How do I connect Kiro to xSpeed?
Put your sites in xSpeed Hub once, then add one URL to Kiro.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub to mcp.json
Open the command palette and run Kiro: Open user MCP config (JSON), then add this entry. The user file applies in every workspace. A project can carry its own .kiro/settings/mcp.json instead, but Kiro does not load a workspace's MCP config until you trust that workspace. Kiro reconnects servers when you save the file.
{
"mcpServers": {
"xspeedhub": {
"url": "https://app.xspeedcache.com/xspeed/mcp"
}
}
} 3Approve access in the browser
After you save, Kiro opens the xSpeed Hub authorization page. It registers itself through dynamic client registration, so there is no client ID to create. Sign in to the Hub, approve, and check the MCP servers tab in the Kiro panel for a connected xspeedhub. There is no token to paste; Kiro keeps the credentials it receives.
4Or use a connection token alternative
If you prefer a header, copy the connection token from Connect AI in the Hub (only the workspace owner sees it) and export it as XSPEED_HUB_TOKEN. Kiro expands only environment variables you approve, so it shows a warning the first time and asks you to approve this one. Do not paste the token itself into a file you commit.
{
"mcpServers": {
"xspeedhub": {
"url": "https://app.xspeedcache.com/xspeed/mcp",
"headers": {
"Authorization": "Bearer ${XSPEED_HUB_TOKEN}"
}
}
}
} Use xSpeed Hub to list my sites and show the page cache status of each one.
You: Using xSpeed Hub, which of my sites has page caching switched off?
list_sites read-only
→ 2 sites: shop and blog
get_cache_status(site: shop) read-only
→ page cache on, hit ratio 74% in the last 24h
get_cache_status(site: blog) read-only
→ page cache off, 0 cached pages
Kiro: blog is the one with page caching off; shop is fine. Turn caching on for blog and warm it afterwards?
You: Yes, turn it on.
toggle_cache(site: blog, enabled: true) changes site
→ page cache enabled, cache drop-in installed
start_preloader(site: blog) changes site
→ preloader started, 180 URLs queued
Kiro: Page caching is on for blog and the preloader is warming 180 URLs. shop already had it on, so I left it alone.
Using it
Prompts to try in Kiro
Paste one as it is, or change the site name.
With xSpeed Hub, list my sites and flag any with a cache hit ratio under 60%.
Use xSpeed Hub to run a benchmark on blog and tell me how much faster cached responses are than uncached ones.
Ask xSpeed Hub for the current settings of the minify module on shop, but do not change anything.
Use xSpeed Hub to preview what a safe optimize_site pass would change on docs. Do not apply it.
Using xSpeed Hub, check the preloader status on shop and tell me how many URLs are still queued.
What can Kiro do with xSpeed?
A guide for each job, written for Kiro.
Purge the WordPress cache with Kiro
Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
Find out why WordPress pages are not cached with Kiro
Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
Scan a website for speed problems with Kiro
Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
Run and track PageSpeed tests with Kiro
Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
Raise a WordPress site's PageSpeed score with Kiro
Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
Tune WordPress cache settings with Kiro
See which modules a site has, read their current settings, change them, and turn page caching on or off.
Warm the WordPress cache with Kiro
Fill the page cache before visitors arrive, for example right after a purge or a deploy.
Set up the Redis object cache with Kiro
Connect a site to Redis or Memcached so database results survive between requests.
Manage Cloudflare caching with Kiro
Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
Manage every WordPress site at once with Kiro
Run one action across all of your sites, or a chosen few, and read the result site by site.
Trust and safety
Does Kiro ask before it changes my site?
Kiro prompts before it runs an MCP tool unless a rule allows it. Rules live in two places: autoApprove in the server's mcp.json entry, which lists tool names, and mcp rules in permissions.yaml, such as a match of xspeedhub/get_* with effect allow. Allow the reads and keep purge_cache, update_settings, toggle_cache and the other write tools off both lists, because the Hub itself runs a write as soon as your connection allows it. Putting "*" in autoApprove skips the prompt for every Hub tool, writes included. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.
xSpeed Hub
xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.
Good to know
- A workspace-level mcp.json is ignored until you trust the workspace. If the Hub is missing in a new project, check trust first, or move the entry to your user file.
- With an Authorization header, Kiro only expands environment variables you have approved. A blocked variable shows a warning, and the connection fails until you approve it.
- If sign-in fails with an OAuth scope error, add "oauthScopes": [] to the xspeedhub entry, which is the fallback Kiro documents for scope errors.
Reference
What is Kiro?
Kiro is Amazon's agentic IDE. It plans work from specs, follows steering files you write for a project, and runs an agent in a chat panel that can edit code, run commands and call tools on MCP servers.
MCP, the Model Context Protocol, is how Kiro reaches services outside your machine. A remote server is one entry with a url in an mcp.json file. Adding xSpeed Hub that way gives the agent the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace.
At a glance
- Made by
- Amazon (AWS)
- Type
- Editor
- Connects with
- an mcp.json entry with a url, then a browser sign-in
- Sign-in
- OAuth sign-in or connection token
- Last checked
- October 2026
Why use Kiro with xSpeed?
Rules per tool
autoApprove and permission rules name individual tools, so you can let the sixteen read tools run and keep each write on a prompt.
Hide what you do not need
disabledTools keeps named tools away from the agent. List the write tools there and Kiro can report on your sites but never change one.
User or project scope
Put the entry in your user mcp.json to have the Hub in every workspace, or in a project's .kiro/settings/mcp.json to share the setup with your team without sharing a token.
How does Kiro compare with other AI clients?
Every client below reaches the same 29 Hub tools once connected. What differs is where it runs, how you add the server and how it signs in.
| Client | Made by | Type | How you connect it | Sign-in |
|---|---|---|---|---|
| Kiro | Amazon (AWS) | Editor | an mcp.json entry with a url, then a browser sign-in | OAuth sign-in or connection token |
| Cursor | Anysphere | Editor | mcp.json with a url, then OAuth | OAuth sign-in or connection token |
| GitHub Copilot in VS Code | GitHub / Microsoft | Editor | mcp.json in your VS Code user profile, or MCP: Add Server | OAuth sign-in or connection token |
| Windsurf | Cognition | Editor | devin mcp add, then devin mcp login (Cascade: mcp_config.json) | OAuth sign-in or connection token |
| Zed | Zed Industries | Editor | context_servers in settings.json, or Settings, AI, MCP Servers | OAuth sign-in or connection token |
Which way should I connect?
Kiro can use the Hub, one site's own MCP server, or the no-account Scan MCP. The Hub is the one most people want.
xSpeed Hub MCPMost people
https://app.xspeedcache.com/xspeed/mcp - Best for
- Most people. One URL in your AI client, every site behind it.
- Reaches
- Every site in your workspace, one connection
- Sign-in
- OAuth sign-in in the browser, or a connection token in an Authorization header
- Tools
- 29 tools (16 read, 13 write), seven of them can act on every site at once
xSpeed Cache Site MCP
https://your-site.com/xspeed/mcp - Best for
- A single site, or work the Hub does not expose, such as database cleanup.
- Reaches
- One WordPress site
- Sign-in
- OAuth sign-in by a site admin, or the site's own token in an Authorization header
- Tools
- The full per-site tool set plus run_command for the WP-CLI surface
xSpeed Scan MCP
https://xspeedcache.com/scan/mcp - Best for
- Grading a site you do not run, or trying xSpeed before you install anything.
- Reaches
- Any public URL, read-only
- Sign-in
- None. No account.
- Tools
- 5 tools: run_speed_scan, get_speed_scan and three product-info tools
WP-CLI
wp xspeed … - Best for
- Agents that already run commands on the server, such as Claude Code or Codex over SSH.
- Reaches
- The site whose server the agent has a shell on
- Sign-in
- Your server login
- Tools
- Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more
Frequently asked questions
Also works with
Documentation
From the blog
- How to Let Claude or ChatGPT Manage Your WordPress Site Speed (via MCP)
- Connecting Claude to a WordPress Fleet in 2026: One of These Five Routes You May Already Be Paying For
- xSpeed Cache MCP vs WP Rocket MCP in 2026: One Connects Once, the Other Once Per Site
- 10 Best WordPress MCP Servers in 2026: 486 in the Directory, Four With More Than Ten Reviews