How Kiro handles this
You have just finished a spec-driven change in Kiro and shipped it to the live WordPress site, so the cache is cold. You ask the agent to warm that site. It calls list_sites to find the handle, then start_preloader, and the plugin on the site begins crawling its sitemap in the background, a small batch of pages at a time. The first visitors after the release get stored pages instead of rebuilds.
Progress is one more question away. The agent calls get_preloader_status, which says whether a run is active and how far through the URL list it has got. It is a read and changes nothing. If the crawl has to stop, ask for stop_preloader and the pages already warmed stay cached. The agent reports each result in plain words, so you can see whether a start actually began or the site refused.
Kiro prompts before it runs an MCP tool unless that tool appears in the server's autoApprove list. That list is how you decide, tool by tool, what runs without a prompt, and Kiro's permission rules can allow, ask or deny a tool by server and name. xSpeed Hub does not add a confirmation of its own, so a start runs as soon as your connection allows writes, and the Kiro prompt is the check you can see. Because the agent works from your project, you can also ask it to write the result of the status check into the notes for the release, so the next person sees which sites were warmed.
Set up Kiro once
Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Kiro guide.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub to mcp.json
Open the command palette and run Kiro: Open user MCP config (JSON), then add this entry. The user file applies in every workspace. A project can carry its own .kiro/settings/mcp.json instead, but Kiro does not load a workspace's MCP config until you trust that workspace. Kiro reconnects servers when you save the file.
{
"mcpServers": {
"xspeedhub": {
"url": "https://app.xspeedcache.com/xspeed/mcp"
}
}
} 3Approve access in the browser
After you save, Kiro opens the xSpeed Hub authorization page. It registers itself through dynamic client registration, so there is no client ID to create. Sign in to the Hub, approve, and check the MCP servers tab in the Kiro panel for a connected xspeedhub. There is no token to paste; Kiro keeps the credentials it receives.
Full Kiro setup, sign-in options and FAQ
Before you send a prompt that changes something
Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Kiro prompts before it runs an MCP tool unless a rule allows it. Rules live in two places: autoApprove in the server's mcp.json entry, which lists tool names, and mcp rules in permissions.yaml, such as a match of xspeedhub/get_* with effect allow. Allow the reads and keep purge_cache, update_settings, toggle_cache and the other write tools off both lists, because the Hub itself runs a write as soon as your connection allows it. Putting "*" in autoApprove skips the prompt for every Hub tool, writes included. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool.
What do I ask?
Three prompts written for Kiro. More for this job are below.
The release is out. Use xSpeed Hub to warm shop and tell me how far the preloader has got.
With xSpeed Hub, check the preloader on blog and say whether a run is active.
Use xSpeed Hub to stop the preloader on shop and then start it on docs.
What happens, step by step
The first visitor to an uncached page pays for building it. The preloader fixes that by visiting your pages first. Through xSpeed Hub an agent can start the crawl on one site or on every site in a workspace, watch how far it has got, and stop it. The crawl runs inside WordPress in the background; the agent only starts it, reads its progress and stops it.
01
Check the cache and the preloader
get_cache_status tells the agent whether page caching is on, because there is nothing to fill when it is off. get_preloader_status shows whether a crawl is already running, so the agent does not start a second one.
02
Make sure the preloader is switched on
The preloader module is off on a fresh install, and the site refuses start_preloader until it is on. The agent can read the module with get_settings and, if you agree, switch it on with update_settings on the preloader module. The Hub tells the agent to briefly confirm intent before an update_settings call, but that is guidance to the agent, not a lock.
03
Start the crawl
start_preloader makes the site read its sitemap, follow any nested sitemap indexes, drop URLs that your cache exclusion rules skip, and queue the rest. The call returns once the queue is built; the pages are then fetched in the background, a few per run. For every site at once the agent passes site: "all", and the Hub starts the sites one after another with a one-second pause.
04
Watch the progress
get_preloader_status reports whether a crawl is running, how many URLs it has processed out of the total, the last URL it visited and the most recent errors. It works on one site at a time, so for several sites the agent calls it once per site.
05
Read what failed
A page that answers 403 or 406 usually means a server firewall is blocking the warmer by its user-agent, not that the page is broken. The status message names the user-agent to allow. A crawl that queues no URLs is reported as an error with the reason, not as a success.
06
Stop it if the server struggles
stop_preloader ends a running crawl. It is safe mid-run: pages already warmed stay cached. The agent can stop one site or every site in the workspace.
Reference
| Start and stop | start_preloader and stop_preloader (write) |
|---|---|
| Progress | get_preloader_status (read): running or not, processed out of total, last URL, recent errors |
| What gets crawled | The sitemap (the WordPress one at /wp-sitemap.xml unless you set another), nested indexes followed, excluded URLs skipped |
| Needs | The preloader module switched on (it is off by default) and page caching on |
| Pages per run | 5 by default, 1 to 50, set in the preloader module |
| Schedule setting | manual, hourly, daily or weekly, set in the preloader module |
| Every site at once | start_preloader and stop_preloader accept site: "all"; get_preloader_status does not |
| Fan-out pacing | Sites start one after another with a 1 second pause, one result per site |
| Warmer user-agent | xSpeed-Warmer/1.0, the string a firewall rule would need to allow |
| Stopping | Safe mid-run; warmed pages stay cached |
| Read-only access | A Viewer member's sign-in, or the connection token with Read-only everywhere on: start_preloader and stop_preloader are refused; get_preloader_status works. An OAuth sign-in by anyone else gets the scopes the client asks for. |
| Confirmation | None on the Hub; your client's prompt is the gate |
Rules worth keeping
- Warm after a purge, not instead of one. The Hub tells the agent that starting the preloader after a purge saves the next visitor from paying for the rebuild.
- A crawl requests every page in the sitemap, so it adds load to the origin. Start with one site, and on a small host keep Pages per run low or stop the crawl if the site slows.
- start_preloader and stop_preloader are write tools. The Hub calls the preloader low-risk and only asks the agent to confirm when the target site is unclear or the call covers every site, so your client's approval prompt and read-only access (a Viewer sign-in, or the connection token with Read-only everywhere on) are the gates that matter.
- A fan-out only starts the crawls. Check each site with get_preloader_status afterwards, and treat some sites failing to start as a partial result, not a failure of the whole call.
Good to know with Kiro
The autoApprove list is the lever, and it is easy to over-fill. Putting get_preloader_status there is sensible, because it is a read. Putting start_preloader or stop_preloader there, or "*", makes every start and stop run without a prompt, on any site the agent names, so leave those out and approve the two writes one at a time. In a workspace you have not trusted, Kiro asks before every MCP call even when autoApprove lists the tool. To keep Kiro from starting crawls at all, list the two writes in disabledTools.
More prompts for this job
They work in any client connected to xSpeed Hub.
Use xSpeed Hub to start the preloader on shop and tell me how many URLs it queued.
Using xSpeed Hub, how far through its crawl is blog? Show processed against total and any errors.
With xSpeed Hub, purge the cache on docs, then warm it again.
Use xSpeed Hub to start the preloader on every site in my workspace and tell me which ones refused.
Use xSpeed Hub to stop the preloader on shop. It is slowing the server down.
The preloader on shop says it is disabled. Use xSpeed Hub to turn the module on, then start the crawl.
Using xSpeed Hub, which of my sites has no running crawl and a low hit ratio?
Frequently asked questions
Keep going
Warm the cache with other agents
More with Kiro
Documentation
- How to warm your cache ahead of visitors
- How to crawl your sitemap
- How to enable Page Cache
- Managing your fleet with xSpeed Hub
- How to write prompts for xSpeed Hub
- Kiro + xSpeed
- Every AI agent that works with xSpeed
From the blog