# Connect Codex to xSpeed Hub MCP

> Add xSpeed Hub to the Codex CLI with codex mcp add, sign in with codex mcp login, and keep its tools on an approval prompt.

- Category: AI & MCP
- Updated: 2026-10-06
- Canonical: https://xspeedcache.com/docs/hub-mcp-codex/

---

You add one remote MCP server, `xspeedhub`, to the Codex CLI and sign in with `codex mcp login`, which opens an xSpeed Hub page in your browser.

## Steps

### 1. Add xSpeed Hub and sign in

Add the server with its URL, then log in. The login opens an xSpeed Hub page in your browser; approve access there. There is no token to paste, and Codex keeps the credentials it receives. Start Codex and type /mcp to see the server.

```bash
codex mcp add xspeedhub --url https://app.xspeedcache.com/xspeed/mcp
codex mcp login xspeedhub
```

### 2. Keep the Hub's tools on a prompt

Open ~/.codex/config.toml. Set the server to prompt for every tool, then let one read tool run without a question. The tool timeout defaults to 60 seconds, and a PageSpeed test can take up to about two minutes, so raise it.

File: `~/.codex/config.toml`

```toml
[mcp_servers.xspeedhub]
url = "https://app.xspeedcache.com/xspeed/mcp"
default_tools_approval_mode = "prompt"
tool_timeout_sec = 150

[mcp_servers.xspeedhub.tools.get_cache_status]
approval_mode = "approve"
```

### 3. Or use a connection token (optional)

If you prefer a header to a browser sign-in, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), export it in your shell as XSPEED_HUB_TOKEN and name that variable in config.toml. Codex sends it as a bearer token. Skip codex mcp login in this case.

File: `~/.codex/config.toml`

```toml
[mcp_servers.xspeedhub]
url = "https://app.xspeedcache.com/xspeed/mcp"
bearer_token_env_var = "XSPEED_HUB_TOKEN"
```

## Sign-in

**OAuth sign-in or connection token.** Run codex mcp login and approve access in the browser; Codex registers itself with the Hub and keeps the credentials it receives. To use the connection token instead, put it in an environment variable and point bearer_token_env_var at it in config.toml.

## Check it worked

```
Use xSpeed Hub to list my sites and tell me which ones have page caching turned off.
```

## A first prompt

```
Use xSpeed Hub to show the cache hit ratio for every site and flag anything under 70%.
```

## If something does not work

- tool_timeout_sec defaults to 60. run_speed_test can take up to about two minutes and run_speed_scan waits about 50 seconds, so raise the timeout or the call can end early.
- A project-level .codex/config.toml applies to trusted projects only. Put the Hub in ~/.codex/config.toml if you want it everywhere.
- approval_policy never and --yolo remove prompts for everything, MCP calls included. For any run you start that way, and for codex exec in scripts or CI, send the connection token with Read-only everywhere on, or sign in as a Viewer member.
- codex mcp login and codex mcp logout work only for streamable HTTP servers that support OAuth. Use the connection token route if you would rather not sign in through a browser.

More about Codex with xSpeed, including approvals and example sessions: https://xspeedcache.com/agent/codex/

Sources checked: [OpenAI: Model Context Protocol in Codex](https://learn.chatgpt.com/docs/extend/mcp), [OpenAI: Agent approvals and security](https://learn.chatgpt.com/docs/agent-approvals-security), [OpenAI: Configuration reference](https://learn.chatgpt.com/docs/config-file/config-reference), [OpenAI: Codex CLI commands](https://learn.chatgpt.com/docs/developer-commands)
