> ## Documentation Index
> Fetch the complete documentation index at: https://docs.natural.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> When building application code, use `@naturalpay/sdk` for TypeScript or `naturalpay` for Python.
> When operating Natural directly for a user, use the payments MCP at `https://mcp.natural.com`.
> When searching Natural documentation, use the docs MCP at `https://docs.natural.com/mcp`.
> Use the Natural CLI for terminal and CI automation.
> Use REST only for unsupported languages or when the user explicitly requests raw HTTP.
> Start integration development and testing in the sandbox. Do not use production unless the user explicitly requests it.
> For sandbox requests that require `customerPartyId`, list customers first. Reuse only the intended fixture; otherwise create a customer.
> REST and SDK amounts use integer minor units. Payments MCP amounts use decimal strings with a required currency code.

# Overview

> Credentials bound to a single agent

An agent key (`agk_*`) is a credential bound to one [Agent](/guides/concepts/agents); its secret starts with `ak_ntl_`. A request made with it acts as that agent. Give it to an agent runtime; it carries the same verified binding as an agent-scoped [MCP OAuth](/guides/platform/mcp) grant.

An [API key](/guides/concepts/api-keys) is the party-wide counterpart: it acts as the party and cannot act as an agent. An agent key is scoped to its agent, nothing else.

## Issuing

Issue one with [`POST /agent-keys`](/api-reference/agent-keys/create-agent-key). Agent keys can only be issued, rotated, or revoked from a user session, so a leaked API key can't create agent identities. Listing works from an API key with the `api_keys.read` scope. Issuing a key for a revoked agent returns `agent_not_active`. See [Manage your agents](/guides/agents/manage-agents) for the full flow.

## Lifecycle

A key is `ACTIVE` until you revoke it, then `REVOKED`; a rotated key's old secret stops authenticating at its `expiresAt`. Rotating with [`POST /agent-keys/{keyId}/rotate`](/api-reference/agent-keys/rotate-agent-key) issues a replacement and keeps the old key valid for a grace period you choose, up to 24 hours, so a running agent switches over without downtime. Revoking with [`DELETE /agent-keys/{keyId}`](/api-reference/agent-keys/revoke-agent-key) invalidates a key immediately, with no replacement. Either way, the secret is shown once.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.