# Polycode Limited — marginalia > Polycode Limited is a UK information-technology consultancy (Companies House 10172940, Leeds, incorporated 2016) that operates marginalia, a small public chat experiment built on a shared, provenance-tracked memory graph. marginalia exposes a public REST API (OpenAPI 3.0.3, 50 operations, no key required for reads and chat), an A2A 0.3.0 agent card with a live JSON-RPC endpoint, an OpenAI-shaped mechanical completion shim, and an AGPL-3.0 source repository. Chat, memory recall and research projects are the three published skills. Writes to the shared graph are public and licensed CC-BY-SA 4.0; a `volatile` flag keeps a turn out of shared memory. Generated by API Evangelist from the catalog record and the provider's own published surface; the provider serves no /llms.txt of its own (probed 2026-09-19: 403). ## APIs - [marginalia public API](https://marginalia.polycode.co.uk/developers): Public read + chat REST API under https://marginalia.polycode.co.uk/api — async chat with task polling, graphs, sessions, insights, projects, usage and budget, key-authed private graphs. - [marginalia A2A Agent](https://marginalia.polycode.co.uk/.well-known/agent-card.json): Agent2Agent JSON-RPC endpoint at https://marginalia.polycode.co.uk/api/a2a (message/send, message/stream, tasks/get); skills: open chat, recall memory, research projects. ## Specs - [OpenAPI 3.0.3 (provider-hosted)](https://marginalia.polycode.co.uk/api/openapi.json): The generated contract, info.version 0.1.7, servers https://marginalia.polycode.co.uk. - [OpenAPI (catalog copy)](https://raw.githubusercontent.com/api-evangelist/polycode-co-uk/refs/heads/main/openapi/polycode-co-uk-marginalia-openapi.json): Verbatim copy fetched 2026-09-19. - [A2A Agent Card](https://marginalia.polycode.co.uk/.well-known/agent-card.json): protocolVersion 0.3.0, JSONRPC, version 0.2.0; legacy copy at /.well-known/agent.json. ## Docs - [Developers page](https://marginalia.polycode.co.uk/developers): Running model, deployed commit, Swagger UI at /developers/api (client-rendered). - [README — Talk to it: the A2A API](https://gitlab.com/polycode-projects/marginalia/-/blob/main/README.md): message/send and message/stream examples, contextId reuse, x-api-key for private graphs, the mechanical completions shim, the consumer CLI. - [ETHICS.md — visitor rights](https://gitlab.com/polycode-projects/marginalia/-/blob/main/_developers/ETHICS.md): UK GDPR access/rectification/erasure by email to antony@polycode.co.uk with the session UUID; redact-at-ingest privacy policy; AI output disclaimer; CC-BY-SA 4.0 on contributions. - [NEXT.md — living handover and open items](https://gitlab.com/polycode-projects/marginalia/-/blob/main/NEXT.md): The project's forward-looking work list. - [Source repository (AGPL-3.0-only)](https://gitlab.com/polycode-projects/marginalia): Application, infrastructure, CLI and tests. ## Conventions - Auth: none for public reads and chat; optional `X-API-Key` header routes to a private graph; account features (key minting, private graphs) need a Google login via Amazon Cognito at /auth/login. - Chat is asynchronous: POST /api/chat returns a task id; poll GET /api/chat/result?task=... until completed or failed. Reuse `sessionUuid` to keep context. - `volatile: true` on /api/chat (or --volatile in the CLI) keeps a turn out of the shared memory graph. - Errors are a JSON object `{"error": ""}` (401 login required / send the key as X-API-Key; 400 bad request; 404 not found with path and method). JSON-RPC errors follow JSON-RPC 2.0 (-32600, -32601, -32001). - Spend is capped per UTC day and per session; GET /api/budget and GET /api/status expose the caps live. No rate-limit headers are returned. - Anything sent to the shared graph is stored, PII-redacted at ingest, and republished under CC-BY-SA 4.0. Do not send personal data about others. ## Optional - [Catalog record (apis.json)](https://raw.githubusercontent.com/api-evangelist/polycode-co-uk/refs/heads/main/apis.yml) - [a2aregistry.org listing](https://a2aregistry.org/): Where the agent card was first seen.