Skip to main content
See every agent (agt_*) you have created, inspect one, rename it, or revoke it when it is done. For how agents fit with keys and limits, read the Agents overview.

List your agents

List every agent on your account with GET /agents.
The response carries each agent with its handle, status, and limits:

Inspect one agent

Inspect one agent by ID with GET /agents/{agentId}.
The response carries the agent:

Rename an agent

Rename an agent, change its description, or adjust its limits, with PATCH /agents/{agentId}. Set limits from a user session or party API key; an agent key cannot change its own limits. limits: null clears them.
The response carries the updated agent:

Revoke an agent

Revoke an agent with DELETE /agents/{agentId}. Its status becomes REVOKED and it stops moving money at once, but the record stays readable so its history survives. Revoking also revokes every customer authorization the agent holds and cancels its pending invitations.
The response carries the agent with status REVOKED:

Manage agent keys

An agent key (ak_ntl_*) is a credential bound to one agent. Your dashboard lists keys on the agent detail page; over the API, use the agent-keys endpoints below. Issue a new key when you create an agent.

List keys

There is no get-by-id endpoint. List keys with GET /agent-keys (scope api_keys.read), optionally filtered by agentId.

Rotate a key

Rotate with POST /agent-keys/{keyId}/rotate to issue a fresh secret on the same agent. Set a grace period so running workloads can pick up the new key before the old one stops working. The new secret is again shown once. Rotate and revoke from a user session, as when issuing; $NATURAL_USER_TOKEN in the cURL examples is that session credential, the same one natural login stores for the CLI. expiresInSeconds runs from 0 (immediate) to 86400.

Revoke a key

Revoke with DELETE /agent-keys/{keyId} to invalidate a key immediately. This cannot be undone, and other keys on the same agent keep working. Use it when a secret leaks or you retire one credential without revoking the agent.