How Hermes Agent handles this
Hermes Agent keeps running between your requests and has a built-in cron scheduler, so the natural use is a regular fleet report for someone who runs many sites and does not want to remember to check. You ask it, or schedule it, to benchmark every site in the workspace. It calls run_benchmark with site set to "all", and the Hub runs the sites one after another with a pause of one second between them, so thirty sites take about thirty seconds to answer.
That delay matters for a cron job. A run across a large portfolio is a long single call, so keep a fleet job on a cadence that leaves it time to finish, and do not start a new run while the last one is in flight. The result comes back as one entry per site, and a site that could not be reached is one failed row with its own error, so Hermes Agent can report a partial success exactly as it happened. The Hub also runs its own daily pass and alerts you by Slack or email, once per incident, when a site goes unreachable or caching is switched off, so your cron job does not need to repeat that.
Use cron for reads and your own attention for writes. purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader and optimize_site all accept "all" and all write. Hermes Agent adds no prompt for a server whose trust is full, which is the default. Set trust to untrusted on the entry and it asks before every call to a tool without a read-only hint, which for the Hub means every call, reads included. A scheduled run has nobody to answer a prompt, and the Hub's confirm-once instruction, which does not name optimize_site, needs a person present, so use a tools include list of the read tools to keep a cron job to reads.
Set up Hermes Agent once
Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Hermes Agent guide.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub to config.yaml
Add this entry under mcp_servers. auth: oauth tells Hermes to handle discovery, dynamic client registration, PKCE and token refresh itself. If you edit the file from inside a running session, Hermes reloads its MCP connections with a 30 second timeout, which is too short for a browser sign-in, so finish the entry and then run the login in the next step.
mcp_servers:
xspeedhub:
url: "https://app.xspeedcache.com/xspeed/mcp"
auth: oauth 3Sign in with hermes mcp login
Run this once. Hermes prints an authorization URL, opens your browser where it can, and waits for the callback on a local loopback port. Sign in to xSpeed Hub and approve. There is no token to paste; Hermes caches the credentials it receives under ~/.hermes/mcp-tokens. On a remote host, paste the redirect URL back into the terminal when Hermes asks, or forward the callback port over SSH.
hermes mcp login xspeedhub hermes mcp test xspeedhub
Full Hermes Agent setup, sign-in options and FAQ
Before you send a prompt that changes something
Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. A Hermes server entry has a trust setting. The default, full, adds no approval prompt for that server's tools, and the approvals setting covers dangerous shell commands, not MCP tools. Set trust: untrusted on the xspeedhub entry and Hermes asks before every call to a tool that lacks a readOnlyHint of true. The Hub does not mark its tools that way, so with untrusted every Hub call asks, reads included. To remove writes instead of prompting, set tools.include on the entry to the read tools; the filter takes globs and include wins over exclude. The Hub itself has no confirmation step.
What do I ask?
Three prompts written for Hermes Agent. More for this job are below.
Every night, use xSpeed Hub to benchmark all my sites and tell me about any whose cached time has gotten worse.
With xSpeed Hub, run the benchmark on every site now and list the sites that failed to respond.
Ask xSpeed Hub for the workspaces I can reach and how many sites each one has.
What happens, step by step
If you run many WordPress sites, repeating one action on each is the slow part. Through xSpeed Hub, seven tools accept every site in a workspace, or a list of handles, in a single call. The Hub runs the sites one after another and returns a result for each, so a site that fails is named instead of hidden. Everything else in the Hub works on one site per call.
01
See what you can reach
list_sites returns each site's handle, URL, status and scopes. When you have more than one workspace, list_workspaces returns each one's handle, id, your role, its site count, which one is the default, and whether this connection can reach it.
02
Choose the scope of the call
The agent passes site: "all" for every site in one workspace, or an array of handles for exactly those sites. For a workspace other than the default it also passes the workspace argument. Omit workspace and the call acts on the default workspace.
03
Confirm once
Before a purge, toggle, settings change or preloader call that touches every site, the Hub tells the agent to say "this will touch all N sites" and wait for you, then make one call. That instruction does not name optimize_site, so for it your client's prompt is the gate. It is guidance to the agent, not a lock. It is one tool call, so one approval in your client covers every site in it.
04
Run it as one call
The Hub runs the sites one after another with a one-second pause between live calls, so a fleet purge is not a burst of traffic at your servers. Revoked sites are skipped from "all". Each site's action lands in the activity log as its own row.
05
Read the result per site
The reply is a summary of targets, succeeded and failed, plus one row per site with ok and either its data or its error. Some sites failing is a partial success. Only a run where every site failed comes back as an error.
06
Follow up on the failures
The agent reports which sites failed and why, then retries just those handles with an array. Tools that read one site, such as get_cache_status and get_health, do not fan out, so a fleet-wide check means one call per site.
Reference
| Fan-out tools | purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader, optimize_site, run_benchmark |
|---|---|
| Selector | site: "all", or an array of handles |
| What all covers | Every site this connection can see in one workspace, minus revoked ones |
| Pacing | One after another, with a 1 second pause between live calls |
| Result | summary (targets, succeeded, failed) and a row per site: ok, then data or error |
| Partial failure | Reported per site; the call counts as an error only when every site failed |
| Workspace argument | Optional. Omit it for the default workspace; name one by its handle or id from list_workspaces |
| Reach | Fixed when you approve the connection; list_workspaces shows reachable: false for the rest |
| Not fan-out | get_health, get_cache_status and every other tool take one site per call |
| Slow tools | optimize_site takes up to 2 minutes per site; a target_score run is capped at 12 rounds per call |
| Read-only | The connection token with Read-only everywhere on, or a Viewer sign-in, refuses every fan-out write; run_benchmark works. An OAuth sign-in gets the scopes the client asks for |
| Hub daily pass | Re-verifies sites, snapshots cache status and hit ratio, reads stored reports, alerts by Slack webhook or email |
Rules worth keeping
- Confirm once, then call once. The Hub has no confirmation step of its own, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates that matter. The Hub's "this will touch all N sites" is an instruction to the agent for purge, toggle, settings and preloader calls, and it does not name optimize_site.
- "all" is one workspace, never every workspace. To act in another workspace, name it. A write to a non-default workspace must name it, and an array of handles is looked up only in the workspace the call names.
- Read every result per site. Treat some sites failing as a partial result, and never accept a blanket "done" from the agent.
- Try a behaviour change on one site before you send it to the fleet. toggle_cache and update_settings on every site are one call, and each site checks values against its own settings, so a Pro setting can fail on a Free site.
- optimize_site on many sites is slow, because each site can take up to two minutes inside one call. Use dry_run first, or name a short list of handles.
- The Hub has no scheduler for agent prompts. Its own daily pass and alerts run without an agent, and an agent can only act when you send a prompt or your AI client runs one on a timer.
Good to know with Hermes Agent
A cron job that writes would run with nobody to confirm it. Hermes Agent can schedule prompts, but the Hub has no scheduler of its own and its instruction to confirm before a purge, toggle, settings change or preloader call on every site only helps when someone is reading. If you want a scheduled job to do more than read, give it its own connection with a scope you chose, and expect that a write runs as soon as the scope allows. Cron never opens a browser, so when the refresh token stops working the Hub server is parked until you sign in again from a terminal, and the next scheduled report fails until you do. Sort out which workspace the job targets, since all covers one only.
More prompts for this job
They work in any client connected to xSpeed Hub.
Use xSpeed Hub to list every site I can reach, and every workspace, and say which workspace you act in by default.
With xSpeed Hub, purge the cache on every site in my workspace and tell me which ones failed.
Use xSpeed Hub to run a benchmark on all my sites and rank them by cached response time.
Use xSpeed Hub to start the preloader on blog, shop and docs only.
With xSpeed Hub, turn page caching on for every site where it is off. Check each site first.
Use xSpeed Hub to stop the preloader everywhere. The servers are busy.
Ask xSpeed Hub to preview a safe optimize_site pass on every site with dry_run and summarize what it would change.
Use xSpeed Hub to purge every site in the client-acme workspace, not my default one.
Frequently asked questions
Keep going
Manage every site at once with other agents
More with Hermes Agent
Documentation
- Managing your fleet with xSpeed Hub
- Teams, roles and workspaces in xSpeed Hub
- Scoped AI connections in xSpeed Hub
- Connecting to xSpeed Hub
- How to write prompts for xSpeed Hub
- Hermes Agent + xSpeed
- Every AI agent that works with xSpeed
From the blog