# Manage every WordPress site at once with Hermes Agent

> Managing every WordPress site at once with Hermes Agent means letting a long-running agent call xSpeed Hub across your whole workspace, by hand or on a cron schedule, and report what each site did.

Page: https://xspeedcache.com/agent/hermes-agent/fleet/
Last updated: October 2026

Hermes Agent keeps running between your requests and has a built-in cron scheduler, so the natural use is a regular fleet report for someone who runs many sites and does not want to remember to check. You ask it, or schedule it, to benchmark every site in the workspace. It calls run_benchmark with site set to "all", and the Hub runs the sites one after another with a pause of one second between them, so thirty sites take about thirty seconds to answer.

That delay matters for a cron job. A run across a large portfolio is a long single call, so keep a fleet job on a cadence that leaves it time to finish, and do not start a new run while the last one is in flight. The result comes back as one entry per site, and a site that could not be reached is one failed row with its own error, so Hermes Agent can report a partial success exactly as it happened. The Hub also runs its own daily pass and alerts you by Slack or email, once per incident, when a site goes unreachable or caching is switched off, so your cron job does not need to repeat that.

Use cron for reads and your own attention for writes. purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader and optimize_site all accept "all" and all write. Hermes Agent adds no prompt for a server whose trust is full, which is the default. Set trust to untrusted on the entry and it asks before every call to a tool without a read-only hint, which for the Hub means every call, reads included. A scheduled run has nobody to answer a prompt, and the Hub's confirm-once instruction, which does not name optimize_site, needs a person present, so use a tools include list of the read tools to keep a cron job to reads.

## Set up Hermes Agent once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to config.yaml

Add this entry under mcp_servers. auth: oauth tells Hermes to handle discovery, dynamic client registration, PKCE and token refresh itself. If you edit the file from inside a running session, Hermes reloads its MCP connections with a 30 second timeout, which is too short for a browser sign-in, so finish the entry and then run the login in the next step.

File: `~/.hermes/config.yaml`

```yaml
mcp_servers:
  xspeedhub:
    url: "https://app.xspeedcache.com/xspeed/mcp"
    auth: oauth
```

### 3. Sign in with hermes mcp login

Run this once. Hermes prints an authorization URL, opens your browser where it can, and waits for the callback on a local loopback port. Sign in to xSpeed Hub and approve. There is no token to paste; Hermes caches the credentials it receives under ~/.hermes/mcp-tokens. On a remote host, paste the redirect URL back into the terminal when Hermes asks, or forward the callback port over SSH.

```bash
hermes mcp login xspeedhub
hermes mcp test xspeedhub
```

Full setup: https://xspeedcache.com/agent/hermes-agent/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. A Hermes server entry has a trust setting. The default, full, adds no approval prompt for that server's tools, and the approvals setting covers dangerous shell commands, not MCP tools. Set trust: untrusted on the xspeedhub entry and Hermes asks before every call to a tool that lacks a readOnlyHint of true. The Hub does not mark its tools that way, so with untrusted every Hub call asks, reads included. To remove writes instead of prompting, set tools.include on the entry to the read tools; the filter takes globs and include wins over exclude. The Hub itself has no confirmation step.

## Prompts

- Every night, use xSpeed Hub to benchmark all my sites and tell me about any whose cached time has gotten worse.
- With xSpeed Hub, run the benchmark on every site now and list the sites that failed to respond.
- Ask xSpeed Hub for the workspaces I can reach and how many sites each one has.

## Example session

```
You: Use xSpeed Hub to run tonight's benchmark on every site and send me the failures.
  → run_benchmark(site: all) [read-only]: 29 of 30 benchmarked; docs-eu unreachable
Agent: Twenty-nine sites measured, one failure. docs-eu did not respond. I changed nothing on any site, because the benchmark is a read.
You: Good. Leave the purge for me to do in the morning.
Agent: Understood. I will not run any write on a schedule.
```

## How it works

1. **See what you can reach**: list_sites returns each site's handle, URL, status and scopes. When you have more than one workspace, list_workspaces returns each one's handle, id, your role, its site count, which one is the default, and whether this connection can reach it.
2. **Choose the scope of the call**: The agent passes site: "all" for every site in one workspace, or an array of handles for exactly those sites. For a workspace other than the default it also passes the workspace argument. Omit workspace and the call acts on the default workspace.
3. **Confirm once**: Before a purge, toggle, settings change or preloader call that touches every site, the Hub tells the agent to say "this will touch all N sites" and wait for you, then make one call. That instruction does not name optimize_site, so for it your client's prompt is the gate. It is guidance to the agent, not a lock. It is one tool call, so one approval in your client covers every site in it.
4. **Run it as one call**: The Hub runs the sites one after another with a one-second pause between live calls, so a fleet purge is not a burst of traffic at your servers. Revoked sites are skipped from "all". Each site's action lands in the activity log as its own row.
5. **Read the result per site**: The reply is a summary of targets, succeeded and failed, plus one row per site with ok and either its data or its error. Some sites failing is a partial success. Only a run where every site failed comes back as an error.
6. **Follow up on the failures**: The agent reports which sites failed and why, then retries just those handles with an array. Tools that read one site, such as get_cache_status and get_health, do not fan out, so a fleet-wide check means one call per site.

## Reference

| | |
| --- | --- |
| Fan-out tools | purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader, optimize_site, run_benchmark |
| Selector | site: "all", or an array of handles |
| What all covers | Every site this connection can see in one workspace, minus revoked ones |
| Pacing | One after another, with a 1 second pause between live calls |
| Result | summary (targets, succeeded, failed) and a row per site: ok, then data or error |
| Partial failure | Reported per site; the call counts as an error only when every site failed |
| Workspace argument | Optional. Omit it for the default workspace; name one by its handle or id from list_workspaces |
| Reach | Fixed when you approve the connection; list_workspaces shows reachable: false for the rest |
| Not fan-out | get_health, get_cache_status and every other tool take one site per call |
| Slow tools | optimize_site takes up to 2 minutes per site; a target_score run is capped at 12 rounds per call |
| Read-only | The connection token with Read-only everywhere on, or a Viewer sign-in, refuses every fan-out write; run_benchmark works. An OAuth sign-in gets the scopes the client asks for |
| Hub daily pass | Re-verifies sites, snapshots cache status and hit ratio, reads stored reports, alerts by Slack webhook or email |

## Rules

- Confirm once, then call once. The Hub has no confirmation step of its own, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates that matter. The Hub's "this will touch all N sites" is an instruction to the agent for purge, toggle, settings and preloader calls, and it does not name optimize_site.
- "all" is one workspace, never every workspace. To act in another workspace, name it. A write to a non-default workspace must name it, and an array of handles is looked up only in the workspace the call names.
- Read every result per site. Treat some sites failing as a partial result, and never accept a blanket "done" from the agent.
- Try a behaviour change on one site before you send it to the fleet. toggle_cache and update_settings on every site are one call, and each site checks values against its own settings, so a Pro setting can fail on a Free site.
- optimize_site on many sites is slow, because each site can take up to two minutes inside one call. Use dry_run first, or name a short list of handles.
- The Hub has no scheduler for agent prompts. Its own daily pass and alerts run without an agent, and an agent can only act when you send a prompt or your AI client runs one on a timer.

## Good to know with Hermes Agent

A cron job that writes would run with nobody to confirm it. Hermes Agent can schedule prompts, but the Hub has no scheduler of its own and its instruction to confirm before a purge, toggle, settings change or preloader call on every site only helps when someone is reading. If you want a scheduled job to do more than read, give it its own connection with a scope you chose, and expect that a write runs as soon as the scope allows. Cron never opens a browser, so when the refresh token stops working the Hub server is parked until you sign in again from a terminal, and the next scheduled report fails until you do. Sort out which workspace the job targets, since all covers one only.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to list every site I can reach, and every workspace, and say which workspace you act in by default.
- With xSpeed Hub, purge the cache on every site in my workspace and tell me which ones failed.
- Use xSpeed Hub to run a benchmark on all my sites and rank them by cached response time.
- Use xSpeed Hub to start the preloader on blog, shop and docs only.
- With xSpeed Hub, turn page caching on for every site where it is off. Check each site first.
- Use xSpeed Hub to stop the preloader everywhere. The servers are busy.
- Ask xSpeed Hub to preview a safe optimize_site pass on every site with dry_run and summarize what it would change.
- Use xSpeed Hub to purge every site in the client-acme workspace, not my default one.

## Frequently asked questions

### How should I schedule fleet checks in Hermes Agent?

Schedule reads. run_benchmark accepts all, changes nothing and returns a result for each site, so a nightly run gives you a report. Leave purges and settings changes to runs where you are present, or filter the write tools out with a tools include list.

### Why does my fleet run take so long?

The Hub runs the sites one at a time with a one-second pause, so a call across thirty sites takes about thirty seconds. Space your scheduled runs so one finishes before the next begins.

### What does site "all" cover?

Every site the connection can see in one workspace. It never crosses workspaces, and revoked sites are skipped. If your connection is limited to some sites, "all" quietly means the sites you are allowed, with no error naming the rest. To act in another workspace, the agent names it with the workspace argument.

### What happens if one site fails?

The other sites still run. The reply has a summary and a row for each site with ok and its data or its error, so a site that was unreachable is named. A run counts as an error only when every site failed. Ask the agent to retry just the failed handles.

### Can the agent check the health of every site in one call?

No. get_health and get_cache_status take one site per call, so the agent loops. The tools that fan out are purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader, optimize_site and run_benchmark. The Hub dashboard has a fleet overview for health.

### Does the Hub watch my fleet when no agent is running?

Yes, on its own. A daily pass re-verifies each site, retrying a failed probe once, snapshots cache status and hit ratio, and reads the PageSpeed and GTmetrix reports your sites already stored. It can alert you by Slack webhook or email when a site becomes unreachable, caching is switched off, the hit ratio falls below a floor you set, or a score regresses. Each alert fires once per incident, not every day.

### Does the Hub ask before it touches every site?

The Hub has no confirmation step. Its instructions tell the agent to confirm once with you, saying how many sites a call will touch, but that is guidance and not a lock. Your AI client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are what stop a write. The instruction covers purge, toggle, settings and preloader calls, not optimize_site. The dashboard's own Purge all button does confirm before it runs.

### Can the agent add sites, remove sites or change who has access?

No. It cannot add, remove or rename sites, change members, roles or billing, mint or rotate tokens, or widen the workspaces this connection reaches. Those stay in the Hub dashboard.

## Manage every site at once with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/fleet/) · [Claude](https://xspeedcache.com/agent/claude/fleet/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/fleet/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/fleet/) · [Codex](https://xspeedcache.com/agent/codex/fleet/) · [Cursor](https://xspeedcache.com/agent/cursor/fleet/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/fleet/) · [Windsurf](https://xspeedcache.com/agent/windsurf/fleet/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/fleet/) · [Antigravity](https://xspeedcache.com/agent/antigravity/fleet/) · [Zed](https://xspeedcache.com/agent/zed/fleet/) · [Kiro](https://xspeedcache.com/agent/kiro/fleet/) · [OpenCode](https://xspeedcache.com/agent/opencode/fleet/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/fleet/) · [Grok Build](https://xspeedcache.com/agent/grok-build/fleet/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/fleet/) · [Grok](https://xspeedcache.com/agent/grok/fleet/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/fleet/) · [Muse](https://xspeedcache.com/agent/muse/fleet/) · [Manus](https://xspeedcache.com/agent/manus/fleet/) · [Kimi Code](https://xspeedcache.com/agent/kimi/fleet/) · [Paperclip](https://xspeedcache.com/agent/paperclip/fleet/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/fleet/)

## More with Hermes Agent

- [Purge the WordPress cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/purge-cache/)
- [Find out why WordPress pages are not cached with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/troubleshoot-cache/)
- [Scan a website for speed problems with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/speed-scan/)
- [Run and track PageSpeed tests with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/optimize-site/)
- [Tune WordPress cache settings with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cache-settings/)
- [Warm the WordPress cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/preload-cache/)
- [Set up the Redis object cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/object-cache/)
- [Manage Cloudflare caching with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/)

## Documentation

- Managing your fleet with xSpeed Hub: https://xspeedcache.com/docs/managing-your-fleet-with-xspeed-hub/
- Teams, roles and workspaces in xSpeed Hub: https://xspeedcache.com/docs/hub-teams-and-workspaces/
- Scoped AI connections in xSpeed Hub: https://xspeedcache.com/docs/hub-connection-scopes/
- Connecting to xSpeed Hub: https://xspeedcache.com/docs/connecting-to-xspeed-hub/
