# Connect Cursor to xSpeed Hub MCP

> Add xSpeed Hub to Cursor with one mcp.json entry, sign in with OAuth, and manage your WordPress sites from the editor chat.

- Category: AI & MCP
- Updated: 2026-10-06
- Canonical: https://xspeedcache.com/docs/hub-mcp-cursor/

---

You add one entry, `xspeedhub`, to Cursor's `mcp.json`. Cursor then signs you in to xSpeed Hub with OAuth.

## Steps

### 1. Add xSpeed Hub to mcp.json

Add the server to ~/.cursor/mcp.json to have it in every project, or to .cursor/mcp.json inside a project to scope it there. The entry is just a name and a url.

File: `~/.cursor/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}
```

### 2. Enable it and sign in

Open Customize in the sidebar, find xspeedhub and make sure it is switched on. When Cursor starts the OAuth sign-in, approve access on the xSpeed Hub page. There is no token to paste. If the server shows an error, open the Output panel with Cmd+Shift+U and pick MCP Logs.

```
Customize  >  xspeedhub  (on)
```

### 3. Or send the connection token in a header (optional)

If you prefer a header to a browser sign-in, copy the connection token from Connect AI in the Hub (only the workspace owner sees it), export it as XSPEED_HUB_TOKEN in your shell profile and reference it with ${env:...}. Do not paste the token itself into a mcp.json that you commit.

File: `~/.cursor/mcp.json`

```json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp",
      "headers": {
        "Authorization": "Bearer ${env:XSPEED_HUB_TOKEN}"
      }
    }
  }
}
```

## Sign-in

**OAuth sign-in or connection token.** Cursor supports OAuth for remote servers: approve access on an xSpeed Hub page, with no token to paste. If you prefer a header, send the connection token from the Hub's Connect AI page through the headers field, read from an environment variable.

## Check it worked

```
Use xSpeed Hub to list my sites and tell me which ones have page caching turned off.
```

## A first prompt

```
Use xSpeed Hub to show the cache hit ratio for every site and flag anything under 70%.
```

## If something does not work

- Run Modes apply to local agents. Cursor says Cloud Agents never ask for approval, so do not give a Cloud Agent a write-capable Hub connection. If one must connect, send the connection token with Read-only everywhere on, or sign in as a Viewer member.
- Auto-review is a classifier model. Cursor says it can allow a call you would have blocked, so it is not a substitute for read-only access. Read-only means the connection token with Read-only everywhere on, or a Viewer member's sign-in.
- A .cursor/mcp.json that you commit is shared with your team. The URL is safe to share. A connection token is not, so keep it in an environment variable.
- Cursor's Ask Every Time mode was deprecated in version 3.5. Allowlist with an empty allowlist gives the same behavior.

More about Cursor with xSpeed, including approvals and example sessions: https://xspeedcache.com/agent/cursor/

Sources checked: [Cursor Docs: Model Context Protocol](https://cursor.com/docs/mcp), [Cursor Docs: Run Modes](https://cursor.com/docs/agent/security/run-modes)
