# OpenCode + xSpeed: Manage WordPress Caching

> OpenCode is an open-source AI coding agent for the terminal, and with xSpeed Hub added as a remote MCP server it can read cache status, purge, change settings and run speed tests on every WordPress site in your workspace. You add one block to your config, sign in once, and say use xspeedhub in a prompt.

Page: https://xspeedcache.com/agent/opencode/
Last updated: October 2026

- One config block, one URL, every site you connected to the Hub
- Tools appear as xspeedhub_<tool>, so permission rules can match reads and writes by name
- Enable the Hub for one agent only, so its 29 tools stay out of every other session

## How do I connect OpenCode to xSpeed?

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to your config

Put this block in your global config, or in opencode.json at a project root to scope it to that project. OpenCode reads both JSON and JSONC. No other field is needed: when the Hub answers 401, OpenCode starts the OAuth flow and registers itself through dynamic client registration.

File: `~/.config/opencode/opencode.json`

```jsonc
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "xspeedhub": {
      "type": "remote",
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

### 3. Sign in with opencode mcp auth

Run this once. It opens a browser page on xSpeed Hub where you sign in and approve access. There is no token to paste; OpenCode stores the credentials it receives. Run opencode mcp list to see the server and its auth status, and opencode mcp debug xspeedhub if the connection fails.

```bash
opencode mcp auth xspeedhub
```

### 4. Or use a connection token (alternative)

If you prefer a header, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), export it as XSPEED_HUB_TOKEN, and turn OAuth off for this server so OpenCode does not start a sign-in.

File: `~/.config/opencode/opencode.json`

```jsonc
{
  "mcp": {
    "xspeedhub": {
      "type": "remote",
      "url": "https://app.xspeedcache.com/xspeed/mcp",
      "oauth": false,
      "headers": {
        "Authorization": "Bearer {env:XSPEED_HUB_TOKEN}"
      }
    }
  }
}
```

**Authentication:** OAuth sign-in or connection token. Run opencode mcp auth xspeedhub and approve access in the browser; OpenCode stores the tokens it receives. If you would rather use a header, switch OAuth off for the server and send the connection token from the Hub's Connect AI page.

**Check it worked:** ask "Use xspeedhub to list my sites and show which ones have a cache hit ratio under 60%."

## Does OpenCode ask before it changes my site?

OpenCode checks MCP tools against its permission rules under the prefixed name, such as xspeedhub_purge_cache, and most permissions default to allow. With no rule of yours in place, a Hub write tool runs without a prompt. Add rules to change that: "xspeedhub_*": "ask" first, then "xspeedhub_get_*": "allow" and "xspeedhub_list_*": "allow", because the last matching rule wins. A deny rule holds even under opencode --auto, which approves everything that is not denied. The Hub itself has no confirmation step, so these rules and read-only access are the gates. For read-only access, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

## Example session

```
You: Use xspeedhub: how much does the cache help on blog right now?
  → run_benchmark(site: blog) [read-only]: cached 38 ms, uncached 412 ms over 5 runs
  → get_preloader_status(site: blog) [read-only]: last run finished 3 days ago, 212 URLs warmed
Agent: Cached responses take about 38 ms against 412 ms uncached. The preloader last ran three days ago, so recent posts may not be warm yet. Start it again?
You: Yes.
  → start_preloader(site: blog) [changes site]: preloader started, 226 URLs queued
Agent: The preloader is running with 226 URLs queued, 14 more than last time. Ask me again in a few minutes and I will check its progress.
```

## What is OpenCode?

OpenCode is an open-source coding agent that runs in your terminal. It reads and edits code, runs commands, and calls tools from MCP servers you list under the mcp key of its config, alongside its built-in tools.

MCP, the Model Context Protocol, is how OpenCode reaches services outside your machine. A remote server is one block with type remote and a url. Adding xSpeed Hub that way gives it the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace.

## Why use OpenCode with xSpeed?

- **Name it in the prompt**: OpenCode lets you refer to a server by name, so use xspeedhub in a prompt points the agent at the Hub without any setup per session.
- **Permission rules by tool name**: Each Hub tool is its own permission key, so one pattern allows the reads and another keeps every write on a prompt or denies it.
- **A Hub agent of its own**: Disable the Hub globally and enable it for a single agent in your config. Your coding agents then never carry the Hub's tool definitions.

## Good to know

- OpenCode starts from permissive defaults. Until you add an ask or deny rule for xspeedhub_ tools, treat every write tool as able to run on the model's say-so.
- The Hub adds 29 tool definitions to every request in the session. OpenCode's docs warn that MCP servers add to context, so enable it per agent if you only need it sometimes.
- OpenCode waits 5 seconds by default to fetch a server's tool list. If discovery times out, raise the timeout field on the xspeedhub entry, in milliseconds.

## Prompts to try

- Use xspeedhub to show the cache hit ratio of every site and flag anything under 70%.
- Use xspeedhub to purge the assets cache on shop, then show its cache status.
- Use xspeedhub to start the preloader on blog and report how many URLs it queued.
- Use xspeedhub to run a mobile PageSpeed test on docs and compare it with the stored history.
- Use xspeedhub to preview a safe optimize_site pass on landing. Do not apply it.

## What can OpenCode do with xSpeed?

- [Purge the WordPress cache with OpenCode](https://xspeedcache.com/agent/opencode/purge-cache/): Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
- [Find out why WordPress pages are not cached with OpenCode](https://xspeedcache.com/agent/opencode/troubleshoot-cache/): Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
- [Scan a website for speed problems with OpenCode](https://xspeedcache.com/agent/opencode/speed-scan/): Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
- [Run and track PageSpeed tests with OpenCode](https://xspeedcache.com/agent/opencode/pagespeed-tests/): Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
- [Raise a WordPress site's PageSpeed score with OpenCode](https://xspeedcache.com/agent/opencode/optimize-site/): Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
- [Tune WordPress cache settings with OpenCode](https://xspeedcache.com/agent/opencode/cache-settings/): See which modules a site has, read their current settings, change them, and turn page caching on or off.
- [Warm the WordPress cache with OpenCode](https://xspeedcache.com/agent/opencode/preload-cache/): Fill the page cache before visitors arrive, for example right after a purge or a deploy.
- [Set up the Redis object cache with OpenCode](https://xspeedcache.com/agent/opencode/object-cache/): Connect a site to Redis or Memcached so database results survive between requests.
- [Manage Cloudflare caching with OpenCode](https://xspeedcache.com/agent/opencode/cloudflare/): Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
- [Manage every WordPress site at once with OpenCode](https://xspeedcache.com/agent/opencode/fleet/): Run one action across all of your sites, or a chosen few, and read the result site by site.

## Which way should I connect?

| Surface | Endpoint | Reaches | Auth | Tools |
| --- | --- | --- | --- | --- |
| [xSpeed Hub MCP](https://xspeedcache.com/docs/hub-mcp/) | `https://app.xspeedcache.com/xspeed/mcp` | Every site in your workspace, one connection | OAuth sign-in in the browser, or a connection token in an Authorization header | 29 tools (16 read, 13 write), seven of them can act on every site at once |
| [xSpeed Cache Site MCP](https://xspeedcache.com/docs/mcp-server/) | `https://your-site.com/xspeed/mcp` | One WordPress site | OAuth sign-in by a site admin, or the site's own token in an Authorization header | The full per-site tool set plus run_command for the WP-CLI surface |
| [xSpeed Scan MCP](https://xspeedcache.com/docs/scan-mcp/) | `https://xspeedcache.com/scan/mcp` | Any public URL, read-only | None. No account. | 5 tools: run_speed_scan, get_speed_scan and three product-info tools |
| [WP-CLI](https://xspeedcache.com/docs/wp-cli-commands/) | `wp xspeed …` | The site whose server the agent has a shell on | Your server login | Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more |

## Frequently asked questions

### How do I add xSpeed Hub to OpenCode?

Add an xspeedhub block under mcp in your OpenCode config with type remote and the url https://app.xspeedcache.com/xspeed/mcp, then run opencode mcp auth xspeedhub and approve access in the browser. After that you can say use xspeedhub in a prompt.

### Do I need an API key?

No. OpenCode signs in to the Hub with OAuth and stores the credentials it receives. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page, set oauth to false on the server and send it in an Authorization header.

### Will OpenCode change my site without asking?

It can, depending on your rules. Most OpenCode permissions default to allow, so a Hub write tool runs without a prompt unless you add an ask or deny rule for it. The Hub has no confirmation step of its own, so set those rules, or send the connection token with Read-only everywhere on, or sign in as a Viewer member, before you let an agent loose on live sites.

### How do I make OpenCode ask before writes?

In your permission config, add a rule that sets every tool whose name starts with xspeedhub_ to ask, then add allow rules for the names that start with xspeedhub_get_ and xspeedhub_list_. OpenCode applies the last matching rule, so the catch-all goes first. Use deny instead of ask for any tool you never want to run.

### Which tools does OpenCode get?

The 29 tools of the xSpeed Hub MCP server, registered with the server name as a prefix, for example xspeedhub_purge_cache. Sixteen only read; thirteen change a site or spend the shared speed-test allowance.

### Can I use OpenCode with one site and no Hub?

Yes. The xSpeed Cache plugin has its own MCP server at your-site.com/xspeed/mcp, switched on from xSpeed Cache, AI and agents, MCP in wp-admin. The Hub is the better fit once you have more than one site.

### How do I disconnect OpenCode?

Run opencode mcp logout xspeedhub to remove the stored credentials, and delete or disable the entry in your config. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in OpenCode.

## Also works with

[Claude Code](https://xspeedcache.com/agent/claude-code/) · [Claude](https://xspeedcache.com/agent/claude/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/) · [Codex](https://xspeedcache.com/agent/codex/) · [Cursor](https://xspeedcache.com/agent/cursor/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/) · [Windsurf](https://xspeedcache.com/agent/windsurf/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/) · [Antigravity](https://xspeedcache.com/agent/antigravity/) · [Zed](https://xspeedcache.com/agent/zed/) · [Kiro](https://xspeedcache.com/agent/kiro/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/) · [Grok Build](https://xspeedcache.com/agent/grok-build/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/) · [Grok](https://xspeedcache.com/agent/grok/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/) · [Muse](https://xspeedcache.com/agent/muse/) · [Manus](https://xspeedcache.com/agent/manus/) · [Kimi Code](https://xspeedcache.com/agent/kimi/) · [Paperclip](https://xspeedcache.com/agent/paperclip/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/)

## Sources

- OpenCode docs: MCP servers: https://opencode.ai/docs/mcp-servers/
- OpenCode docs: Permissions: https://opencode.ai/docs/permissions/
- OpenCode docs: Config: https://opencode.ai/docs/config/
- OpenCode source: MCP tool permission check: https://github.com/sst/opencode/blob/dev/packages/opencode/src/session/tools.ts
- OpenCode source: default permissions: https://github.com/sst/opencode/blob/dev/packages/opencode/src/agent/agent.ts
