# Kiro + xSpeed: Manage WordPress Caching

> Kiro is the agentic IDE from Amazon (AWS), and with xSpeed Hub added as an MCP server its chat panel can read cache status, purge, change settings and run speed tests on every WordPress site in your workspace. You add one entry to mcp.json, approve access in the browser, and ask in plain language.

Page: https://xspeedcache.com/agent/kiro/
Last updated: October 2026

- One mcp.json entry, one URL, every site you connected to the Hub
- autoApprove and permission rules work per tool, so reads can skip the prompt while writes keep it
- disabledTools hides the write tools from the agent entirely when you only want reporting

## How do I connect Kiro to xSpeed?

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to mcp.json

Open the command palette and run Kiro: Open user MCP config (JSON), then add this entry. The user file applies in every workspace. A project can carry its own .kiro/settings/mcp.json instead, but Kiro does not load a workspace's MCP config until you trust that workspace. Kiro reconnects servers when you save the file.

File: `~/.kiro/settings/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

### 3. Approve access in the browser

After you save, Kiro opens the xSpeed Hub authorization page. It registers itself through dynamic client registration, so there is no client ID to create. Sign in to the Hub, approve, and check the MCP servers tab in the Kiro panel for a connected xspeedhub. There is no token to paste; Kiro keeps the credentials it receives.

### 4. Or use a connection token (alternative)

If you prefer a header, copy the connection token from Connect AI in the Hub (only the workspace owner sees it) and export it as XSPEED_HUB_TOKEN. Kiro expands only environment variables you approve, so it shows a warning the first time and asks you to approve this one. Do not paste the token itself into a file you commit.

File: `~/.kiro/settings/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp",
      "headers": {
        "Authorization": "Bearer ${XSPEED_HUB_TOKEN}"
      }
    }
  }
}
```

**Authentication:** OAuth sign-in or connection token. Save the entry and approve access on the xSpeed Hub page Kiro opens; there is no token to paste, and Kiro keeps the credentials it receives. If you would rather use a header, put the connection token from the Hub's Connect AI page in an environment variable and reference it from headers.

**Check it worked:** ask "Use xSpeed Hub to list my sites and show the page cache status of each one."

## Does Kiro ask before it changes my site?

Kiro prompts before it runs an MCP tool unless a rule allows it. Rules live in two places: autoApprove in the server's mcp.json entry, which lists tool names, and mcp rules in permissions.yaml, such as a match of xspeedhub/get_* with effect allow. Allow the reads and keep purge_cache, update_settings, toggle_cache and the other write tools off both lists, because the Hub itself runs a write as soon as your connection allows it. Putting "*" in autoApprove skips the prompt for every Hub tool, writes included. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

## Example session

```
You: Using xSpeed Hub, which of my sites has page caching switched off?
  → list_sites [read-only]: 2 sites: shop and blog
  → get_cache_status(site: shop) [read-only]: page cache on, hit ratio 74% in the last 24h
  → get_cache_status(site: blog) [read-only]: page cache off, 0 cached pages
Agent: blog is the one with page caching off; shop is fine. Turn caching on for blog and warm it afterwards?
You: Yes, turn it on.
  → toggle_cache(site: blog, enabled: true) [changes site]: page cache enabled, cache drop-in installed
  → start_preloader(site: blog) [changes site]: preloader started, 180 URLs queued
Agent: Page caching is on for blog and the preloader is warming 180 URLs. shop already had it on, so I left it alone.
```

## What is Kiro?

Kiro is Amazon's agentic IDE. It plans work from specs, follows steering files you write for a project, and runs an agent in a chat panel that can edit code, run commands and call tools on MCP servers.

MCP, the Model Context Protocol, is how Kiro reaches services outside your machine. A remote server is one entry with a url in an mcp.json file. Adding xSpeed Hub that way gives the agent the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace.

## Why use Kiro with xSpeed?

- **Rules per tool**: autoApprove and permission rules name individual tools, so you can let the sixteen read tools run and keep each write on a prompt.
- **Hide what you do not need**: disabledTools keeps named tools away from the agent. List the write tools there and Kiro can report on your sites but never change one.
- **User or project scope**: Put the entry in your user mcp.json to have the Hub in every workspace, or in a project's .kiro/settings/mcp.json to share the setup with your team without sharing a token.

## Good to know

- A workspace-level mcp.json is ignored until you trust the workspace. If the Hub is missing in a new project, check trust first, or move the entry to your user file.
- With an Authorization header, Kiro only expands environment variables you have approved. A blocked variable shows a warning, and the connection fails until you approve it.
- If sign-in fails with an OAuth scope error, add "oauthScopes": [] to the xspeedhub entry, which is the fallback Kiro documents for scope errors.

## Prompts to try

- With xSpeed Hub, list my sites and flag any with a cache hit ratio under 60%.
- Use xSpeed Hub to run a benchmark on blog and tell me how much faster cached responses are than uncached ones.
- Ask xSpeed Hub for the current settings of the minify module on shop, but do not change anything.
- Use xSpeed Hub to preview what a safe optimize_site pass would change on docs. Do not apply it.
- Using xSpeed Hub, check the preloader status on shop and tell me how many URLs are still queued.

## What can Kiro do with xSpeed?

- [Purge the WordPress cache with Kiro](https://xspeedcache.com/agent/kiro/purge-cache/): Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
- [Find out why WordPress pages are not cached with Kiro](https://xspeedcache.com/agent/kiro/troubleshoot-cache/): Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
- [Scan a website for speed problems with Kiro](https://xspeedcache.com/agent/kiro/speed-scan/): Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
- [Run and track PageSpeed tests with Kiro](https://xspeedcache.com/agent/kiro/pagespeed-tests/): Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
- [Raise a WordPress site's PageSpeed score with Kiro](https://xspeedcache.com/agent/kiro/optimize-site/): Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
- [Tune WordPress cache settings with Kiro](https://xspeedcache.com/agent/kiro/cache-settings/): See which modules a site has, read their current settings, change them, and turn page caching on or off.
- [Warm the WordPress cache with Kiro](https://xspeedcache.com/agent/kiro/preload-cache/): Fill the page cache before visitors arrive, for example right after a purge or a deploy.
- [Set up the Redis object cache with Kiro](https://xspeedcache.com/agent/kiro/object-cache/): Connect a site to Redis or Memcached so database results survive between requests.
- [Manage Cloudflare caching with Kiro](https://xspeedcache.com/agent/kiro/cloudflare/): Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
- [Manage every WordPress site at once with Kiro](https://xspeedcache.com/agent/kiro/fleet/): Run one action across all of your sites, or a chosen few, and read the result site by site.

## Which way should I connect?

| Surface | Endpoint | Reaches | Auth | Tools |
| --- | --- | --- | --- | --- |
| [xSpeed Hub MCP](https://xspeedcache.com/docs/hub-mcp/) | `https://app.xspeedcache.com/xspeed/mcp` | Every site in your workspace, one connection | OAuth sign-in in the browser, or a connection token in an Authorization header | 29 tools (16 read, 13 write), seven of them can act on every site at once |
| [xSpeed Cache Site MCP](https://xspeedcache.com/docs/mcp-server/) | `https://your-site.com/xspeed/mcp` | One WordPress site | OAuth sign-in by a site admin, or the site's own token in an Authorization header | The full per-site tool set plus run_command for the WP-CLI surface |
| [xSpeed Scan MCP](https://xspeedcache.com/docs/scan-mcp/) | `https://xspeedcache.com/scan/mcp` | Any public URL, read-only | None. No account. | 5 tools: run_speed_scan, get_speed_scan and three product-info tools |
| [WP-CLI](https://xspeedcache.com/docs/wp-cli-commands/) | `wp xspeed …` | The site whose server the agent has a shell on | Your server login | Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more |

## Frequently asked questions

### How do I add xSpeed Hub to Kiro?

Run Kiro: Open user MCP config (JSON) from the command palette and add an xspeedhub entry under mcpServers with the url https://app.xspeedcache.com/xspeed/mcp. Save the file, approve access on the xSpeed Hub page Kiro opens, and check the MCP servers tab for a connected server.

### Do I need an API key?

No. Kiro signs in to the Hub with OAuth and keeps the credentials it receives. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page and reference it from headers through an environment variable.

### Will Kiro change my site without asking?

Kiro prompts before an MCP tool call unless a rule or autoApprove entry allows that tool. The Hub has no confirmation step of its own, so a write tool you auto-approve runs as soon as your connection allows writes. Auto-approve the reads, keep the writes on the prompt. For read-only access, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

### Which tools does Kiro get?

The 29 tools of the xSpeed Hub MCP server. Sixteen only read; thirteen change a site or spend the shared speed-test allowance. Use disabledTools in the entry if you want to hide some of them.

### Should I use the user file or the workspace file?

Use the user file, ~/.kiro/settings/mcp.json, to have the Hub in every workspace. A workspace file, .kiro/settings/mcp.json, applies to one project and is only loaded once you trust that workspace. If both define xspeedhub, the workspace entry wins.

### Can I use Kiro with one site and no Hub?

Yes. The xSpeed Cache plugin has its own MCP server at your-site.com/xspeed/mcp, switched on from xSpeed Cache, AI and agents, MCP in wp-admin. The Hub is the better fit once you have more than one site.

### How do I disconnect Kiro?

Set disabled to true on the xspeedhub entry or delete it from mcp.json. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in Kiro.

## Also works with

[Claude Code](https://xspeedcache.com/agent/claude-code/) · [Claude](https://xspeedcache.com/agent/claude/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/) · [Codex](https://xspeedcache.com/agent/codex/) · [Cursor](https://xspeedcache.com/agent/cursor/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/) · [Windsurf](https://xspeedcache.com/agent/windsurf/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/) · [Antigravity](https://xspeedcache.com/agent/antigravity/) · [Zed](https://xspeedcache.com/agent/zed/) · [OpenCode](https://xspeedcache.com/agent/opencode/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/) · [Grok Build](https://xspeedcache.com/agent/grok-build/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/) · [Grok](https://xspeedcache.com/agent/grok/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/) · [Muse](https://xspeedcache.com/agent/muse/) · [Manus](https://xspeedcache.com/agent/manus/) · [Kimi Code](https://xspeedcache.com/agent/kimi/) · [Paperclip](https://xspeedcache.com/agent/paperclip/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/)

## Sources

- Kiro docs: Model Context Protocol (MCP): https://kiro.dev/docs/mcp
- Kiro docs: MCP configuration: https://kiro.dev/docs/mcp/configuration
- Kiro docs: Permissions: https://kiro.dev/docs/permissions
