for these two, and your client's prompt is the gate |

## Rules

- Read before you write. Ask for list_modules and get_settings first, so the agent changes real keys with valid values instead of guessing.
- update_settings and toggle_cache change how a live site behaves. They run as soon as your connection allows writes. The Hub tells the agent to briefly confirm intent first, which is guidance to the agent, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates. The switch does not limit an OAuth sign-in.
- For site: "all", the Hub tells the agent to confirm once with "this will touch all N sites", then make one call. The result is per site, and some sites failing is a partial result to report, not a blanket success or failure.
- Do not ask an agent to set credentials such as a Cloudflare token or Redis password. The site refuses those writes by default, and they belong in the xSpeed dashboard.
- If a settings result says a value is saved but inactive on this server, relay that. Do not tell the user the feature is enabled.

## Good to know with Hermes Agent

Hermes Agent adds no prompt for a server with the default trust of full, so until you set trust to untrusted, update_settings is only held back by the Hub's request to confirm. With untrusted you will be asked for reads such as get_settings as well. A cron job has nobody watching it: give it a tools include list of read tools, or a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) so the Hub refuses every write, and keep the write connection for conversations where you read the proposal.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to list the modules on shop and tell me which ones are off.
- Ask xSpeed Hub for the current minify settings on blog.
- With xSpeed Hub, turn on HTML minification on blog, then benchmark the cache and tell me if it helped.
- Use xSpeed Hub to turn page caching off on staging while I debug, and tell me when it is off.
- Using xSpeed Hub, read the gzip settings on shop first, then enable the same options on every site.
- Use xSpeed Hub to set the page cache lifespan on docs to 30 days, and if the site refuses it, tell me why.

## Frequently asked questions

### Can Hermes Agent check my cache exclusions on a schedule?

Yes, through hermes cron. The scheduler lives in the gateway process, which has to be running, and each job starts a fresh session, calls get_settings and messages you if an exclusion changes. The Hub has no scheduler for agent prompts, so the timer is on the Hermes Agent side. Keep the job to read tools so it cannot write on its own.

### Will adding a URL to the exclusions fix a page already in the cache?

No. The exclusion stops that URL being stored from now on, but a copy stored earlier stays until it expires or you purge. Ask Hermes Agent to purge the page cache on that site after it writes the exclusion.

### How does an agent know which settings exist?

It calls list_modules for the site, which returns every available module with its settings schema and status, then get_settings for the one module it wants to change. The schema says which keys exist and what values each accepts.

### What happens if the agent sends a wrong setting key?

The site refuses the whole update and writes nothing. The error names the keys it rejected and why, such as an unknown key, a value outside the allowed range, or a field fixed by a constant in wp-config.php, and it can suggest the nearest valid key.

### How do I turn page caching on or off with an agent?

Use toggle_cache with enabled set to true or false. It installs or removes the cache drop-in and the WP_CACHE constant. Setting cache_enabled through update_settings does not work. If another caching plugin already owns the drop-in, the site will not enable xSpeed and says why.

### Can one prompt change settings on all of my sites?

Yes. update_settings and toggle_cache accept site: "all", and the Hub runs the sites one after another with a one-second pause and returns a result per site. Each site checks the values against its own schema, so a site that lacks the module fails its own row while the others apply.

### Can the agent change my Cloudflare or Redis credentials?

Not by default. Writing credential fields over MCP is off unless the site owner allows it, and the site refuses the write and names the fields. Set credentials in the xSpeed dashboard. Credential values also come back masked when an agent reads settings.

## Tune cache settings with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/cache-settings/) · [Claude](https://xspeedcache.com/agent/claude/cache-settings/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/cache-settings/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/cache-settings/) · [Codex](https://xspeedcache.com/agent/codex/cache-settings/) · [Cursor](https://xspeedcache.com/agent/cursor/cache-settings/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/cache-settings/) · [Windsurf](https://xspeedcache.com/agent/windsurf/cache-settings/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/cache-settings/) · [Antigravity](https://xspeedcache.com/agent/antigravity/cache-settings/) · [Zed](https://xspeedcache.com/agent/zed/cache-settings/) · [Kiro](https://xspeedcache.com/agent/kiro/cache-settings/) · [OpenCode](https://xspeedcache.com/agent/opencode/cache-settings/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/cache-settings/) · [Grok Build](https://xspeedcache.com/agent/grok-build/cache-settings/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/cache-settings/) · [Grok](https://xspeedcache.com/agent/grok/cache-settings/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/cache-settings/) · [Muse](https://xspeedcache.com/agent/muse/cache-settings/) · [Manus](https://xspeedcache.com/agent/manus/cache-settings/) · [Kimi Code](https://xspeedcache.com/agent/kimi/cache-settings/) · [Paperclip](https://xspeedcache.com/agent/paperclip/cache-settings/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/cache-settings/)

## More with Hermes Agent

- [Purge the WordPress cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/purge-cache/)
- [Find out why WordPress pages are not cached with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/troubleshoot-cache/)
- [Scan a website for speed problems with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/speed-scan/)
- [Run and track PageSpeed tests with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/optimize-site/)
- [Warm the WordPress cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/preload-cache/)
- [Set up the Redis object cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/object-cache/)
- [Manage Cloudflare caching with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/)
- [Manage every WordPress site at once with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/fleet/)

## Documentation

- How to enable Page Cache: https://xspeedcache.com/docs/page-cache/
- How to minify CSS and JavaScript: https://xspeedcache.com/docs/minify/
- How to add cache rules and bypasses: https://xspeedcache.com/docs/rules-and-bypass/
- Site MCP tool reference: https://xspeedcache.com/docs/mcp-tool-reference/
