# Manage Cloudflare caching with Paperclip

> Managing Cloudflare with Paperclip means giving an agent it runs xSpeed Hub, so a routine verifies every site's Cloudflare link and posts failures on a task, while purges and development mode wait for a person.

Page: https://xspeedcache.com/agent/paperclip/cloudflare/
Last updated: October 2026

In Paperclip the Cloudflare check becomes a recurring ticket. A routine fires on a cron schedule, creates a task and wakes the agent you assigned. The task asks it to call cloudflare_verify on each site, one call per site, and to post the ones where Cloudflare rejected the token or the site has no Cloudflare connection in xSpeed, with the HTTP status and Cloudflare's message. Every call lands on the task trace, so the record of what was checked lives in the dashboard, not in someone's memory.

When a launch needs a fresh edge, that is a separate task you assign while you are around: purge_cache on the server first, then purge_cloudflare for the zone, on the sites named in the ticket. set_cloudflare_dev_mode, which bypasses the edge for about three hours and slows real visitors, rarely belongs in an agent's ticket at all; switch it from a client you sit in front of. None of the three Cloudflare tools accepts site: "all".

A failed verify means a person has to act. The Cloudflare credentials are set in the xSpeed Cache panel in wp-admin on that site, not through the Hub, so the ticket should name the site and stop there, and never ask anyone to paste a token into a task.

## Set up Paperclip once

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub to the agent Paperclip runs

For a Claude Code agent, run this on the machine that hosts it, as the same OS user the Paperclip heartbeat runs as. Paperclip's docs say MCP wiring lives at the adapter and runtime layer, and user scope makes the Hub available to every Claude Code agent that user runs.

```bash
claude mcp add --transport http --scope user xspeedhub https://app.xspeedcache.com/xspeed/mcp
```

### 3. Sign in once, or use a token

Start claude interactively as that same user, run /mcp, choose xspeedhub and approve access on the xSpeed Hub page. Claude Code keeps the credentials, so later headless runs need no browser; claude mcp get xspeedhub shows the status. On a host with no browser, add the server with the connection token from Connect AI in the Hub instead, ideally with Read-only everywhere on.

```bash
# Interactive sign-in
claude
/mcp

# Or a token, no browser
claude mcp add --transport http --scope user xspeedhub https://app.xspeedcache.com/xspeed/mcp \
  --header "Authorization: Bearer <your connection token>"
```

Full setup: https://xspeedcache.com/agent/paperclip/

### Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Paperclip's Claude Code adapter runs headless with dangerouslySkipPermissions on by default, which lets the agent call MCP tools without asking. Set it to false and a tool that needs approval does not run. A server added on the adapter does not pass through Paperclip's action permissions or review queue. A Paperclip connector does: each Hub tool is set to Allowed, Ask first or Off, and because the Hub publishes no annotations Paperclip classifies them by name, which can under-classify, so start every write Off. xSpeed Hub has no confirmation step of its own, so a write that gets past those settings runs as soon as your connection allows writes. For unattended routines, send a connection token with Read-only everywhere on, which makes the Hub refuse every write tool.

## Prompts

- Routine, twice a week: use xSpeed Hub to verify Cloudflare on every site and post failures on this task. Change nothing.
- With xSpeed Hub, purge the page cache and then the Cloudflare edge on shop, and post both results on this ticket.
- Using xSpeed Hub, list which sites have Cloudflare connected and which do not, one verify call per site.

## Example session

```
You: Ticket: use xSpeed Hub to verify Cloudflare on every site. Read only.
  → list_sites [read-only]: 3 sites: shop, blog, docs
  → cloudflare_verify(site: shop) [read-only]: Credentials and zone resolve; Cloudflare connected
  → cloudflare_verify(site: blog) [read-only]: error: verify failed, HTTP 403, Cloudflare says the token is invalid
  → cloudflare_verify(site: docs) [read-only]: error: Cloudflare is not connected on this site
Agent: Posted on the ticket: shop resolves. blog's stored token was rejected with HTTP 403, so its purges would fail too, and someone needs to update it in wp-admin. docs has no Cloudflare connection in xSpeed, which may be intended. Nothing was purged or switched.
```

## How it works

1. **Verify the connection**: cloudflare_verify calls Cloudflare's API with the credentials stored on the site and checks that the token and zone still resolve. It purges nothing and works on a read-only connection. If Cloudflare is not connected on that site, the call comes back as an error and the agent should tell you rather than retry.
2. **Purge the edge**: purge_cloudflare empties the Cloudflare edge cache for the site's zone. It does not touch the copies on your server. When Cloudflare is in front of a site, a content change usually needs both, so the agent runs purge_cache first and purge_cloudflare after it, or one purge_cache of type all, which reaches the edge when Cloudflare is connected.
3. **Turn development mode on to see origin changes**: set_cloudflare_dev_mode with enabled true bypasses the edge for about three hours, so changes on the origin show immediately. It slows the site for real visitors the whole time. Your client's prompt is the gate here, because the Hub's instructions do not name this tool in their confirm list.
4. **Turn it off when you finish**: set_cloudflare_dev_mode with enabled false switches development mode off. Cloudflare also ends it on its own after about three hours. No Hub tool reads whether it is currently on, so note when you turned it on.
5. **Read a failure**: A rejected token, an empty zone ID or a refused call comes back as an error that names the action, the HTTP status and Cloudflare's message when it gave one. It is not reported as a success. The credentials themselves are set in the xSpeed Cache panel in wp-admin, not through the Hub.

## Reference

| | |
| --- | --- |
| Read tool | cloudflare_verify; purges nothing and works on a read-only connection |
| Write tools | purge_cloudflare and set_cloudflare_dev_mode (enabled true or false) |
| Needs | Cloudflare connected in xSpeed on that site: integration on, an API token (or the legacy key and email) and a Zone ID |
| Edge purge scope | Everything Cloudflare holds for the site's zone; the server copies stay |
| Development mode | Bypasses the edge for about 3 hours, then Cloudflare switches it off |
| Token permissions | Zone Cache Purge, and Zone Settings Edit for development mode |
| What verify proves | The token and zone resolve; a token without Zone Settings Edit still verifies |
| Through purge_cache | Type all also clears the edge when Cloudflare is connected; page, assets, object and rest do not |
| Every site at once | None of the three accept site: "all"; one site per call |
| Failure shape | An error with the action, the HTTP status and Cloudflare's message |
| Read-only connection | The connection token with Read-only everywhere on, or a Viewer member's sign-in; purge_cloudflare and set_cloudflare_dev_mode are refused and cloudflare_verify works. An OAuth sign-in gets the scopes the client asks for, so the switch does not make it read-only |
| Confirmation | None on the Hub; your client's prompt is the gate |

## Rules

- Run cloudflare_verify first, but do not read a pass as proof that every call will work. A token that lacks Zone Settings Edit verifies and purges fine, then fails the first time development mode is switched.
- Purge the server and the edge together after a content change. Purging only the site leaves visitors on the old page until the edge copy expires.
- Turn development mode off as soon as you are done. It slows the site for real visitors for up to about three hours, and no tool reports its state.
- Never paste a Cloudflare token or Global API Key into the chat. Connect Cloudflare in the xSpeed Cache panel in wp-admin, and use a scoped API token rather than the Global API Key.
- purge_cloudflare and set_cloudflare_dev_mode are write tools. The Hub runs them as soon as your connection allows writes, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer member's sign-in) are the gates that matter.

## Good to know with Paperclip

The Claude Code adapter runs headless with dangerouslySkipPermissions on by default, so an agent with the Hub in its host config can call purge_cloudflare or set_cloudflare_dev_mode with no prompt, and an adapter-level server skips Paperclip's action permissions and review queue. The Hub has no confirmation step of its own, and its instructions to the agent do not list set_cloudflare_dev_mode among the tools to confirm. Give routine agents a connection token with Read-only everywhere on, which leaves cloudflare_verify working and refuses both writes. If you attach the Hub on the Connectors page instead, Paperclip classifies tools by name because the Hub publishes no annotations, and that can under-classify. Check where both Cloudflare writes landed and set them to Ask first or Off, and look again after Refresh actions, which can widen what agents may call.

## More prompts for this job

They work in any client connected to xSpeed Hub.

- Use xSpeed Hub to check that the Cloudflare connection on shop still works.
- With xSpeed Hub, purge the Cloudflare edge cache on blog.
- I changed the checkout page on shop. Use xSpeed Hub to purge the site cache and the Cloudflare edge.
- Use xSpeed Hub to turn Cloudflare development mode on for shop. I am editing the theme.
- With xSpeed Hub, turn Cloudflare development mode off on shop.
- Ask xSpeed Hub to verify Cloudflare on shop and tell me what is wrong if it fails.
- Using xSpeed Hub, which of my sites have a working Cloudflare connection? Check them one at a time.

## Frequently asked questions

### Can a Paperclip routine purge Cloudflare unattended?

It can if the agent's connection allows writes, because the Claude Code adapter skips permission prompts by default and the Hub has no confirmation step. Keep routines to cloudflare_verify and give them a connection token with Read-only everywhere on, or set the writes to Ask first or Off on a connector.

### What should the agent do when cloudflare_verify fails?

Post the site, the HTTP status and Cloudflare's message on the task and stop. The fix is in the xSpeed Cache panel in wp-admin on that site, where the Cloudflare credentials are set, not something the agent can change through the Hub.

### What does a site need before the Cloudflare tools work?

Cloudflare has to be connected in xSpeed on that site: the integration switched on, an API token (or the legacy Global API Key with your Cloudflare email) and the Zone ID of the domain. You set these in the xSpeed Cache panel in wp-admin. Without them, the tools return an error instead of acting.

### Does purging the xSpeed cache also clear Cloudflare?

A purge_cache of type all does, when the site has Cloudflare connected, and it reports each step. A page, assets, object or rest purge stays on your server. purge_cloudflare clears only the edge, so use it when the server copy is already fresh.

### How long does development mode last?

About three hours. Cloudflare switches it off on its own after that. While it is on, the edge is bypassed, so origin changes show at once and real visitors get a slower site. Turn it off yourself with set_cloudflare_dev_mode set to false when you are done.

### Why did cloudflare_verify pass but development mode failed?

Verifying and purging do not need Zone Settings Edit on the token, so a token without it looks fine. Development mode writes a zone setting, so it is refused. Edit the token in Cloudflare so it has both Zone Cache Purge and Zone Settings Edit, then try again.

### Can I purge Cloudflare on all my sites with one prompt?

Not with purge_cloudflare, which takes one site per call. A purge_cache of type all with site set to all clears the edge on each site that has Cloudflare connected, and the result is reported per site. The Hub tells the agent to confirm a write across every site with you once first.

## Manage Cloudflare with other agents

[Claude Code](https://xspeedcache.com/agent/claude-code/cloudflare/) · [Claude](https://xspeedcache.com/agent/claude/cloudflare/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/cloudflare/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/cloudflare/) · [Codex](https://xspeedcache.com/agent/codex/cloudflare/) · [Cursor](https://xspeedcache.com/agent/cursor/cloudflare/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/cloudflare/) · [Windsurf](https://xspeedcache.com/agent/windsurf/cloudflare/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/cloudflare/) · [Antigravity](https://xspeedcache.com/agent/antigravity/cloudflare/) · [Zed](https://xspeedcache.com/agent/zed/cloudflare/) · [Kiro](https://xspeedcache.com/agent/kiro/cloudflare/) · [OpenCode](https://xspeedcache.com/agent/opencode/cloudflare/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/cloudflare/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/cloudflare/) · [Grok Build](https://xspeedcache.com/agent/grok-build/cloudflare/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/cloudflare/) · [Grok](https://xspeedcache.com/agent/grok/cloudflare/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/cloudflare/) · [Muse](https://xspeedcache.com/agent/muse/cloudflare/) · [Manus](https://xspeedcache.com/agent/manus/cloudflare/) · [Kimi Code](https://xspeedcache.com/agent/kimi/cloudflare/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/cloudflare/)

## More with Paperclip

- [Purge the WordPress cache with Paperclip](https://xspeedcache.com/agent/paperclip/purge-cache/)
- [Find out why WordPress pages are not cached with Paperclip](https://xspeedcache.com/agent/paperclip/troubleshoot-cache/)
- [Scan a website for speed problems with Paperclip](https://xspeedcache.com/agent/paperclip/speed-scan/)
- [Run and track PageSpeed tests with Paperclip](https://xspeedcache.com/agent/paperclip/pagespeed-tests/)
- [Raise a WordPress site's PageSpeed score with Paperclip](https://xspeedcache.com/agent/paperclip/optimize-site/)
- [Tune WordPress cache settings with Paperclip](https://xspeedcache.com/agent/paperclip/cache-settings/)
- [Warm the WordPress cache with Paperclip](https://xspeedcache.com/agent/paperclip/preload-cache/)
- [Set up the Redis object cache with Paperclip](https://xspeedcache.com/agent/paperclip/object-cache/)
- [Manage every WordPress site at once with Paperclip](https://xspeedcache.com/agent/paperclip/fleet/)

## Documentation

- How to connect Cloudflare: https://xspeedcache.com/docs/cloudflare/
- How to serve assets from a CDN: https://xspeedcache.com/docs/cdn/
- How to enable Page Cache: https://xspeedcache.com/docs/page-cache/
