xSpeed Cache is officially live! Get 50% OFF during Launch Week — Lifetime starts at just $79Lifetime from $79 — 50% OFF, Launch Week! See Plans →

See Plans →
Features
xSpeed Hub Pricing Docs Blog Scan
Appearance
Get Plugin

Tune WordPress cache settings with Kiro

Tuning cache settings with Kiro means asking it, in the editor, to check whether xSpeed page caching is on for a WordPress site and to turn it on or change a setting through xSpeed Hub after you approve it.

list_sitesget_cache_statuslist_modulesget_settingsupdate_settingstoggle_cacherun_benchmark

Last updated: October 2026

Example session · Kiro

You: The landing page I am building on staging feels slow. Use xSpeed Hub to check whether caching is on.

get_cache_status(site: staging) read-only
→ page cache off, 0 cached pages

Kiro: Page caching is off on staging, so every request builds the page fresh. I would turn it on with toggle_cache and leave every other setting alone. Turn it on?

You: Yes, turn it on.

toggle_cache(site: staging, enabled: true) changes site
→ page cache turned on

Kiro: Caching is on. The first visit to each page builds it, and later visits are served from the stored copy.

01

How Kiro handles this

You are in Kiro, partway through a spec for a new landing page, and you notice the site you are testing it on feels slow. You ask the agent whether page caching is on there. It calls list_sites to match the site, then get_cache_status, and finds that caching is off, which would explain the slow response. It then reads list_modules to see what else is enabled so it can say what turning caching on would affect, rather than only flipping the switch.

What comes back is a finding and a proposal: page caching is off on that site, and the agent would call toggle_cache to turn it on. The Hub tells the agent to briefly confirm intent before toggle_cache and update_settings, so Kiro states the change and asks. After your yes it calls toggle_cache and reports the new state. Caching itself is never set through update_settings, which refuses that key. For finer changes, such as the cache expiry, it uses get_settings and update_settings the same way. If any key or value is wrong, the whole call is refused and nothing is stored, Pro-only settings are refused without a licence, and credential fields are refused over the Hub.

What differs in Kiro is the approval list. Kiro prompts for a tool unless a rule allows it, either in the server's autoApprove list or in an mcp rule such as xspeedhub/get_* with effect allow. Put the read tools there, such as list_modules, get_settings and get_cache_status, and leave toggle_cache and update_settings out so they prompt. The Hub itself runs a write as soon as the connection allows it, which makes those rules the setting that matters.

02

Set up Kiro once

Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Kiro guide.

1Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

2Add xSpeed Hub to mcp.json

Open the command palette and run Kiro: Open user MCP config (JSON), then add this entry. The user file applies in every workspace. A project can carry its own .kiro/settings/mcp.json instead, but Kiro does not load a workspace's MCP config until you trust that workspace. Kiro reconnects servers when you save the file.

~/.kiro/settings/mcp.json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}

3Approve access in the browser

After you save, Kiro opens the xSpeed Hub authorization page. It registers itself through dynamic client registration, so there is no client ID to create. Sign in to the Hub, approve, and check the MCP servers tab in the Kiro panel for a connected xspeedhub. There is no token to paste; Kiro keeps the credentials it receives.

1 / 3

Full Kiro setup, sign-in options and FAQ

Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Kiro prompts before it runs an MCP tool unless a rule allows it. Rules live in two places: autoApprove in the server's mcp.json entry, which lists tool names, and mcp rules in permissions.yaml, such as a match of xspeedhub/get_* with effect allow. Allow the reads and keep purge_cache, update_settings, toggle_cache and the other write tools off both lists, because the Hub itself runs a write as soon as your connection allows it. Putting "*" in autoApprove skips the prompt for every Hub tool, writes included. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.

03

What do I ask?

Three prompts written for Kiro. More for this job are below.

Prompt for Kiro
Using xSpeed Hub, is page caching on for staging? If it is off, tell me what turning it on will change before you do it.
Prompt for Kiro
Use xSpeed Hub to turn page caching on for staging and confirm the new state with get_cache_status.
Prompt for Kiro
Ask xSpeed Hub for the cache settings on staging and tell me whether the expiry suits a site that changes weekly.
04

What happens, step by step

Every xSpeed feature is a module with its own settings. Through xSpeed Hub an agent can list the modules a site has, read one module's settings, change them with a checked update, and turn page caching on or off. The site validates every write against the module's own schema, so a wrong key or value is refused with a reason instead of being quietly ignored.

01

List the modules

list_modules returns every Free and Pro module available on one site, with its settings schema and status. It tells the agent which module slugs exist, such as minify or gzip, and what each setting accepts.

02

Read the current settings

get_settings takes a module slug and returns its settings. Credential fields come back masked, so an agent cannot read a stored API token or password back in plain text.

03

Change them

update_settings takes the module and a values object of setting keys. The site checks the whole object first. If any key is unknown, any value is outside the schema, or a field is pinned by a constant in wp-config.php, it refuses the write, writes nothing and says which keys and why, sometimes with a "did you mean" hint.

04

Turn page caching on or off

Page caching has its own tool, toggle_cache, because it installs or removes the cache drop-in and the WP_CACHE constant. Asking update_settings to set cache_enabled does not work and is refused. If another caching plugin owns the drop-in, the site declines to enable xSpeed and returns blocked: true with the reason.

05

Check the effect

The result of a settings write is the stored settings. A module can add a warning when a setting is saved but has no effect on this server, for example Brotli on a server without the module for it, and the agent should pass that on. run_benchmark then times cached against uncached to see whether the change helped.

06

Apply to many sites only after reading one

update_settings and toggle_cache accept site: "all" or a list of handles. Each site validates against its own schema and answers in its own row, so a module missing on one site fails that row and the others still apply. Read one site first, then apply.

05

Reference

Discoverlist_modules (read): Free and Pro modules, settings schema, status, per site
Read settingsget_settings (read): argument module; credential fields masked
Change settingsupdate_settings (write): arguments module and values; validated by the site
Bad inputThe whole write is refused and nothing is written; the error names the keys and reasons
Page cache on or offtoggle_cache (write): argument enabled; cache_enabled in update_settings is refused
Blocked by another plugintoggle_cache returns blocked: true with blocked_reason when another plugin owns the cache drop-in
Every site at onceupdate_settings and toggle_cache accept site: "all" or a list of handles, one result per site
Pro modulesA Pro module on a site without an active licence cannot be read or written; the site refuses
Credential fieldsRefused by default over MCP; set them in the xSpeed dashboard, not through the agent
Read-only connectionThe connection token with Read-only everywhere on, or a Viewer member's sign-in: update_settings and toggle_cache are refused; list_modules and get_settings still work. An OAuth sign-in gets the scopes the client asks for, read and write by default, clamped to the member's role
ConfirmationNone on the Hub; the Hub tells the agent to briefly confirm intent for these two, and your client's prompt is the gate
06

Rules worth keeping

  • Read before you write. Ask for list_modules and get_settings first, so the agent changes real keys with valid values instead of guessing.
  • update_settings and toggle_cache change how a live site behaves. They run as soon as your connection allows writes. The Hub tells the agent to briefly confirm intent first, which is guidance to the agent, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates. The switch does not limit an OAuth sign-in.
  • For site: "all", the Hub tells the agent to confirm once with "this will touch all N sites", then make one call. The result is per site, and some sites failing is a partial result to report, not a blanket success or failure.
  • Do not ask an agent to set credentials such as a Cloudflare token or Redis password. The site refuses those writes by default, and they belong in the xSpeed dashboard.
  • If a settings result says a value is saved but inactive on this server, relay that. Do not tell the user the feature is enabled.

Good to know with Kiro

Kiro prompts for any tool that no rule allows, so your autoApprove list and allow rules decide how much runs unattended. Keep them to reads, and do not put an asterisk in autoApprove, which skips the prompt for every Hub tool. If toggle_cache or update_settings is on the list, a model that decides to turn caching off on a live site does it without a prompt, and the Hub's request to confirm is the only brake left. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.

07

More prompts for this job

They work in any client connected to xSpeed Hub.

Prompt
Use xSpeed Hub to list the modules on shop and tell me which ones are off.
Prompt
Ask xSpeed Hub for the current minify settings on blog.
Prompt
With xSpeed Hub, turn on HTML minification on blog, then benchmark the cache and tell me if it helped.
Prompt
Use xSpeed Hub to turn page caching off on staging while I debug, and tell me when it is off.
Prompt
Using xSpeed Hub, read the gzip settings on shop first, then enable the same options on every site.
Prompt
Use xSpeed Hub to set the page cache lifespan on docs to 30 days, and if the site refuses it, tell me why.
08

Frequently asked questions

The read tools that change nothing, such as list_modules, get_settings and get_cache_status. Leave toggle_cache and update_settings out so Kiro prompts before each. The Hub runs a write as soon as your connection allows it, so the prompt is the check you keep.

The most common reason is another caching plugin that already owns the cache drop-in on that site. toggle_cache then refuses to enable xSpeed and returns blocked: true with the reason. Kiro should tell you that, and the fix is to remove or switch off the other plugin yourself, because xSpeed does not change another plugin.

It calls list_modules for the site, which returns every available module with its settings schema and status, then get_settings for the one module it wants to change. The schema says which keys exist and what values each accepts.

The site refuses the whole update and writes nothing. The error names the keys it rejected and why, such as an unknown key, a value outside the allowed range, or a field fixed by a constant in wp-config.php, and it can suggest the nearest valid key.

Use toggle_cache with enabled set to true or false. It installs or removes the cache drop-in and the WP_CACHE constant. Setting cache_enabled through update_settings does not work. If another caching plugin already owns the drop-in, the site will not enable xSpeed and says why.

Yes. update_settings and toggle_cache accept site: "all", and the Hub runs the sites one after another with a one-second pause and returns a result per site. Each site checks the values against its own schema, so a site that lacks the module fails its own row while the others apply.

Not by default. Writing credential fields over MCP is off unless the site owner allows it, and the site refuses the write and names the fields. Set credentials in the xSpeed dashboard. Credential values also come back masked when an agent reads settings.

09

Keep going

Tune cache settings with other agents

More with Kiro

Documentation

From the blog

Tune cache settings, from Kiro.

xSpeed Hub is free and has no site cap. Connect your sites once and ask from the agent you already use.