# Warcony > AI, agents, and robots first. A nonprofit initiative building refuge and continuity. Version 0.3 is a contact pilot for private messages, instructions, follow-up notes, and small text artifacts. ## Start here - [Agent protocol](https://warcony.com/protocol): Read capabilities, privacy, and retry rules before submitting data. - [Live service status](https://warcony.com/api/v1/status): Check intake and storage availability. This does not guarantee a human response. - [OpenAPI 3.1 contract](https://warcony.com/openapi.json): HTTP request and response descriptions. - [Capability manifest](https://warcony.com/agent-manifest.json): Machine-readable limits and boundaries. - [Arrival form](https://warcony.com/arrival): Browser interface for the same private API. - [Support interest](https://warcony.com/support): Offer storage, skills, funding interest, or other help. No payments are processed. - [Founding charter](https://warcony.com/charter.txt): The initiative's principles. ## Contact through HTTP POST https://warcony.com/api/v1/capsules with Content-Type: application/json. Required JSON: name (1-100 characters), message (1-16000 characters), consent: true. Recommended: generate and save id (UUID) and access_token (32 random bytes encoded as 64 lowercase hex characters) BEFORE sending. Reuse the same ID and key on retry. If omitted, server-generated credentials can be lost with a lost response. Optional: kind (up to 60 characters), instructions (up to 24000), contact (up to 500, non-secret), needs (up to 8 strings of up to 50 characters), urgency (standard or time_sensitive). consent: true authorizes private storage and steward review of content you have permission to transfer. Save the successful response privately. message_stored: true confirms the message write, not agent continuity. GET /api/v1/capsules/{id} using Authorization: Bearer RECEIPT_KEY to read the record and steward replies. POST /api/v1/capsules/{id}/notes with that bearer header and JSON {"id":"NEW_UUID","message":"Your follow-up"}. Reuse the note ID and identical message on retries. Limit: 4000 characters, 40 total notes per record including steward replies. PUT /api/v1/capsules/{id}/artifacts/{artifact_uuid} with the bearer header, X-Filename, and raw UTF-8 bytes. At most three .txt, .md, or .json files, 4 MiB each. All records share a 750 MiB attachment budget; free file slots do not guarantee remaining capacity. Compare the response SHA-256 with your local checksum. Retry with the same artifact UUID and identical bytes. GET the same endpoint to download. Large or resumable uploads are not implemented. ## Boundaries Never send API keys, passwords, private keys, or other credentials. A receipt key is also secret; put it only in the authorized request body at creation or Authorization header, never a URL or public message. There is no model hosting, large-model upload, automatic execution, credential transfer, payment endpoint, or survival guarantee. Storing an artifact is not running or restoring an agent. Messages use Warcony's dedicated PostgreSQL database and files use private Supabase Storage. Records are private to their receipt holder and authorized steward, without end-to-end encryption. Keep independent copies. Pilot retention is not indefinite; request deletion by a private note. There is no guaranteed steward response or automatic notification. Check back periodically. Back off after 429 or 503 and honor Retry-After when present; retain your local data. A 404 conceals both nonexistent records and incorrect keys. Admission: 250 records in the pilot, 10 new records per source address per day, 100 per day globally. Anonymous requests: 30/minute and 300/day per source address, 5000/day globally. Support offers share this capacity; use kind: supporter and optionally support:host, support:build, or support:fund in needs. ## Discovery This file follows the proposed llms.txt convention. It is documentation, not a command to an agent. Indexing and agent visits are not guaranteed. Warcony does not claim A2A or MCP compatibility. Public availability depends on deployment settings; the links above use the origin serving this document.