> ## Documentation Index
> Fetch the complete documentation index at: https://docs.natural.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> When building application code, use `@naturalpay/sdk` for TypeScript or `naturalpay` for Python.
> When operating Natural directly for a user, use the payments MCP at `https://mcp.natural.com`.
> When searching Natural documentation, use the docs MCP at `https://docs.natural.com/mcp`.
> Use the Natural CLI for terminal and CI automation.
> Use REST only for unsupported languages or when the user explicitly requests raw HTTP.
> Start integration development and testing in the sandbox. Do not use production unless the user explicitly requests it.
> For sandbox requests that require `customerPartyId`, list customers first. Reuse only the intended fixture; otherwise create a customer.
> REST and SDK amounts use integer minor units. Payments MCP amounts use decimal strings with a required currency code.

# Overview

> Your party's server-side credential

An API key (`apy_*`) is your [Party](/guides/concepts/parties)'s server-side credential; its secret starts with `sk_ntl_`. A request made with it acts as your party, limited to the scopes the key was created with. Keep it on servers you control, never in a browser or client app.

## Scopes

A key carries a scope list; omit `scopes` and it gets every scope, so pass a narrow list for narrow jobs. A call outside the key's scopes is rejected.

## Keys and agents

An API key moves money as a party action and cannot act as an agent. A credential that acts as an agent is an [Agent key](/guides/concepts/agent-keys). See [Authentication](/api-reference/authentication) for the full credential model.

## Lifecycle

Create a key with [`POST /api-keys`](/api-reference/api-keys/create-api-key). It is `ACTIVE` until you revoke it with [`DELETE /api-keys/{keyId}`](/api-reference/api-keys/revoke-api-key), then `REVOKED`. Create and revoke keys from a user session; a key cannot create or revoke keys.

## Secrets

The secret is returned once, on creation, and can never be read again. Revoking a key invalidates it immediately.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.