xSpeed Cache is officially live! Get 50% OFF during Launch Week — Lifetime starts at just $79Lifetime from $79 — 50% OFF, Launch Week! See Plans →

See Plans →
Features
xSpeed Hub Pricing Docs Blog Scan
Appearance
Get Plugin

Amazon (AWS)

Editor

Kiro + xSpeed

Kiro is the agentic IDE from Amazon (AWS), and with xSpeed Hub added as an MCP server its chat panel can read cache status, purge, change settings and run speed tests on every WordPress site in your workspace. You add one entry to mcp.json, approve access in the browser, and ask in plain language.

  • One mcp.json entry, one URL, every site you connected to the Hub
  • autoApprove and permission rules work per tool, so reads can skip the prompt while writes keep it
  • disabledTools hides the write tools from the agent entirely when you only want reporting

Last updated: October 2026

Kiro Editor
xSpeed Hub 29 tools
  • shop
  • blog
  • docs
Connects with an mcp.json entry with a url, then a browser sign-in. Sign-in: OAuth sign-in or connection token.
01

How do I connect Kiro to xSpeed?

Put your sites in xSpeed Hub once, then add one URL to Kiro.

1Connect4 steps

1Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

2Add xSpeed Hub to mcp.json

Open the command palette and run Kiro: Open user MCP config (JSON), then add this entry. The user file applies in every workspace. A project can carry its own .kiro/settings/mcp.json instead, but Kiro does not load a workspace's MCP config until you trust that workspace. Kiro reconnects servers when you save the file.

~/.kiro/settings/mcp.json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}

3Approve access in the browser

After you save, Kiro opens the xSpeed Hub authorization page. It registers itself through dynamic client registration, so there is no client ID to create. Sign in to the Hub, approve, and check the MCP servers tab in the Kiro panel for a connected xspeedhub. There is no token to paste; Kiro keeps the credentials it receives.

4Or use a connection token alternative

If you prefer a header, copy the connection token from Connect AI in the Hub (only the workspace owner sees it) and export it as XSPEED_HUB_TOKEN. Kiro expands only environment variables you approve, so it shows a warning the first time and asks you to approve this one. Do not paste the token itself into a file you commit.

~/.kiro/settings/mcp.json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp",
      "headers": {
        "Authorization": "Bearer ${XSPEED_HUB_TOKEN}"
      }
    }
  }
}
1 / 4
Sign-in OAuth sign-in or connection token

Save the entry and approve access on the xSpeed Hub page Kiro opens; there is no token to paste, and Kiro keeps the credentials it receives. If you would rather use a header, put the connection token from the Hub's Connect AI page in an environment variable and reference it from headers.

2Askexample session
Check it worked

Use xSpeed Hub to list my sites and show the page cache status of each one.

Example session · Kiro

You: Using xSpeed Hub, which of my sites has page caching switched off?

list_sites read-only
→ 2 sites: shop and blog

get_cache_status(site: shop) read-only
→ page cache on, hit ratio 74% in the last 24h

get_cache_status(site: blog) read-only
→ page cache off, 0 cached pages

Kiro: blog is the one with page caching off; shop is fine. Turn caching on for blog and warm it afterwards?

You: Yes, turn it on.

toggle_cache(site: blog, enabled: true) changes site
→ page cache enabled, cache drop-in installed

start_preloader(site: blog) changes site
→ preloader started, 180 URLs queued

Kiro: Page caching is on for blog and the preloader is warming 180 URLs. shop already had it on, so I left it alone.

Using it

02

Prompts to try in Kiro

Paste one as it is, or change the site name.

Prompt
With xSpeed Hub, list my sites and flag any with a cache hit ratio under 60%.
Prompt
Use xSpeed Hub to run a benchmark on blog and tell me how much faster cached responses are than uncached ones.
Prompt
Ask xSpeed Hub for the current settings of the minify module on shop, but do not change anything.
Prompt
Use xSpeed Hub to preview what a safe optimize_site pass would change on docs. Do not apply it.
Prompt
Using xSpeed Hub, check the preloader status on shop and tell me how many URLs are still queued.
03

What can Kiro do with xSpeed?

A guide for each job, written for Kiro.

Trust and safety

04

Does Kiro ask before it changes my site?

Kiro

Kiro prompts before it runs an MCP tool unless a rule allows it. Rules live in two places: autoApprove in the server's mcp.json entry, which lists tool names, and mcp rules in permissions.yaml, such as a match of xspeedhub/get_* with effect allow. Allow the reads and keep purge_cache, update_settings, toggle_cache and the other write tools off both lists, because the Hub itself runs a write as soon as your connection allows it. Putting "*" in autoApprove skips the prompt for every Hub tool, writes included. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.

xSpeed Hub

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

Good to know

  • A workspace-level mcp.json is ignored until you trust the workspace. If the Hub is missing in a new project, check trust first, or move the entry to your user file.
  • With an Authorization header, Kiro only expands environment variables you have approved. A blocked variable shows a warning, and the connection fails until you approve it.
  • If sign-in fails with an OAuth scope error, add "oauthScopes": [] to the xspeedhub entry, which is the fallback Kiro documents for scope errors.

Reference

05

What is Kiro?

Kiro is Amazon's agentic IDE. It plans work from specs, follows steering files you write for a project, and runs an agent in a chat panel that can edit code, run commands and call tools on MCP servers.

MCP, the Model Context Protocol, is how Kiro reaches services outside your machine. A remote server is one entry with a url in an mcp.json file. Adding xSpeed Hub that way gives the agent the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace.

At a glance

Made by
Amazon (AWS)
Type
Editor
Connects with
an mcp.json entry with a url, then a browser sign-in
Sign-in
OAuth sign-in or connection token
Last checked
October 2026
06

Why use Kiro with xSpeed?

Rules per tool

autoApprove and permission rules name individual tools, so you can let the sixteen read tools run and keep each write on a prompt.

Hide what you do not need

disabledTools keeps named tools away from the agent. List the write tools there and Kiro can report on your sites but never change one.

User or project scope

Put the entry in your user mcp.json to have the Hub in every workspace, or in a project's .kiro/settings/mcp.json to share the setup with your team without sharing a token.

07

How does Kiro compare with other AI clients?

Every client below reaches the same 29 Hub tools once connected. What differs is where it runs, how you add the server and how it signs in.

ClientMade byTypeHow you connect itSign-in
Kiro Amazon (AWS) Editor an mcp.json entry with a url, then a browser sign-in OAuth sign-in or connection token
Cursor Anysphere Editor mcp.json with a url, then OAuth OAuth sign-in or connection token
GitHub Copilot in VS Code GitHub / Microsoft Editor mcp.json in your VS Code user profile, or MCP: Add Server OAuth sign-in or connection token
Windsurf Cognition Editor devin mcp add, then devin mcp login (Cascade: mcp_config.json) OAuth sign-in or connection token
Zed Zed Industries Editor context_servers in settings.json, or Settings, AI, MCP Servers OAuth sign-in or connection token
08

Which way should I connect?

Kiro can use the Hub, one site's own MCP server, or the no-account Scan MCP. The Hub is the one most people want.

xSpeed Hub MCPMost people

https://app.xspeedcache.com/xspeed/mcp
Best for
Most people. One URL in your AI client, every site behind it.
Reaches
Every site in your workspace, one connection
Sign-in
OAuth sign-in in the browser, or a connection token in an Authorization header
Tools
29 tools (16 read, 13 write), seven of them can act on every site at once
Read the guide →

xSpeed Cache Site MCP

https://your-site.com/xspeed/mcp
Best for
A single site, or work the Hub does not expose, such as database cleanup.
Reaches
One WordPress site
Sign-in
OAuth sign-in by a site admin, or the site's own token in an Authorization header
Tools
The full per-site tool set plus run_command for the WP-CLI surface
Read the guide →

xSpeed Scan MCP

https://xspeedcache.com/scan/mcp
Best for
Grading a site you do not run, or trying xSpeed before you install anything.
Reaches
Any public URL, read-only
Sign-in
None. No account.
Tools
5 tools: run_speed_scan, get_speed_scan and three product-info tools
Read the guide →

WP-CLI

wp xspeed …
Best for
Agents that already run commands on the server, such as Claude Code or Codex over SSH.
Reaches
The site whose server the agent has a shell on
Sign-in
Your server login
Tools
Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more
Read the guide →
09

Frequently asked questions

Run Kiro: Open user MCP config (JSON) from the command palette and add an xspeedhub entry under mcpServers with the url https://app.xspeedcache.com/xspeed/mcp. Save the file, approve access on the xSpeed Hub page Kiro opens, and check the MCP servers tab for a connected server.

No. Kiro signs in to the Hub with OAuth and keeps the credentials it receives. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page and reference it from headers through an environment variable.

Kiro prompts before an MCP tool call unless a rule or autoApprove entry allows that tool. The Hub has no confirmation step of its own, so a write tool you auto-approve runs as soon as your connection allows writes. Auto-approve the reads, keep the writes on the prompt. For read-only access, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

The 29 tools of the xSpeed Hub MCP server. Sixteen only read; thirteen change a site or spend the shared speed-test allowance. Use disabledTools in the entry if you want to hide some of them.

Use the user file, ~/.kiro/settings/mcp.json, to have the Hub in every workspace. A workspace file, .kiro/settings/mcp.json, applies to one project and is only loaded once you trust that workspace. If both define xspeedhub, the workspace entry wins.

Yes. The xSpeed Cache plugin has its own MCP server at your-site.com/xspeed/mcp, switched on from xSpeed Cache, AI and agents, MCP in wp-admin. The Hub is the better fit once you have more than one site.

Set disabled to true on the xspeedhub entry or delete it from mcp.json. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in Kiro.

10

Also works with

Sources checked (3)

Connect Kiro to every site at once.

xSpeed Hub is free and has no site cap. Connect your sites, add one URL, and ask.