Connect Cursor to xSpeed Hub MCP
Add xSpeed Hub to Cursor with one mcp.json entry, sign in with OAuth, and manage your WordPress sites from the editor chat.
You add one entry, xspeedhub, to Cursor’s mcp.json. Cursor then signs you in to xSpeed Hub with OAuth.
Before you start
You need a free xSpeed Hub account with at least one site connected. Connect your sites to xSpeed Hub first if you have not.
Steps
-
Add xSpeed Hub to mcp.json
Add the server to ~/.cursor/mcp.json to have it in every project, or to .cursor/mcp.json inside a project to scope it there. The entry is just a name and a url.
{ "mcpServers": { "xspeedhub": { "url": "https://app.xspeedcache.com/xspeed/mcp" } } } -
Enable it and sign in
Open Customize in the sidebar, find xspeedhub and make sure it is switched on. When Cursor starts the OAuth sign-in, approve access on the xSpeed Hub page. There is no token to paste. If the server shows an error, open the Output panel with Cmd+Shift+U and pick MCP Logs.
Customize > xspeedhub (on)
Sign-in
OAuth sign-in or connection token. Cursor supports OAuth for remote servers: approve access on an xSpeed Hub page, with no token to paste. If you prefer a header, send the connection token from the Hub's Connect AI page through the headers field, read from an environment variable.
Alternative
Or send the connection token in a header
If you prefer a header to a browser sign-in, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), export it as XSPEED_HUB_TOKEN in your shell profile and reference it with ${env:...}. Do not paste the token itself into a mcp.json that you commit.
{
"mcpServers": {
"xspeedhub": {
"url": "https://app.xspeedcache.com/xspeed/mcp",
"headers": {
"Authorization": "Bearer ${env:XSPEED_HUB_TOKEN}"
}
}
}
} Check it worked
Ask Cursor this. It only reads, so nothing changes on your sites.
Use xSpeed Hub to list my sites and tell me which ones have page caching turned off.
A first prompt
Use xSpeed Hub to show the cache hit ratio for every site and flag anything under 70%.
If something does not work
- Run Modes apply to local agents. Cursor says Cloud Agents never ask for approval, so do not give a Cloud Agent a write-capable Hub connection. If one must connect, send the connection token with Read-only everywhere on, or sign in as a Viewer member.
- Auto-review is a classifier model. Cursor says it can allow a call you would have blocked, so it is not a substitute for read-only access. Read-only means the connection token with Read-only everywhere on, or a Viewer member's sign-in.
- A .cursor/mcp.json that you commit is shared with your team. The URL is safe to share. A connection token is not, so keep it in an environment variable.
- Cursor's Ask Every Time mode was deprecated in version 3.5. Allowlist with an empty allowlist gives the same behavior.