Why I publish every guide for free
2026-09-29
My site carries 24 guides to the standards agents use to find and act on a site, and every one of them is free to read in full. People ask me why I give away the thing I sell. The guides are reading I have to do anyway, and I would rather be caught wrong in a free guide than in a client's work.
Why not keep the guides for paying clients?
What a client pays for is my name on the result. The reading behind it is worth more in public.
When I work for a client, I answer for the implementation and the result under my own name. turva.dev is a sole proprietorship, so no company name stands between the report and me. If a recommendation is wrong because a specification moved and I missed it, the mistake is mine and the client has already paid for it.
A published guide puts the same reading in front of anyone before a client pays. Anyone can hold it up against the primary sources it cites, and a buyer can see how I understand a protocol before hiring me. I would rather a stranger find my error in a guide than a client find it on their site.
Why do I have to keep studying?
The rules I measure sites against change faster than client work arrives. If I read a specification only when a client needed it, I would be reading it on their time.
Writing a guide makes me read the primary text first, and keeping it true makes me read it again. A scheduled AI review re-reads all 24 guides against their sources on the 15th of every month, and a second run re-reads the fastest-moving ones on the 1st. A second check reads each finding against the source before anything on the site changes, and each guide page shows the date its sources were last checked.
What changed in the last two months?
Three specifications I build my site on released new versions between late July and late August, and the review on 15 September found four more claims that had gone stale.
On 28 July the Model Context Protocol released its 2026-07-28 revision, the largest breaking set it has had. It removed protocol sessions and the initialize handshake, made the protocol stateless, required servers to answer a new server/discover call and deprecated OAuth Dynamic Client Registration, which stays a supported fallback for now. I had built my own MCP server on a library path that would never serve the new revision, so the update was a rewrite and not a version bump. It went live the next morning. The next day I found that a request on the new revision needs its protocol version and method as headers, and on 1 August that a tool call needs the tool's name as a header too. I found both by measuring my own client, not by reading.
On 10 August llms.txt published its second version. The file format did not change at all. What changed is discovery: a page can now name its Markdown version and the llms.txt that covers it, in the HTML head or in an HTTP Link header. On 24 August I made every page on my site answer at its own .md address and pointed every link in my llms.txt at those addresses.
On 26 August the Agentic Resource Discovery draft, version 0.91, renamed its well-known file from ai-catalog.json to ard.json and said a conformant client must read the new path. The scanner I measure with still read the old path when I added the new one, so my site serves both.
What did the September review find?
It found four claims in my guides that had moved since the previous read, and all four corrections are on the site.
The ARD repository now carries a versioned draft, and a normative change starts as an issue. The x402 payment protocol's repository moved from Coinbase to the x402 Foundation, which sits under the Linux Foundation, and my x402 guide still linked the old address. Work on AP2, the agent payments protocol, continues in FIDO Alliance working groups. The Google page three of my guides cited no longer carried the sentence they attributed to it, and the same guidance now sits on another Google page, which the guides link instead.
What did the review get wrong?
It flagged a fifth claim that was true. My agent commerce guide says that ACP's discovery document entered the released specification with the 2026-04-17 snapshot, and the review found ACP's own RFC file still marked as a proposal.
I had already approved the correction. On the day it was to go in, the measurement read ACP's changelog for that snapshot and its published schema, and both show the discovery document released. Only the RFC file's status header had never been updated. Making the approved correction would have turned a true sentence on my site into a false one.
What happens when nothing has changed?
Every guide still gets a full read. The run on 1 September re-read the seven fastest-moving guides, found no errors and changed two date stamps. I only know nothing had moved because the reading was done.
What does this not show?
It does not show that the guides are free of errors. The review is an AI run. In September it flagged a true sentence as false, and it can pass a false one as easily.
These are the changes that touched my own site and guides. The field moved in more places than that, and a guide covers only what I chose to write about.
Frequently asked
Are the guides the same material you use in client work?
Yes. I write them from the primary sources I measure client sites against, and a guide is where that reading ends up in public. A client report adds what a guide cannot: the measurements of that one site, what to fix in which order, and who owns each fix.
How often are the guides checked?
Every guide is re-read against its primary sources once a month, and the fastest-moving ones get a second read at the start of each month. Each guide page shows the date of its last check.
What happens when a guide turns out to be wrong?
The guide is corrected, and the date of its last check moves. A blog post that was wrong gets a dated note at its end saying what was wrong and what changed.
Corrected 2026-09-29. One sentence said the reading costs the same when nothing has changed. The review runs record no durations, so the sentence now says what they do record: every guide still gets a full read.