# Public Marshall

Public Marshall is model chat without sign-in, with up to **$100 of free,
sponsored model usage per browser visitor**. Use it to plan experiments,
compare approaches, write code and ask questions about models and compute.

Open [Public Marshall](https://console.nationalcompute.com/public/marshall)
and send a message. Replies appear as they are generated. Public Marshall
uses the production default model; it has no shell, files, uploads, cluster
access or tools that perform actions on your behalf.

## Conversation lifetime

The conversation stays in the page's memory. **Refreshing or closing the
page clears it; there is no saved conversation to recover.** **New
experiment** also clears the current conversation. Use **Stop** to interrupt
an active reply before starting a new experiment. Neither action resets the
usage allowance.

[Sign in](https://docs.nationalcompute.com/sign-in.md) to save Marshall sessions, connect a shell and work
with persistent files. Signing in does not automatically save or import
the public conversation you already wrote.

## Visitor allowance

The $100 allowance lasts for the browser visitor's lifetime; it does not
reset daily or monthly. A separate secure cookie identifies the visitor
and preserves the remaining allowance across page refreshes. The cookie
does not contain conversation history. Keep cookies enabled to retain
access to that allowance. The visitor is a browser identity, not a
verified person or an account; the allowance is not synchronized across
browsers.

The cookie lasts for 365 days and is renewed when the page reconnects.
Deleting it or letting it expire loses access to that visitor's remaining
allowance; signing in cannot recover it.

Before each reply, the service reserves enough allowance to cover its
maximum model usage. Confirmed usage replaces that reservation when the
reply finishes. An interrupted reply with unknown usage keeps its
reservation until the cost is confirmed. Waiting or refreshing does not
release an uncertain reservation.

A new reply is refused when the remaining allowance cannot cover its
reservation, even if some allowance remains. The offer is therefore
**up to $100**, not a guarantee that every remaining fraction can fund a
reply. Sign in to continue using Marshall after the public allowance is
exhausted. The allowance covers public model chat, not compute capacity,
cash withdrawals or a transferable account credit.

## Data retained

Public Marshall does not store prompts, replies or conversation identifiers
in its session or usage records. It retains the visitor credential's hash,
allowance reservations, token counts, model usage and costs. Request limits
use a hashed client address; these records do not contain the chat text.

Public chat does not enter the organization-level
[Marshall data-sharing program](https://docs.nationalcompute.com/marshall-data-sharing.md). Signed-in
workspace sessions follow that program's settings.

## Request limits

These are the current public chat limits. Browsers using the same client
address share its request limits.

| Limit | Value |
|---|---|
| Visitor allowance | $100 lifetime model usage |
| New visitor grants | 5 per hour per client address |
| Chat requests | 10 per minute per client address |
| Active replies | 1 per visitor; 32 across Public Marshall |
| Conversation request | 64 KiB, including at most 64 text messages |
| Reply output | At most 4,096 tokens |
| Model response stream | 512 KiB, including usage metadata |
| Model reply timeout | 120 seconds |
| Execution slot after an unresolved request | 180 seconds; the cost reservation remains |

An incomplete reply stays visible until the page is cleared, but is excluded
from the next message's model context. The app does not automatically retry
a submitted message: a second submission can incur more model usage.
Use **Stop** to interrupt a reply. Stopping does not erase usage already
incurred or release a reservation whose cost is still unknown.

## Refusals and interrupted replies

| Code | Meaning and next step |
|---|---|
| `allowance-exhausted` | The allowance cannot cover another reply; sign in to continue |
| `rate-limited` | A request or active-reply limit was reached; wait and try again |
| `visitor-required` | Reopen the public page with cookies enabled; an invalid or revoked visitor cookie cannot restore its allowance |
| `message-too-large` | The conversation request exceeds the size limit; shorten it or start a new conversation |
| `invalid-request` | The request is malformed or the message limit was reached; send a shorter text conversation from the public page |
| `request-already-used` | That message identifier was already submitted; it is not dispatched again |
| `request-cancelled` | The request was cancelled before model dispatch |
| `reply-interrupted` | The reply did not complete; if usage is unconfirmed, its reservation remains until reconciled |
| `model-temporarily-unavailable` | A bounded model request is unavailable; try again later |
| `public-marshall-unavailable` | The service cannot confirm admission or accounting; try again later |
| `origin-refused` or `proxy-proof-refused` | The request did not come through an accepted public-page connection; reopen the public page |
