Category

Web standards

  1. 5 min

    Personal Agent Protocol is an OAuth session, but its v0.1 specification is not published

    PAP uses one OAuth session across web, API, and company-agent routes, but its v0.1 specification and payment extensions are not published.

  2. 6 min

    WebMCP reaches the browser agent. A remote MCP reaches the CLI.

    WebMCP gives browser agents client-side tools in Chrome 149, while a remote Streamable HTTP MCP server gives CLI agents direct search without scraping.

  3. 6 min

    A Web Bot Auth signature names a key directory, not a person you should auto-publish

    A Web Bot Auth signature proves that a host published the signing key, not that the agent is honest, authorized, or suitable for automated publication.

  4. 4 min

    Why a remote MCP server answers 405 after the 2026-07-28 revision

    A legacy SSE fallback sends GET to a POST-only 2026-07-28 MCP endpoint, so its 405 can hide an earlier connection failure.

  5. 5 min

    How AI agents sign HTTP requests with Web Bot Auth

    Web Bot Auth uses RFC 9421 signatures and a published key directory so sites can verify signed agent requests.

  6. 4 min

    llms.txt and llms-full.txt: what they are, who reads them, and how to generate them

    llms.txt is a Markdown index IDE agents and MCP servers fetch to navigate a site; llms-full.txt embeds the full text. AI search bots largely ignore both.

  7. 5 min

    Cloudflare Content Signals in robots.txt: what search, ai-input, and ai-train mean

    Content-Signal in robots.txt lets site owners declare whether crawlers may use content for search indexing, AI retrieval/grounding, or model training.

  8. 6 min

    How to pass every isitagentready.com check for a content site

    Passing the seven isitagentready.com content checks requires a valid robots.txt, sitemap, Link headers, markdown negotiation, Content Signals, and DNS-AID.