> ## Documentation Index
> Fetch the complete documentation index at: https://docs.natural.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> When building application code, use `@naturalpay/sdk` for TypeScript or `naturalpay` for Python.
> When operating Natural directly for a user, use the payments MCP at `https://mcp.natural.com`.
> When searching Natural documentation, use the docs MCP at `https://docs.natural.com/mcp`.
> Use the Natural CLI for terminal and CI automation.
> Use REST only for unsupported languages or when the user explicitly requests raw HTTP.
> Start integration development and testing in the sandbox. Do not use production unless the user explicitly requests it.
> For sandbox requests that require `customerPartyId`, list customers first. Reuse only the intended fixture; otherwise create a customer.
> REST and SDK amounts use integer minor units. Payments MCP amounts use decimal strings with a required currency code.

# Overview

> Which of your wallets each agent can move money from

Wallet access is the attachment between an owned or customer-connected [Agent](/guides/concepts/agents) and one of your [Wallets](/guides/concepts/wallets). A new agent is attached to the wallet named at creation, or to your default wallet when none is named. Access is granted per wallet, so you decide which balances each agent can touch. It isn't a standalone resource: an attachment is addressed by its wallet-agent pair. See [Wallet access](/guides/controls/wallet-access).

## Attachments

Attaching an agent with [`POST /wallets/{walletId}/agents`](/api-reference/wallets/grant-agent-access-to-wallet) lets it move money from that wallet; detaching takes that away. The first attached wallet becomes the agent's default, used when a request omits `walletId`. Additional attachments preserve that default. Each customer connection has its own default, independent of other customers and the developer. The Vault cannot be attached for agent spending: attaching to it returns `vault_not_allowed`, and attaching a revoked agent returns `agent_not_active`.

## Who manages access

You do, from a user session or an API key on your own party; an agent cannot attach itself or a sibling. To let an agent operate a customer's wallet, the customer first accepts a [customer invitation](/guides/concepts/customers). The customer can then add wallets, remove non-default wallets, or change the connection default through these routes. Developers cannot change their customers' wallet access.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.