# Manage Cloudflare caching with OpenClaw

> Managing Cloudflare with OpenClaw means asking your always-on agent to verify WordPress sites' Cloudflare links, purge the edge cache or toggle development mode through xSpeed Hub, now or on an automation it runs.

Page: https://xspeedcache.com/agent/openclaw/cloudflare/
Last updated: October 2026

OpenClaw is an agent that stays running, so the useful question is what it should do when you are not there. For Cloudflare the safe answer is to check. A Cloudflare token can be revoked, a zone can change, and nobody notices until a purge fails. You can have OpenClaw call cloudflare_verify on each site on a schedule and report any that no longer resolve, which uses a read tool and changes nothing on any site.

The writes are different. purge_cloudflare clears the edge copy for one site, and set_cloudflare_dev_mode bypasses the edge for about three hours, slowing real visitors the whole time. Both need Cloudflare connected in xSpeed on that site, and neither accepts site: "all", so an automation that touches ten sites makes ten calls. The Hub has no scheduler for agent prompts: if a job runs on a timer, it is OpenClaw's automation that fires it, not the Hub. The Hub runs its own daily checks and sends its own alerts, separate from anything OpenClaw schedules.

When you ask in a chat, OpenClaw behaves like any other agent: it verifies, tells you what it found, and acts on your answer. The Hub adds no prompt, so OpenClaw's own gates matter. A per-server tool include list decides which Hub tools exist for the agent, so a list with only cloudflare_verify keeps both writes out of reach. When the Codex runtime runs your turns, you can set the server to prompt on every call, but the default full-permission posture does not prompt. For an automation, decide ahead of time which tools it may call, because a scheduled run is unattended. A scheduled job should report only, and any write should wait for you.

## Set up OpenClaw once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Save xSpeed Hub as an MCP server

Run this on the machine that hosts your OpenClaw Gateway. Set the transport to streamable-http: OpenClaw falls back to SSE when you leave it out. With --auth oauth the command saves the server without a connection test, because sign-in has to happen first.

```bash
openclaw mcp add xspeedhub \
  --url https://app.xspeedcache.com/xspeed/mcp \
  --transport streamable-http \
  --auth oauth
```

### 3. Sign in with openclaw mcp login

OpenClaw prints an authorization URL and listens on a loopback address for the callback. Open the URL, sign in to xSpeed Hub and approve; the token exchange finishes by itself. There is no token to paste. If your browser is on another machine, copy the code from the redirect and pass it back with openclaw mcp login xspeedhub --code. Then check the connection.

```bash
openclaw mcp login xspeedhub
openclaw mcp doctor xspeedhub --probe
```

Full setup: https://xspeedcache.com/agent/openclaw/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. OpenClaw gives you two client-side gates, and the Hub adds none. First, openclaw mcp tools xspeedhub --include limits which tools exist for the agent, so a list of read tools keeps every write out of reach. Second, when the Codex runtime runs your agent turns, MCP tool approvals follow the session's permission posture, and the default full-permission posture does not prompt. openclaw mcp configure xspeedhub --approval prompt asks on every call, and Allow Always saves a grant for that one tool with any arguments. OpenClaw's docs describe that per-call prompt for the Codex runtime; with its own embedded runtime, use the tool filter to decide what the agent can call. The Hub has no confirmation step of its own.

## Prompts

- Every morning, use xSpeed Hub to verify the Cloudflare connection on each of my sites and message me only if one fails.
- With xSpeed Hub, purge the Cloudflare edge cache on shop now, and tell me what the tool returned.
- Use xSpeed Hub to turn on Cloudflare development mode for blog and turn it off when I say I am done.

## Example session

```
You: Use xSpeed Hub to check the Cloudflare link on blog. The nightly report said the token might have changed.
  → cloudflare_verify(site: blog) [read-only]: Cloudflare token rejected; credentials need checking
Agent: Cloudflare rejected the stored token on blog, so a purge there would fail too. Update the token in xSpeed on that site, then I can verify again. I have not purged anything.
You: I updated the token in xSpeed. Check the link again.
  → cloudflare_verify(site: blog) [read-only]: Credentials and zone resolve; Cloudflare connected
Agent: The link works again on blog. I can purge the edge cache or turn on development mode whenever you say.
```

## How it works

1. **Verify the connection**: cloudflare_verify calls Cloudflare's API with the credentials stored on the site and checks that the token and zone still resolve. It purges nothing and works on a read-only connection. If Cloudflare is not connected on that site, the call comes back as an error and the agent should tell you rather than retry.
2. **Purge the edge**: purge_cloudflare empties the Cloudflare edge cache for the site's zone. It does not touch the copies on your server. When Cloudflare is in front of a site, a content change usually needs both, so the agent runs purge_cache first and purge_cloudflare after it, or one purge_cache of type all, which reaches the edge when Cloudflare is connected.
3. **Turn development mode on to see origin changes**: set_cloudflare_dev_mode with enabled true bypasses the edge for about three hours, so changes on the origin show immediately. It slows the site for real visitors the whole time. Your client's prompt is the gate here, because the Hub's instructions do not name this tool in their confirm list.
4. **Turn it off when you finish**: set_cloudflare_dev_mode with enabled false switches development mode off. Cloudflare also ends it on its own after about three hours. No Hub tool reads whether it is currently on, so note when you turned it on.
5. **Read a failure**: A rejected token, an empty zone ID or a refused call comes back as an error that names the action, the HTTP status and Cloudflare's message when it gave one. It is not reported as a success. The credentials themselves are set in the xSpeed Cache panel in wp-admin, not through the Hub.

## Reference

| | |
| --- | --- |
| Read tool | cloudflare_verify; purges nothing and works on a read-only connection |
| Write tools | purge_cloudflare and set_cloudflare_dev_mode (enabled true or false) |
| Needs | Cloudflare connected in xSpeed on that site: integration on, an API token (or the legacy key and email) and a Zone ID |
| Edge purge scope | Everything Cloudflare holds for the site's zone; the server copies stay |
| Development mode | Bypasses the edge for about 3 hours, then Cloudflare switches it off |
| Token permissions | Zone Cache Purge, and Zone Settings Edit for development mode |
| What verify proves | The token and zone resolve; a token without Zone Settings Edit still verifies |
| Through purge_cache | Type all also clears the edge when Cloudflare is connected; page, assets, object and rest do not |
| Every site at once | None of the three accept site: "all"; one site per call |
| Failure shape | An error with the action, the HTTP status and Cloudflare's message |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in; purge_cloudflare and set_cloudflare_dev_mode are refused and cloudflare_verify works. An OAuth sign-in gets the scopes the client asks for, so the switch does not make it read-only |
| Confirmation | None on the Hub; your client's prompt is the gate |

## Rules

- Run cloudflare_verify first, but do not read a pass as proof that every call will work. A token that lacks Zone Settings Edit verifies and purges fine, then fails the first time development mode is switched.
- Purge the server and the edge together after a content change. Purging only the site leaves visitors on the old page until the edge copy expires.
- Turn development mode off as soon as you are done. It slows the site for real visitors for up to about three hours, and no tool reports its state.
- Never paste a Cloudflare token or Global API Key into the chat. Connect Cloudflare in the xSpeed Cache panel in wp-admin, and use a scoped API token rather than the Global API Key.
- purge_cloudflare and set_cloudflare_dev_mode are write tools. The Hub runs them as soon as your connection allows writes, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer member's sign-in) are the gates that matter.

## Good to know with OpenClaw

An always-on agent keeps working from the connection you gave it, and the Hub has no confirmation step of its own. If an automation holds a write-enabled connection and both writes are exposed to it, a purge or a dev mode switch it decides on runs with nobody watching, and development mode left on slows the site for about three hours. Limit a scheduled job's tools to cloudflare_verify, or give it the connection token with Read-only everywhere on (a Viewer member's sign-in works too), where cloudflare_verify works and both writes are refused. Use a write-enabled connection only for chats where you are present.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to check that the Cloudflare connection on shop still works.
- With xSpeed Hub, purge the Cloudflare edge cache on blog.
- I changed the checkout page on shop. Use xSpeed Hub to purge the site cache and the Cloudflare edge.
- Use xSpeed Hub to turn Cloudflare development mode on for shop. I am editing the theme.
- With xSpeed Hub, turn Cloudflare development mode off on shop.
- Ask xSpeed Hub to verify Cloudflare on shop and tell me what is wrong if it fails.
- Using xSpeed Hub, which of my sites have a working Cloudflare connection? Check them one at a time.

## Frequently asked questions

### Can OpenClaw check my Cloudflare connection every day?

Yes, with an automation of its own that calls cloudflare_verify on each site. The Hub does not schedule agent prompts, so OpenClaw fires the job. The check only reads, so it is a good fit for an unattended run.

### Should an OpenClaw automation purge Cloudflare unattended?

Only if you accept that nobody confirms it. The Hub runs a purge as soon as the connection allows writes. For scheduled jobs, use a read-only connection, meaning the connection token with Read-only everywhere on or a Viewer member's sign-in, and let the automation report problems for you to act on.

### What does a site need before the Cloudflare tools work?

Cloudflare has to be connected in xSpeed on that site: the integration switched on, an API token (or the legacy Global API Key with your Cloudflare email) and the Zone ID of the domain. You set these in the xSpeed Cache panel in wp-admin. Without them, the tools return an error instead of acting.

### Does purging the xSpeed cache also clear Cloudflare?

A purge_cache of type all does, when the site has Cloudflare connected, and it reports each step. A page, assets, object or rest purge stays on your server. purge_cloudflare clears only the edge, so use it when the server copy is already fresh.

### How long does development mode last?

About three hours. Cloudflare switches it off on its own after that. While it is on, the edge is bypassed, so origin changes show at once and real visitors get a slower site. Turn it off yourself with set_cloudflare_dev_mode set to false when you are done.

### Why did cloudflare_verify pass but development mode failed?

Verifying and purging do not need Zone Settings Edit on the token, so a token without it looks fine. Development mode writes a zone setting, so it is refused. Edit the token in Cloudflare so it has both Zone Cache Purge and Zone Settings Edit, then try again.

### Can I purge Cloudflare on all my sites with one prompt?

Not with purge_cloudflare, which takes one site per call. A purge_cache of type all with site set to all clears the edge on each site that has Cloudflare connected, and the result is reported per site. The Hub tells the agent to confirm a write across every site with you once first.

## Manage Cloudflare with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/cloudflare/) · [Claude](https://xspeedcache.com/agent/claude/cloudflare/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/cloudflare/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/cloudflare/) · [Codex](https://xspeedcache.com/agent/codex/cloudflare/) · [Cursor](https://xspeedcache.com/agent/cursor/cloudflare/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/cloudflare/) · [Windsurf](https://xspeedcache.com/agent/windsurf/cloudflare/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/cloudflare/) · [Antigravity](https://xspeedcache.com/agent/antigravity/cloudflare/) · [Zed](https://xspeedcache.com/agent/zed/cloudflare/) · [Kiro](https://xspeedcache.com/agent/kiro/cloudflare/) · [OpenCode](https://xspeedcache.com/agent/opencode/cloudflare/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/) · [Grok Build](https://xspeedcache.com/agent/grok-build/cloudflare/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/cloudflare/) · [Grok](https://xspeedcache.com/agent/grok/cloudflare/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/cloudflare/) · [Muse](https://xspeedcache.com/agent/muse/cloudflare/) · [Manus](https://xspeedcache.com/agent/manus/cloudflare/) · [Kimi Code](https://xspeedcache.com/agent/kimi/cloudflare/) · [Paperclip](https://xspeedcache.com/agent/paperclip/cloudflare/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/cloudflare/)

## More with OpenClaw

- [Purge the WordPress cache with OpenClaw](https://xspeedcache.com/agent/openclaw/purge-cache/)
- [Find out why WordPress pages are not cached with OpenClaw](https://xspeedcache.com/agent/openclaw/troubleshoot-cache/)
- [Scan a website for speed problems with OpenClaw](https://xspeedcache.com/agent/openclaw/speed-scan/)
- [Run and track PageSpeed tests with OpenClaw](https://xspeedcache.com/agent/openclaw/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with OpenClaw](https://xspeedcache.com/agent/openclaw/optimize-site/)
- [Tune WordPress cache settings with OpenClaw](https://xspeedcache.com/agent/openclaw/cache-settings/)
- [Warm the WordPress cache with OpenClaw](https://xspeedcache.com/agent/openclaw/preload-cache/)
- [Set up the Redis object cache with OpenClaw](https://xspeedcache.com/agent/openclaw/object-cache/)
- [Manage every WordPress site at once with OpenClaw](https://xspeedcache.com/agent/openclaw/fleet/)

## Documentation

- How to connect Cloudflare: https://xspeedcache.com/docs/cloudflare/
- How to serve assets from a CDN: https://xspeedcache.com/docs/cdn/
- How to enable Page Cache: https://xspeedcache.com/docs/page-cache/
