# Raise a WordPress site's PageSpeed score with Kiro

> Raising a WordPress PageSpeed score with Kiro means asking its agent to preview and then apply an xSpeed optimization pass through xSpeed Hub, approving the tool calls that change the site.

Page: https://xspeedcache.com/agent/kiro/optimize-site/
Last updated: October 2026

In Kiro you ask for the result in the chat: raise the score on the booking site, preview what xSpeed would change. Kiro prompts before it runs an MCP tool unless an autoApprove entry or a permission rule allows it, so the first prompts you see are for list_sites and then optimize_site with dry_run on. The preview comes back as a plan: the settings xSpeed would turn on, in order, at the level it chose. The site is unchanged.

Check the plan against what you know about the site. A booking site, for example, has forms and calendars that do not like aggressive script changes, so you may want the safe level. When you are ready, tell Kiro to apply it. xSpeed measures the site, applies each setting one at a time, checks the page after every change, and undoes anything that breaks it, which takes up to two minutes per site. The reply lists applied, undone with the reason, and unfixable.

Treat that unfixable list as honest information, not a failure. Caching cannot reduce page weight, fix images hotlinked from another domain, or shrink the page structure, and xSpeed says so rather than promising a score. A site that is already tuned answers that everything is already on. Finally, the Hub gives Kiro a list of verify_urls and tells it to look at the pages before it says the pass worked. The plugin cannot run JavaScript, so open those pages in a browser with the console visible.

## Set up Kiro once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to mcp.json

Open the command palette and run Kiro: Open user MCP config (JSON), then add this entry. The user file applies in every workspace. A project can carry its own .kiro/settings/mcp.json instead, but Kiro does not load a workspace's MCP config until you trust that workspace. Kiro reconnects servers when you save the file.

File: `~/.kiro/settings/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

### 3. Approve access in the browser

After you save, Kiro opens the xSpeed Hub authorization page. It registers itself through dynamic client registration, so there is no client ID to create. Sign in to the Hub, approve, and check the MCP servers tab in the Kiro panel for a connected xspeedhub. There is no token to paste; Kiro keeps the credentials it receives.

Full setup: https://xspeedcache.com/agent/kiro/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Kiro prompts before it runs an MCP tool unless a rule allows it. Rules live in two places: autoApprove in the server's mcp.json entry, which lists tool names, and mcp rules in permissions.yaml, such as a match of xspeedhub/get_* with effect allow. Allow the reads and keep purge_cache, update_settings, toggle_cache and the other write tools off both lists, because the Hub itself runs a write as soon as your connection allows it. Putting "*" in autoApprove skips the prompt for every Hub tool, writes included. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.

## Prompts

- Ask xSpeed Hub to preview an optimization for the booking site at the safe level. Stop after the plan.
- With xSpeed Hub, apply that plan to booking, then tell me which pages to test, starting with the booking form.
- What is left on the xSpeed Hub unfixable list, and which of those items does the booking form page cause?

## Example session

```
You: Use xSpeed Hub to raise the PageSpeed score on the booking site. Safe level, plan first.
  → list_sites [read-only]: 3 sites; booking is booking.example.com
  → optimize_site(site: booking, aggressiveness: safe, dry_run: true) [dry run]: plan: 3 settings to apply (lazy-load images, compression, browser cache), nothing changed
Agent: At the safe level it would turn on lazy-loading, compression and browser caching, and leave your scripts alone. Nothing has changed. Apply it to booking?
You: Yes, apply it.
  → optimize_site(site: booking, aggressiveness: safe) [changes site]: applied 3, undone 0, unfixable: calendar widget script, large header image
Agent: All three settings are on. The calendar widget script and the header image are on the unfixable list. Open the home page and the booking form in a browser, make a test booking if you can, and check the console.
```

## How it works

1. **See where the site stands**: The agent reads get_score_history for the last stored scores and list_modules for which modules exist on that site and what state they are in. Neither changes anything.
2. **Preview with dry_run**: optimize_site with dry_run: true returns the plan: each change and its tier, what would be skipped (already on, or needing a higher aggressiveness) and what it cannot fix. Nothing is applied. The tool description tells the agent to prefer this before the first real run on a site you have not optimized before.
3. **Apply it**: optimize_site without dry_run applies the plan. aggressiveness is safe (removals and server-side changes only), standard (the default) or aggressive, which includes settings known to break some themes and should be opted into deliberately. A run can take up to about 2 minutes per site.
4. **Look at the site afterwards**: When changes were applied, the result carries verify_urls and a note. The site checks its own HTML and reverts anything that breaks it, but it cannot run JavaScript, so verified: true does not prove the page works in a browser. The Hub tells the agent to open those URLs and check the page renders and the console is clean, or to tell you which URLs to check.
5. **Reach for a number only if you named one**: target_score (1 to 100, Pro sites only) turns one pass into repeated rounds toward that score, up to max_rounds, with 3 as the most per site. Each round is a real PageSpeed measurement and up to about 2 minutes. The result says why it stopped, and diminishing returns means what is left is outside what caching can reach.
6. **Critical CSS on Pro sites**: generate_critical_css generates above-the-fold CSS so the first screen can paint without waiting for the full stylesheets. It needs the Pro Critical CSS module on that site, and the site answers with an unknown-tool error without it. Pages are rebuilt with it on their next build, so the agent purges the cache afterwards.

## Reference

| | |
| --- | --- |
| Main tool | optimize_site (write): measure, apply one setting at a time, verify, undo what breaks, re-measure |
| Preview | dry_run: true returns the plan and changes nothing |
| aggressiveness | safe, standard (default) or aggressive |
| Every site at once | site: "all" or a list of handles, one result per site, sites run one after another; the Hub's confirm-once instruction does not name optimize_site, so your client's prompt is the gate |
| Time | Up to about 2 minutes per site |
| target_score | 1 to 100; needs Pro on the site; without it the site runs one pass and says so |
| max_rounds | Up to 3 per site; only sent along with target_score; 12 rounds in total per call |
| Wide fan-out with a target | Each site gets fewer rounds, and the result carries a note saying so |
| Result fields | applied, skipped, reverted, unfixable, score, verified, rounds; verify_urls after a run that changed something |
| Already tuned site | Returns "everything is already on" plus what it cannot fix; that is an answer, not a failure |
| Critical CSS | generate_critical_css (write), Pro Critical CSS module required; purge_cache afterwards |
| Read-only connection | optimize_site and generate_critical_css are refused; dry_run is still a write call, so it is refused too. Applies to the connection token with Read-only everywhere on and to a Viewer sign-in, not to other OAuth sign-ins |

## Rules

- Run dry_run first. optimize_site changes live site settings as soon as your connection allows writes. The tool description tells the agent to preview first on a site that has not been optimized, but that is guidance, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the real gates.
- Keep aggressive for a deliberate choice. It includes settings known to break some themes, and the agent should say so before using it.
- After a run that changed something, open the pages in verify_urls. The HTML checks cannot run JavaScript, so a page can pass them and still be broken in a browser. Do not call a run safe because verified is true.
- Relay the unfixable list. When a site is already tuned, the honest answer is that caching is done and the rest is page weight, hotlinked images or DOM size. The agent should not retry the tool or claim a gain it did not make.
- Only ask for target_score when you want the site driven to a number. Each round costs a real PageSpeed measurement, and a plain "make it faster" is one pass.

## Good to know with Kiro

Kiro prompts before an MCP tool runs unless the tool is in the autoApprove list of its mcp.json entry or an mcp rule in permissions.yaml allows it, and both work per tool. Do not add optimize_site to either just to stop the preview from prompting, because the real pass is the same tool and would then run without a prompt too, and an asterisk in autoApprove skips the prompt for every Hub tool. If you want fewer prompts, auto-approve read tools such as list_sites and list_modules, and keep optimize_site, generate_critical_css and purge_cache on a prompt. In a workspace you have not trusted, Kiro asks before every MCP call anyway.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Ask xSpeed Hub to preview what optimize_site would change on shop with a safe pass. Do not apply anything.
- Use xSpeed Hub to optimize the blog site with the standard pass, then give me the pages to check by hand.
- With xSpeed Hub, get docs to a mobile PageSpeed score of 90 if you can, and tell me why it stopped if it does not get there.
- Use xSpeed Hub to show me what optimize_site would do on every site, as a dry run, and list which sites have the most left to change.
- Use xSpeed Hub to generate critical CSS for shop, then purge the cache so the pages are rebuilt with it.
- With xSpeed Hub, optimize shop, then compare the new PageSpeed score with the last stored one.
- Using xSpeed Hub, what could optimize_site not fix on the shop site?

## Frequently asked questions

### Which xSpeed tools are safe to put on Kiro's autoApprove list?

Read tools such as list_sites, list_modules and get_score_history change nothing, so they are reasonable candidates. Keep optimize_site, generate_critical_css and purge_cache off the list, because they change the site.

### Can Kiro apply an aggressive xSpeed pass?

It can if you ask for aggressiveness aggressive. That level includes settings known to break some themes, so use the dry run first, test on a staging copy where you can, and check every verify URL in a browser.

### What does optimize_site actually do?

It measures the site, applies the recommended xSpeed settings one at a time, checks that the page still renders after each change, and undoes any change that breaks it. It then reports what was applied, skipped and reverted, and what it could not fix. It reaches caching and asset delivery only.

### Should I run a dry run first?

Yes, especially on a site you have not optimized before. dry_run: true returns the plan, what would be skipped and what cannot be fixed, and changes nothing. The tool description tells the agent to prefer it, but nothing forces it, so say so in your prompt if you want a preview.

### Can I tell it to get my site to a score of 90?

Yes, with target_score, on a site that has xSpeed Pro. It repeats measure, apply and re-measure for up to 3 rounds per site and stops early when rounds stop helping, saying why. On a Free site the score target is ignored and you get a single pass with a note that no iterative tuner is installed.

### Why did it say everything is already on?

That is a real answer. The settings it can apply were already enabled, so there was nothing to change. The result also lists what it could not fix, such as page weight, images hosted on another domain or DOM size, and those need changes outside a caching plugin.

### Does the agent check that my pages still work?

The site checks its own HTML after each change and reverts anything that breaks it, but it cannot run JavaScript. After a run that changed something, the Hub tells the agent to open the returned verify_urls and check the page renders and the console is clean, or to give you the URLs to check yourself.

### Does generate_critical_css work on a Free site?

No. It needs the Pro Critical CSS module on that site, and without it the site answers with an unknown-tool error. On a Pro site, purge the cache afterwards, because pages already cached were built without the critical CSS.

## Raise the PageSpeed score with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/optimize-site/) · [Claude](https://xspeedcache.com/agent/claude/optimize-site/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/optimize-site/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/optimize-site/) · [Codex](https://xspeedcache.com/agent/codex/optimize-site/) · [Cursor](https://xspeedcache.com/agent/cursor/optimize-site/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/optimize-site/) · [Windsurf](https://xspeedcache.com/agent/windsurf/optimize-site/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/optimize-site/) · [Antigravity](https://xspeedcache.com/agent/antigravity/optimize-site/) · [Zed](https://xspeedcache.com/agent/zed/optimize-site/) · [OpenCode](https://xspeedcache.com/agent/opencode/optimize-site/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/optimize-site/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/optimize-site/) · [Grok Build](https://xspeedcache.com/agent/grok-build/optimize-site/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/optimize-site/) · [Grok](https://xspeedcache.com/agent/grok/optimize-site/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/optimize-site/) · [Muse](https://xspeedcache.com/agent/muse/optimize-site/) · [Manus](https://xspeedcache.com/agent/manus/optimize-site/) · [Kimi Code](https://xspeedcache.com/agent/kimi/optimize-site/) · [Paperclip](https://xspeedcache.com/agent/paperclip/optimize-site/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/optimize-site/)

## More with Kiro

- [Purge the WordPress cache with Kiro](https://xspeedcache.com/agent/kiro/purge-cache/)
- [Find out why WordPress pages are not cached with Kiro](https://xspeedcache.com/agent/kiro/troubleshoot-cache/)
- [Scan a website for speed problems with Kiro](https://xspeedcache.com/agent/kiro/speed-scan/)
- [Run and track PageSpeed tests with Kiro](https://xspeedcache.com/agent/kiro/pagespeed-tests/)
- [Tune WordPress cache settings with Kiro](https://xspeedcache.com/agent/kiro/cache-settings/)
- [Warm the WordPress cache with Kiro](https://xspeedcache.com/agent/kiro/preload-cache/)
- [Set up the Redis object cache with Kiro](https://xspeedcache.com/agent/kiro/object-cache/)
- [Manage Cloudflare caching with Kiro](https://xspeedcache.com/agent/kiro/cloudflare/)
- [Manage every WordPress site at once with Kiro](https://xspeedcache.com/agent/kiro/fleet/)

## Documentation

- How to generate Critical CSS: https://xspeedcache.com/docs/critical-css/
- Performance recommendations: https://xspeedcache.com/docs/performance-recommendations/
- How to run a speed test: https://xspeedcache.com/docs/external-score/
- Free vs Pro: what is included: https://xspeedcache.com/docs/free-vs-pro/
