# Hermes Agent + xSpeed: Manage WordPress Caching

> Hermes Agent is the open-source, self-hosted agent from Nous Research, and with xSpeed Hub added as an MCP server it can read cache status, purge, change settings and run speed tests on every WordPress site in your workspace, from the terminal or from the chat apps its gateway serves. You add a few lines of YAML, sign in once, and ask in plain language.

Page: https://xspeedcache.com/agent/hermes-agent/
Last updated: October 2026

- One mcp_servers entry, one URL, every site you connected to the Hub
- A tools include list decides which Hub tools Hermes registers, so a reads-only list leaves every write out
- Hermes cron can run a report-only xSpeed check on a schedule and deliver it to Telegram, Slack or Discord

## How do I connect Hermes Agent to xSpeed?

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to config.yaml

Add this entry under mcp_servers. auth: oauth tells Hermes to handle discovery, dynamic client registration, PKCE and token refresh itself. If you edit the file from inside a running session, Hermes reloads its MCP connections with a 30 second timeout, which is too short for a browser sign-in, so finish the entry and then run the login in the next step.

File: `~/.hermes/config.yaml`

```yaml
mcp_servers:
  xspeedhub:
    url: "https://app.xspeedcache.com/xspeed/mcp"
    auth: oauth
```

### 3. Sign in with hermes mcp login

Run this once. Hermes prints an authorization URL, opens your browser where it can, and waits for the callback on a local loopback port. Sign in to xSpeed Hub and approve. There is no token to paste; Hermes caches the credentials it receives under ~/.hermes/mcp-tokens. On a remote host, paste the redirect URL back into the terminal when Hermes asks, or forward the callback port over SSH.

```bash
hermes mcp login xspeedhub
hermes mcp test xspeedhub
```

### 4. Or use a connection token (alternative)

If you prefer a header, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), add it to ~/.hermes/.env as XSPEED_HUB_TOKEN, and drop auth: oauth from the entry. Hermes resolves the variable when it connects.

File: `~/.hermes/config.yaml`

```yaml
mcp_servers:
  xspeedhub:
    url: "https://app.xspeedcache.com/xspeed/mcp"
    headers:
      Authorization: "Bearer ${XSPEED_HUB_TOKEN}"
```

**Authentication:** OAuth sign-in or connection token. Set auth: oauth, then run hermes mcp login xspeedhub and approve access in the browser; Hermes caches the credentials it receives and refreshes them. If you would rather use a header, put the connection token from the Hub's Connect AI page in ~/.hermes/.env and reference it from headers.

**Check it worked:** ask "Call xSpeed Hub and list my sites, with the hit ratio of each over the last day."

## Does Hermes Agent ask before it changes my site?

A Hermes server entry has a trust setting. The default, full, adds no approval prompt for that server's tools, and the approvals setting covers dangerous shell commands, not MCP tools. Set trust: untrusted on the xspeedhub entry and Hermes asks before every call to a tool that lacks a readOnlyHint of true. The Hub does not mark its tools that way, so with untrusted every Hub call asks, reads included. To remove writes instead of prompting, set tools.include on the entry to the read tools; the filter takes globs and include wins over exclude. The Hub itself has no confirmation step.

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

## Example session

```
You: Use xSpeed Hub to check shop's PageSpeed history, then run a fresh mobile test and compare the two.
  → get_score_history(site: shop) [read-only]: last stored mobile result 61, nine days ago
Agent: A new test spends some of the shared speed-test allowance and can take about two minutes. Run it on mobile?
You: Yes, run it.
  → run_speed_test(site: shop, strategy: mobile) [uses quota]: mobile 64, largest contentful paint 3.1 s
Agent: Mobile reads 64 now, against 61 nine days ago. Scores move between runs, so treat three points as a small change. I can run the benchmark too if you want the cached versus uncached timing.
```

## What is Hermes Agent?

Hermes Agent is an open-source, self-hosted AI agent built by Nous Research. It runs on your own machine or server, keeps memory across sessions, writes its own reusable skills, and can be reached from the command line and from messaging apps such as Telegram, Discord and Slack.

MCP, the Model Context Protocol, is how Hermes reaches services outside your machine. Servers are listed under mcp_servers in config.yaml, and a remote one takes a url. Adding xSpeed Hub that way gives Hermes the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace.

## Why use Hermes Agent with xSpeed?

- **Filters before the model**: tools.include and tools.exclude decide which Hub tools Hermes registers at all. List only reads and the agent has nothing to purge with.
- **A trust tier per server**: Mark the Hub untrusted and Hermes asks before each call. Leave it at the default and Hermes adds no prompt of its own, so choose on purpose.
- **Cron for routine checks**: Hermes cron runs a prompt on a schedule and delivers the answer to your messaging app, which suits a daily cache report.

## Good to know

- Hermes registers each tool as mcp_xspeedhub_ followed by the tool name, for example mcp_xspeedhub_purge_cache. Filters in config use the original tool names, such as purge_cache.
- Editing config.yaml from inside a running session starts an automatic MCP reload with a 30 second timeout. Add the entry first, then run hermes mcp login.
- Background runs, the gateway and cron never open a browser. When a refresh token stops working, the server is parked until you run hermes mcp login xspeedhub again.

## Prompts to try

- Use xSpeed Hub to show the cache hit ratio for every site and flag anything under 70%.
- With xSpeed Hub, purge the page cache on blog, then start the preloader and tell me how many URLs it queued.
- Use xSpeed Hub to run a desktop PageSpeed test on docs and compare it with the stored score history.
- Using xSpeed Hub, check whether Redis is reachable on shop before you turn on the object cache.
- Ask xSpeed Hub to list the modules on landing and tell me which ones are off, without changing any.

## Schedule a report-only cache check

Hermes has a cron scheduler. It lives in the gateway process, so the gateway has to be running. Each job starts a fresh session and delivers its answer to a target such as Telegram. The Hub has no scheduler for agent prompts, so the timer is Hermes's. A scheduled tick has nobody to answer a prompt. If a rule or the default trust setting pre-approves writes, a scheduled job can run them with no one watching, so keep scheduled jobs to reads unless you mean it, and consider a tools.include list of read tools on the entry. Through the cronjob tool, a job can also set enabled_toolsets to the Hub's toolset, mcp-xspeedhub, so it carries no shell or browser tools.

```bash
# Create the job
hermes cron create "0 8 * * *" \
  "Use the xspeedhub tools to read the cache status of every site. List any site with page caching off or a hit ratio under 70%. Only read: do not purge, toggle or change anything." \
  --name "xSpeed daily cache report" \
  --deliver telegram

# Check that the scheduler is alive
hermes cron status
```

## What can Hermes Agent do with xSpeed?

- [Purge the WordPress cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/purge-cache/): Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
- [Find out why WordPress pages are not cached with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/troubleshoot-cache/): Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
- [Scan a website for speed problems with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/speed-scan/): Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
- [Run and track PageSpeed tests with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/pagespeed-tests/): Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
- [Raise a WordPress site's PageSpeed score with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/optimize-site/): Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
- [Tune WordPress cache settings with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cache-settings/): See which modules a site has, read their current settings, change them, and turn page caching on or off.
- [Warm the WordPress cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/preload-cache/): Fill the page cache before visitors arrive, for example right after a purge or a deploy.
- [Set up the Redis object cache with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/object-cache/): Connect a site to Redis or Memcached so database results survive between requests.
- [Manage Cloudflare caching with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/): Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
- [Manage every WordPress site at once with Hermes Agent](https://xspeedcache.com/agent/hermes-agent/fleet/): Run one action across all of your sites, or a chosen few, and read the result site by site.

## Which way should I connect?

| Surface | Endpoint | Reaches | Auth | Tools |
| --- | --- | --- | --- | --- |
| [xSpeed Hub MCP](https://xspeedcache.com/docs/hub-mcp/) | `https://app.xspeedcache.com/xspeed/mcp` | Every site in your workspace, one connection | OAuth sign-in in the browser, or a connection token in an Authorization header | 29 tools (16 read, 13 write), seven of them can act on every site at once |
| [xSpeed Cache Site MCP](https://xspeedcache.com/docs/mcp-server/) | `https://your-site.com/xspeed/mcp` | One WordPress site | OAuth sign-in by a site admin, or the site's own token in an Authorization header | The full per-site tool set plus run_command for the WP-CLI surface |
| [xSpeed Scan MCP](https://xspeedcache.com/docs/scan-mcp/) | `https://xspeedcache.com/scan/mcp` | Any public URL, read-only | None. No account. | 5 tools: run_speed_scan, get_speed_scan and three product-info tools |
| [WP-CLI](https://xspeedcache.com/docs/wp-cli-commands/) | `wp xspeed …` | The site whose server the agent has a shell on | Your server login | Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more |

## Frequently asked questions

### How do I add xSpeed Hub to Hermes Agent?

Add an xspeedhub entry under mcp_servers in ~/.hermes/config.yaml with the url https://app.xspeedcache.com/xspeed/mcp and auth set to oauth, then run hermes mcp login xspeedhub and approve access in the browser. hermes mcp test xspeedhub shows what the server answers.

### Do I need an API key?

No. Hermes signs in to the Hub with OAuth and caches the credentials it receives. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page and reference it from headers through an environment variable in ~/.hermes/.env.

### Will Hermes Agent change my site without asking?

It can. The Hub has no confirmation step of its own, and Hermes adds no prompt for a server marked trust full, which is the default. Set trust to untrusted on the entry to make Hermes ask before Hub calls, filter the write tools out with tools include. For read-only access, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

### Can Hermes Agent run xSpeed jobs on a schedule?

Yes, through hermes cron. Create a job with a schedule and a prompt, and the gateway runs it in a fresh session and delivers the result to a messaging target. The Hub has no scheduler of its own. Nobody can answer a prompt during a scheduled run, so keep scheduled jobs to reads such as a daily hit-ratio report unless you intend them to write.

### Which tools does Hermes Agent get?

The 29 tools of the xSpeed Hub MCP server, registered with the prefix mcp_xspeedhub_. Sixteen only read; thirteen change a site or spend the shared speed-test allowance. A tools include or exclude list on the entry narrows them.

### Can I use Hermes Agent with one site and no Hub?

Yes. The xSpeed Cache plugin has its own MCP server at your-site.com/xspeed/mcp, switched on from xSpeed Cache, AI and agents, MCP in wp-admin. The Hub is the better fit once you have more than one site.

### How do I disconnect Hermes Agent?

Set enabled to false on the xspeedhub entry or remove it from config.yaml. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in Hermes Agent.

## Also works with

[Claude Code](https://xspeedcache.com/agent/claude-code/) · [Claude](https://xspeedcache.com/agent/claude/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/) · [Codex](https://xspeedcache.com/agent/codex/) · [Cursor](https://xspeedcache.com/agent/cursor/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/) · [Windsurf](https://xspeedcache.com/agent/windsurf/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/) · [Antigravity](https://xspeedcache.com/agent/antigravity/) · [Zed](https://xspeedcache.com/agent/zed/) · [Kiro](https://xspeedcache.com/agent/kiro/) · [OpenCode](https://xspeedcache.com/agent/opencode/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/) · [Grok Build](https://xspeedcache.com/agent/grok-build/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/) · [Grok](https://xspeedcache.com/agent/grok/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/) · [Muse](https://xspeedcache.com/agent/muse/) · [Manus](https://xspeedcache.com/agent/manus/) · [Kimi Code](https://xspeedcache.com/agent/kimi/) · [Paperclip](https://xspeedcache.com/agent/paperclip/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/)

## Sources

- Hermes Agent docs: MCP: https://hermes-agent.nousresearch.com/docs/user-guide/features/mcp
- Hermes Agent docs: MCP config reference: https://hermes-agent.nousresearch.com/docs/reference/mcp-config-reference
- Hermes Agent docs: Scheduled tasks (cron): https://hermes-agent.nousresearch.com/docs/user-guide/features/cron
- Hermes Agent docs: Security: https://hermes-agent.nousresearch.com/docs/user-guide/security
- Hermes Agent docs: OAuth over SSH: https://hermes-agent.nousresearch.com/docs/guides/oauth-over-ssh
