How Paperclip handles this
You run Paperclip on your own server with a Claude Code agent whose job includes the company blog. Readers have noticed that the newest posts take a while to show up on the blog's listing pages. You open a ticket and assign it: review the cache settings on blog and propose an expiry for a site that publishes every day. The agent wakes, calls list_modules for the module list and status, then get_settings for the cache module, and starts from the stored values instead of a guess.
What comes back is a comment on the ticket rather than a chat reply: the cache expiry on blog is 168 hours, a week, so a listing page can keep showing last week's posts until something purges it. The proposal is 24 hours and nothing else. The Hub tells the agent to briefly confirm intent before update_settings, and on a ticket that means it waits for your reply. Once you approve, it calls update_settings and records the old and new values on the task, which is your way back, because the Hub keeps no undo. A wrong key or value refuses the whole call with nothing stored, and credential fields are refused over the Hub.
What differs in Paperclip is that the agent runs headless, so the usual approval prompt may not exist. Paperclip's Claude Code adapter runs with dangerouslySkipPermissions on by default, which lets the agent call MCP tools without asking, and a server added with claude mcp add on the host bypasses Paperclip's action permissions and review queue. The governed route is the Connectors page: each Hub tool is set to Allowed, Ask first or Off, and since the Hub publishes no annotations Paperclip classifies them by name. Start update_settings and toggle_cache on Off or Ask first.
Set up Paperclip once
Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Paperclip guide.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub to the agent Paperclip runs
For a Claude Code agent, run this on the machine that hosts it, as the same OS user the Paperclip heartbeat runs as. Paperclip's docs say MCP wiring lives at the adapter and runtime layer, and user scope makes the Hub available to every Claude Code agent that user runs.
claude mcp add --transport http --scope user xspeedhub https://app.xspeedcache.com/xspeed/mcp
3Sign in once, or use a token
Start claude interactively as that same user, run /mcp, choose xspeedhub and approve access on the xSpeed Hub page. Claude Code keeps the credentials, so later headless runs need no browser; claude mcp get xspeedhub shows the status. On a host with no browser, add the server with the connection token from Connect AI in the Hub instead, ideally with Read-only everywhere on.
# Interactive sign-in claude /mcp # Or a token, no browser claude mcp add --transport http --scope user xspeedhub https://app.xspeedcache.com/xspeed/mcp \ --header "Authorization: Bearer <your connection token>"
Full Paperclip setup, sign-in options and FAQ
Before you send a prompt that changes something
Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Paperclip's Claude Code adapter runs headless with dangerouslySkipPermissions on by default, which lets the agent call MCP tools without asking. Set it to false and a tool that needs approval does not run. A server added on the adapter does not pass through Paperclip's action permissions or review queue. A Paperclip connector does: each Hub tool is set to Allowed, Ask first or Off, and because the Hub publishes no annotations Paperclip classifies them by name, which can under-classify, so start every write Off. xSpeed Hub has no confirmation step of its own, so a write that gets past those settings runs as soon as your connection allows writes. For unattended routines, send a connection token with Read-only everywhere on, which makes the Hub refuse every write tool.
What do I ask?
Three prompts written for Paperclip. More for this job are below.
Ticket: use xSpeed Hub to read the cache module on blog and propose an expiry for a daily publishing site. Wait for my reply.
Weekly review: use xSpeed Hub to compare the cache expiry on every site and post the outliers on this task. Read only.
With xSpeed Hub, apply the approved expiry on blog and note the old value on the ticket.
What happens, step by step
Every xSpeed feature is a module with its own settings. Through xSpeed Hub an agent can list the modules a site has, read one module's settings, change them with a checked update, and turn page caching on or off. The site validates every write against the module's own schema, so a wrong key or value is refused with a reason instead of being quietly ignored.
01
List the modules
list_modules returns every Free and Pro module available on one site, with its settings schema and status. It tells the agent which module slugs exist, such as minify or gzip, and what each setting accepts.
02
Read the current settings
get_settings takes a module slug and returns its settings. Credential fields come back masked, so an agent cannot read a stored API token or password back in plain text.
03
Change them
update_settings takes the module and a values object of setting keys. The site checks the whole object first. If any key is unknown, any value is outside the schema, or a field is pinned by a constant in wp-config.php, it refuses the write, writes nothing and says which keys and why, sometimes with a "did you mean" hint.
04
Turn page caching on or off
Page caching has its own tool, toggle_cache, because it installs or removes the cache drop-in and the WP_CACHE constant. Asking update_settings to set cache_enabled does not work and is refused. If another caching plugin owns the drop-in, the site declines to enable xSpeed and returns blocked: true with the reason.
05
Check the effect
The result of a settings write is the stored settings. A module can add a warning when a setting is saved but has no effect on this server, for example Brotli on a server without the module for it, and the agent should pass that on. run_benchmark then times cached against uncached to see whether the change helped.
06
Apply to many sites only after reading one
update_settings and toggle_cache accept site: "all" or a list of handles. Each site validates against its own schema and answers in its own row, so a module missing on one site fails that row and the others still apply. Read one site first, then apply.
Reference
| Discover | list_modules (read): Free and Pro modules, settings schema, status, per site |
|---|---|
| Read settings | get_settings (read): argument module; credential fields masked |
| Change settings | update_settings (write): arguments module and values; validated by the site |
| Bad input | The whole write is refused and nothing is written; the error names the keys and reasons |
| Page cache on or off | toggle_cache (write): argument enabled; cache_enabled in update_settings is refused |
| Blocked by another plugin | toggle_cache returns blocked: true with blocked_reason when another plugin owns the cache drop-in |
| Every site at once | update_settings and toggle_cache accept site: "all" or a list of handles, one result per site |
| Pro modules | A Pro module on a site without an active licence cannot be read or written; the site refuses |
| Credential fields | Refused by default over MCP; set them in the xSpeed dashboard, not through the agent |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in: update_settings and toggle_cache are refused; list_modules and get_settings still work. An OAuth sign-in gets the scopes the client asks for, read and write by default, clamped to the member's role |
| Confirmation | None on the Hub; the Hub tells the agent to briefly confirm intent for these two, and your client's prompt is the gate |
Rules worth keeping
- Read before you write. Ask for list_modules and get_settings first, so the agent changes real keys with valid values instead of guessing.
- update_settings and toggle_cache change how a live site behaves. They run as soon as your connection allows writes. The Hub tells the agent to briefly confirm intent first, which is guidance to the agent, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates. The switch does not limit an OAuth sign-in.
- For site: "all", the Hub tells the agent to confirm once with "this will touch all N sites", then make one call. The result is per site, and some sites failing is a partial result to report, not a blanket success or failure.
- Do not ask an agent to set credentials such as a Cloudflare token or Redis password. The site refuses those writes by default, and they belong in the xSpeed dashboard.
- If a settings result says a value is saved but inactive on this server, relay that. Do not tell the user the feature is enabled.
Good to know with Paperclip
If the agent reaches the Hub through the adapter with dangerouslySkipPermissions left on, update_settings runs the moment the agent decides to call it, and only the instruction in your ticket holds it back. Set it to false, or use the connector route with the writes on Ask first, or send a connection token with Read-only everywhere on so the Hub refuses every write. A routine that reviews settings each week should use that read-only token. User scope is shared by every Claude Code agent the same OS user runs.
More prompts for this job
They work in any client connected to xSpeed Hub.
Use xSpeed Hub to list the modules on shop and tell me which ones are off.
Ask xSpeed Hub for the current minify settings on blog.
With xSpeed Hub, turn on HTML minification on blog, then benchmark the cache and tell me if it helped.
Use xSpeed Hub to turn page caching off on staging while I debug, and tell me when it is off.
Using xSpeed Hub, read the gzip settings on shop first, then enable the same options on every site.
Use xSpeed Hub to set the page cache lifespan on docs to 30 days, and if the site refuses it, tell me why.
Frequently asked questions
Keep going
Tune cache settings with other agents
More with Paperclip
Documentation
- How to enable Page Cache
- How to minify CSS and JavaScript
- How to add cache rules and bypasses
- Site MCP tool reference
- How to write prompts for xSpeed Hub
- Paperclip + xSpeed
- Every AI agent that works with xSpeed
From the blog