How Paperclip handles this
Paperclip suits an agency that already thinks in tickets. You run a team of agents, one of them a Claude Code agent with the Hub added on its host, and fleet maintenance becomes work you assign. A ticket says to clear and warm every client site after Thursday's plugin update. The agent calls purge_cache with site set to "all", then start_preloader, and posts the per-site result on the task: which sites cleared, which did not, and the error for each failure. You read it in the Paperclip dashboard beside everything else the team did that day.
Routines give you the recurring version. A routine fires on a cron schedule, creates a task and wakes the agent you assign, and timer heartbeats stay off until you turn them on. The Hub has no scheduler for agent prompts, so the cron is Paperclip's. A weekly routine that runs run_benchmark across every site is a sound choice, because that tool is a read and changes nothing. The other six fan-out tools (purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader and optimize_site) write, and a routine runs with nobody watching.
Which gate applies depends on how the agent reaches the Hub. Added with claude mcp add on the host, the server does not pass through Paperclip's action permissions or review queue, and the Claude Code adapter runs headless with dangerouslySkipPermissions on by default, so a fleet purge runs as soon as the agent decides to. Set it to false and a tool that needs approval does not run. Attached on the Connectors page instead, each Hub tool is set to Allowed, Ask first or Off. xSpeed Hub has no confirmation step of its own; its instruction to confirm once before a fleet-wide purge, toggle, settings or preloader call reaches the agent as text, and it does not name optimize_site.
Set up Paperclip once
Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Paperclip guide.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub to the agent Paperclip runs
For a Claude Code agent, run this on the machine that hosts it, as the same OS user the Paperclip heartbeat runs as. Paperclip's docs say MCP wiring lives at the adapter and runtime layer, and user scope makes the Hub available to every Claude Code agent that user runs.
claude mcp add --transport http --scope user xspeedhub https://app.xspeedcache.com/xspeed/mcp
3Sign in once, or use a token
Start claude interactively as that same user, run /mcp, choose xspeedhub and approve access on the xSpeed Hub page. Claude Code keeps the credentials, so later headless runs need no browser; claude mcp get xspeedhub shows the status. On a host with no browser, add the server with the connection token from Connect AI in the Hub instead, ideally with Read-only everywhere on.
# Interactive sign-in claude /mcp # Or a token, no browser claude mcp add --transport http --scope user xspeedhub https://app.xspeedcache.com/xspeed/mcp \ --header "Authorization: Bearer <your connection token>"
Full Paperclip setup, sign-in options and FAQ
Before you send a prompt that changes something
Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Paperclip's Claude Code adapter runs headless with dangerouslySkipPermissions on by default, which lets the agent call MCP tools without asking. Set it to false and a tool that needs approval does not run. A server added on the adapter does not pass through Paperclip's action permissions or review queue. A Paperclip connector does: each Hub tool is set to Allowed, Ask first or Off, and because the Hub publishes no annotations Paperclip classifies them by name, which can under-classify, so start every write Off. xSpeed Hub has no confirmation step of its own, so a write that gets past those settings runs as soon as your connection allows writes. For unattended routines, send a connection token with Read-only everywhere on, which makes the Hub refuse every write tool.
What do I ask?
Three prompts written for Paperclip. More for this job are below.
Weekly routine: use xSpeed Hub to benchmark every site and post one line per site on this task. Report only.
Ticket: with xSpeed Hub, purge every client site after the plugin update and list the failures here.
Use xSpeed Hub to list the workspaces this agent can reach and the site count in each, without calling any write tool.
What happens, step by step
If you run many WordPress sites, repeating one action on each is the slow part. Through xSpeed Hub, seven tools accept every site in a workspace, or a list of handles, in a single call. The Hub runs the sites one after another and returns a result for each, so a site that fails is named instead of hidden. Everything else in the Hub works on one site per call.
01
See what you can reach
list_sites returns each site's handle, URL, status and scopes. When you have more than one workspace, list_workspaces returns each one's handle, id, your role, its site count, which one is the default, and whether this connection can reach it.
02
Choose the scope of the call
The agent passes site: "all" for every site in one workspace, or an array of handles for exactly those sites. For a workspace other than the default it also passes the workspace argument. Omit workspace and the call acts on the default workspace.
03
Confirm once
Before a purge, toggle, settings change or preloader call that touches every site, the Hub tells the agent to say "this will touch all N sites" and wait for you, then make one call. That instruction does not name optimize_site, so for it your client's prompt is the gate. It is guidance to the agent, not a lock. It is one tool call, so one approval in your client covers every site in it.
04
Run it as one call
The Hub runs the sites one after another with a one-second pause between live calls, so a fleet purge is not a burst of traffic at your servers. Revoked sites are skipped from "all". Each site's action lands in the activity log as its own row.
05
Read the result per site
The reply is a summary of targets, succeeded and failed, plus one row per site with ok and either its data or its error. Some sites failing is a partial success. Only a run where every site failed comes back as an error.
06
Follow up on the failures
The agent reports which sites failed and why, then retries just those handles with an array. Tools that read one site, such as get_cache_status and get_health, do not fan out, so a fleet-wide check means one call per site.
Reference
| Fan-out tools | purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader, optimize_site, run_benchmark |
|---|---|
| Selector | site: "all", or an array of handles |
| What all covers | Every site this connection can see in one workspace, minus revoked ones |
| Pacing | One after another, with a 1 second pause between live calls |
| Result | summary (targets, succeeded, failed) and a row per site: ok, then data or error |
| Partial failure | Reported per site; the call counts as an error only when every site failed |
| Workspace argument | Optional. Omit it for the default workspace; name one by its handle or id from list_workspaces |
| Reach | Fixed when you approve the connection; list_workspaces shows reachable: false for the rest |
| Not fan-out | get_health, get_cache_status and every other tool take one site per call |
| Slow tools | optimize_site takes up to 2 minutes per site; a target_score run is capped at 12 rounds per call |
| Read-only | The connection token with Read-only everywhere on, or a Viewer sign-in, refuses every fan-out write; run_benchmark works. An OAuth sign-in gets the scopes the client asks for |
| Hub daily pass | Re-verifies sites, snapshots cache status and hit ratio, reads stored reports, alerts by Slack webhook or email |
Rules worth keeping
- Confirm once, then call once. The Hub has no confirmation step of its own, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates that matter. The Hub's "this will touch all N sites" is an instruction to the agent for purge, toggle, settings and preloader calls, and it does not name optimize_site.
- "all" is one workspace, never every workspace. To act in another workspace, name it. A write to a non-default workspace must name it, and an array of handles is looked up only in the workspace the call names.
- Read every result per site. Treat some sites failing as a partial result, and never accept a blanket "done" from the agent.
- Try a behaviour change on one site before you send it to the fleet. toggle_cache and update_settings on every site are one call, and each site checks values against its own settings, so a Pro setting can fail on a Free site.
- optimize_site on many sites is slow, because each site can take up to two minutes inside one call. Use dry_run first, or name a short list of handles.
- The Hub has no scheduler for agent prompts. Its own daily pass and alerts run without an agent, and an agent can only act when you send a prompt or your AI client runs one on a timer.
Good to know with Paperclip
The Hub publishes no tool annotations, so on the Connectors page Paperclip classifies its tools by name, and Paperclip says that fallback can under-classify. Start every Hub write Off, promote purge_cache or start_preloader to Ask first when a ticket needs them, and use Refresh actions with care, since it can widen what agents may call. For the adapter route, give routines a connection token with Read-only everywhere on: the Hub then refuses every fan-out write from that agent, and run_benchmark still works. User scope in Claude Code is shared by every Claude Code agent that OS user runs, so each of them reaches every site in the workspace. If only one agent should handle fleet work, run it as a dedicated OS user. Name the workspace on any ticket for a client workspace, because "all" covers one.
More prompts for this job
They work in any client connected to xSpeed Hub.
Use xSpeed Hub to list every site I can reach, and every workspace, and say which workspace you act in by default.
With xSpeed Hub, purge the cache on every site in my workspace and tell me which ones failed.
Use xSpeed Hub to run a benchmark on all my sites and rank them by cached response time.
Use xSpeed Hub to start the preloader on blog, shop and docs only.
With xSpeed Hub, turn page caching on for every site where it is off. Check each site first.
Use xSpeed Hub to stop the preloader everywhere. The servers are busy.
Ask xSpeed Hub to preview a safe optimize_site pass on every site with dry_run and summarize what it would change.
Use xSpeed Hub to purge every site in the client-acme workspace, not my default one.
Frequently asked questions
Keep going
Manage every site at once with other agents
More with Paperclip
Documentation
- Managing your fleet with xSpeed Hub
- Teams, roles and workspaces in xSpeed Hub
- Scoped AI connections in xSpeed Hub
- Connecting to xSpeed Hub
- How to write prompts for xSpeed Hub
- Paperclip + xSpeed
- Every AI agent that works with xSpeed
From the blog