# Windsurf + xSpeed: Manage WordPress Caching

> Windsurf, which now ships as Devin Desktop, is an AI editor from Cognition, and with xSpeed Hub added as an MCP server its agent can read cache status, purge, change settings and run speed tests on your WordPress sites. You add one server, sign in once, and ask from the agent panel.

Page: https://xspeedcache.com/agent/windsurf/
Last updated: October 2026

- One command adds the Hub for the Devin Local agent; legacy Cascade takes a serverUrl entry instead
- Devin Local prompts before it calls an MCP tool, and you can allow one tool or the whole xspeedhub server
- Every site you connected to the Hub is reachable from the same editor session

## How do I connect Windsurf to xSpeed?

### 1. Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

### 2. Add xSpeed Hub for the Devin Local agent

Run this in a terminal. Devin Local shares its MCP configuration with Devin CLI, and -s user saves the server to ~/.config/devin/mcp_config.json (%APPDATA%\devin\mcp_config.json on Windows) so it applies to every project. Without -s, the command saves to local scope, which is the current project only.

```bash
devin mcp add -s user xspeedhub https://app.xspeedcache.com/xspeed/mcp
```

### 3. Sign in

Run the login command and approve access on the xSpeed Hub page that opens in your browser. There is no token to paste, and the client keeps the credentials it receives. If the server later shows Needs auth in the Devin Local MCP list, click Authenticate, or run devin mcp logout and then login again.

```bash
devin mcp login xspeedhub
```

### 4. Legacy Cascade agent, or a connection token (alternative)

Cascade reads the same kind of file but names the remote address serverUrl. Open the Cascade panel, click the ... Actions menu and choose the MCP config file, then add the entry. To use the connection token instead of a browser sign-in, add a headers object with Authorization set to Bearer and your token; both agents accept headers. Only the workspace owner sees the token, on the Hub's Connect AI page.

File: `~/.config/devin/mcp_config.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "serverUrl": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

**Authentication:** OAuth sign-in or connection token. Run devin mcp login xspeedhub and approve access in the browser; the client stores the tokens locally and refreshes them. If you prefer a header, add the connection token from the Hub's Connect AI page under headers in the server entry.

**Check it worked:** ask "Use xSpeed Hub to list my sites and show whether page caching is on for each one."

## Does Windsurf ask before it changes my site?

The Devin Local agent prompts for approval before it calls any MCP tool. In the prompt you can allow that one tool or every tool on the xspeedhub server, for this session or permanently, and permission rules such as mcp__xspeedhub__get_cache_status allow, deny or always ask for a named tool. Smart mode lets a fast model run what it judges safe without a prompt, and Bypass mode approves everything, so with either of those a write reaches the Hub as soon as your connection allows writes. xSpeed Hub has no confirmation step of its own.

xSpeed Hub has no confirmation step of its own. Read tools change nothing on your sites, with one exception to know about: contact_support sends an email to xSpeed support, and a read-only connection can still call it. A write tool (a purge, a settings change, a cache toggle, or a speed test that spends the shared allowance) runs as soon as your connection allows writes. Three things stand between a prompt and a change: your connection's scope, because a read-only connection refuses every write tool (the connection token has a Read-only everywhere switch, and a Viewer member only ever gets read access); your AI client's own tool-approval prompt; and the Hub's instructions to the agent, which tell it to confirm the target site and to ask once before a write that touches every site.

## Example session

```
You: Using xSpeed Hub, is the shop preloader still running? If it finished, check how warm the cache is.
  → get_preloader_status(site: shop) [read-only]: finished, 340 of 340 URLs warmed
  → get_cache_status(site: shop) [read-only]: page cache on, 340 cached pages, hit ratio 64% in the last 24h
Agent: The preloader finished and all 340 URLs are cached. The hit ratio over the last day is 64%. Want a cached versus uncached timing on shop?
You: Yes, run it.
  → run_benchmark(site: shop) [read-only]: cached 38 ms, uncached 412 ms (server response time, no Lighthouse score)
Agent: A cached page answers in 38 ms against 412 ms uncached. That is server response time only; run a PageSpeed test if you want a score.
```

## What is Windsurf?

Windsurf is an AI code editor that now ships as Devin Desktop. New tabs start with the Devin Local agent, and the older Cascade agent stays available for existing conversations.

MCP, the Model Context Protocol, is how both agents reach services outside your machine. Adding xSpeed Hub as a remote HTTP server gives them the Hub's caching tools: status, purge, settings, preloader, object cache, Cloudflare and speed tests, for every site in your workspace.

## Why use Windsurf with xSpeed?

- **Prompt-by-default in Devin Local**: Devin Local asks before it calls an MCP tool, and the permission rules let you allow single xSpeed reads while every write keeps asking.
- **Terminal and editor share one setup**: Devin Local shares its MCP configuration with Devin CLI, so the commands that add and sign in the server are ones you may already use in a terminal.
- **The whole fleet from one tab**: The Hub fronts every site you connected. Ask about one site by name, or ask a question that spans all of them and read the per-site result.

## Good to know

- The name changed. docs.windsurf.com now redirects to the Devin documentation, and the editor is Devin Desktop. Menu labels and package names may still say Windsurf in places.
- Without -s user, devin mcp add saves to local scope, which is the current project only, so the server looks missing in other projects.
- Each MCP client keeps its own OAuth session. Signing in to xSpeed Hub from another tool does not sign in Devin, and you run devin mcp login separately.
- Cascade can use at most 100 tools at a time across all servers. xSpeed Hub adds 29.

## Prompts to try

- With xSpeed Hub, show page cache status and hit ratio for every site, and flag anything under 70%.
- Use xSpeed Hub to purge the blog cache, then start the preloader and report how many URLs it queued.
- Use xSpeed Hub to run a mobile PageSpeed test on shop and compare it with the stored score history.
- Ask xSpeed Hub to preview a safe optimize_site pass on docs. Do not apply it.
- Using xSpeed Hub, tell me whether Cloudflare is connected on shop before you purge anything.

## What can Windsurf do with xSpeed?

- [Purge the WordPress cache with Windsurf](https://xspeedcache.com/agent/windsurf/purge-cache/): Clear stale pages after a deploy, an edit or a plugin update, on one site or all of them.
- [Find out why WordPress pages are not cached with Windsurf](https://xspeedcache.com/agent/windsurf/troubleshoot-cache/): Work out why a site misses the cache, serves slow pages or shows a low hit ratio, using read-only checks first.
- [Scan a website for speed problems with Windsurf](https://xspeedcache.com/agent/windsurf/speed-scan/): Get a graded speed report with the fix for every failing check and a link you can share, for your own site or any public URL.
- [Run and track PageSpeed tests with Windsurf](https://xspeedcache.com/agent/windsurf/pagespeed-tests/): Read the PageSpeed scores a site already has, run a new test when something changed, and tell a Lighthouse score from a cache benchmark.
- [Raise a WordPress site's PageSpeed score with Windsurf](https://xspeedcache.com/agent/windsurf/optimize-site/): Preview and apply xSpeed's recommended settings to a site, check the pages still work, and be told plainly what caching cannot fix.
- [Tune WordPress cache settings with Windsurf](https://xspeedcache.com/agent/windsurf/cache-settings/): See which modules a site has, read their current settings, change them, and turn page caching on or off.
- [Warm the WordPress cache with Windsurf](https://xspeedcache.com/agent/windsurf/preload-cache/): Fill the page cache before visitors arrive, for example right after a purge or a deploy.
- [Set up the Redis object cache with Windsurf](https://xspeedcache.com/agent/windsurf/object-cache/): Connect a site to Redis or Memcached so database results survive between requests.
- [Manage Cloudflare caching with Windsurf](https://xspeedcache.com/agent/windsurf/cloudflare/): Check the Cloudflare connection, clear the edge cache and switch development mode on or off for a site.
- [Manage every WordPress site at once with Windsurf](https://xspeedcache.com/agent/windsurf/fleet/): Run one action across all of your sites, or a chosen few, and read the result site by site.

## Which way should I connect?

| Surface | Endpoint | Reaches | Auth | Tools |
| --- | --- | --- | --- | --- |
| [xSpeed Hub MCP](https://xspeedcache.com/docs/hub-mcp/) | `https://app.xspeedcache.com/xspeed/mcp` | Every site in your workspace, one connection | OAuth sign-in in the browser, or a connection token in an Authorization header | 29 tools (16 read, 13 write), seven of them can act on every site at once |
| [xSpeed Cache Site MCP](https://xspeedcache.com/docs/mcp-server/) | `https://your-site.com/xspeed/mcp` | One WordPress site | OAuth sign-in by a site admin, or the site's own token in an Authorization header | The full per-site tool set plus run_command for the WP-CLI surface |
| [xSpeed Scan MCP](https://xspeedcache.com/docs/scan-mcp/) | `https://xspeedcache.com/scan/mcp` | Any public URL, read-only | None. No account. | 5 tools: run_speed_scan, get_speed_scan and three product-info tools |
| [WP-CLI](https://xspeedcache.com/docs/wp-cli-commands/) | `wp xspeed …` | The site whose server the agent has a shell on | Your server login | Every xSpeed command: cache, purge, preloader, objcache, cf, score, settings and more |

## Frequently asked questions

### Is Windsurf now Devin Desktop?

Yes. The Windsurf documentation now redirects to the Devin documentation, which calls the editor Devin Desktop. Its primary agent is Devin Local, and the earlier Cascade agent remains for existing conversations. The steps on this page cover both.

### How do I add xSpeed Hub to Windsurf?

For the Devin Local agent, run devin mcp add -s user xspeedhub https://app.xspeedcache.com/xspeed/mcp, then devin mcp login xspeedhub and approve access in the browser. For the legacy Cascade agent, add an xspeedhub entry with a serverUrl field to its mcp_config.json file.

### Do I need an API key?

No. The client signs in to the Hub with OAuth, registers itself automatically and keeps the credentials it receives. If you prefer a header, the workspace owner can copy the connection token from the Hub's Connect AI page and add it under headers in the server entry.

### Will the agent change my site without asking?

Devin Local prompts before it calls any MCP tool by default, and you can allow a single tool or the whole server. The Hub has no confirmation step of its own, so a tool you have allowed, or Smart or Bypass mode, lets a write run without a prompt. Allow reads, keep writes on a prompt. For read-only access, send the connection token with Read-only everywhere on, or sign in as a Viewer member.

### Which tools does Windsurf get from xSpeed Hub?

The 29 tools of the xSpeed Hub MCP server. Sixteen only read. Thirteen change a site or spend the shared speed-test allowance. In permission rules their names take the form mcp__xspeedhub__ followed by the tool name.

### Does it work without the Hub?

Yes. The xSpeed Cache plugin has its own MCP server at your-site.com/xspeed/mcp, and you add it the same way under a different name. The Hub is the better fit once you have more than one site.

### How do I disconnect it?

Run devin mcp logout xspeedhub to remove the stored sign-in, and devin mcp remove xspeedhub to delete the server. Rotating or disconnecting the connection token in the Hub revokes only clients that send that token, so it does not end an OAuth sign-in; that is removed in Windsurf.

## Also works with

[Claude Code](https://xspeedcache.com/agent/claude-code/) · [Claude](https://xspeedcache.com/agent/claude/) · [Claude Cowork](https://xspeedcache.com/agent/claude-cowork/) · [ChatGPT](https://xspeedcache.com/agent/chatgpt/) · [Codex](https://xspeedcache.com/agent/codex/) · [Cursor](https://xspeedcache.com/agent/cursor/) · [GitHub Copilot in VS Code](https://xspeedcache.com/agent/github-copilot/) · [Gemini CLI](https://xspeedcache.com/agent/gemini-cli/) · [Antigravity](https://xspeedcache.com/agent/antigravity/) · [Zed](https://xspeedcache.com/agent/zed/) · [Kiro](https://xspeedcache.com/agent/kiro/) · [OpenCode](https://xspeedcache.com/agent/opencode/) · [OpenClaw](https://xspeedcache.com/agent/openclaw/) · [Hermes Agent](https://xspeedcache.com/agent/hermes-agent/) · [Grok Build](https://xspeedcache.com/agent/grok-build/) · [ChatGPT dots](https://xspeedcache.com/agent/chatgpt-dots/) · [Grok](https://xspeedcache.com/agent/grok/) · [Grok Bot](https://xspeedcache.com/agent/grok-bot/) · [Muse](https://xspeedcache.com/agent/muse/) · [Manus](https://xspeedcache.com/agent/manus/) · [Kimi Code](https://xspeedcache.com/agent/kimi/) · [Paperclip](https://xspeedcache.com/agent/paperclip/) · [NanoClaw](https://xspeedcache.com/agent/nanoclaw/)

## Sources

- Devin Desktop: Cascade MCP integration (legacy Cascade agent): https://docs.devin.ai/desktop/cascade/mcp
- Devin Desktop: Devin Local agent: https://docs.devin.ai/desktop/devin-local
- Devin CLI: MCP configuration: https://docs.devin.ai/cli/extensibility/mcp/configuration
- Devin CLI: Permissions: https://docs.devin.ai/cli/reference/permissions
- Devin Desktop: Welcome: https://docs.devin.ai/desktop/getting-started
