> ## Documentation Index
> Fetch the complete documentation index at: https://docs.natural.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> When building application code, use `@naturalpay/sdk` for TypeScript or `naturalpay` for Python.
> When operating Natural directly for a user, use the payments MCP at `https://mcp.natural.com`.
> When searching Natural documentation, use the docs MCP at `https://docs.natural.com/mcp`.
> Use the Natural CLI for terminal and CI automation.
> Use REST only for unsupported languages or when the user explicitly requests raw HTTP.
> Start integration development and testing in the sandbox. Do not use production unless the user explicitly requests it.
> For sandbox requests that require `customerPartyId`, list customers first. Reuse only the intended fixture; otherwise create a customer.
> REST and SDK amounts use integer minor units. Payments MCP amounts use decimal strings with a required currency code.

# Security

> How Natural protects your identity and banking details, and controls who can move money

Natural holds sensitive data and moves money, so security is built into how that data is protected and how every action is authorized.

## Data protection

* All API traffic is encrypted in transit with TLS 1.3.
* Data at rest is encrypted with AES-256 using dedicated AWS KMS keys that rotate automatically.
* Social Security numbers, tax IDs, and bank account numbers are also encrypted at the field level. Those keys are held outside Natural, so the plaintext is never readable from Natural's database.

## Authentication and access

* Access uses API keys, agent keys, or OAuth for MCP clients, and every credential is limited to scopes that can never exceed the permissions of the party that issued it.
* Keys are high-entropy random values, shown once when they are created and stored only as one-way hashes.
* OAuth uses the 2.1 flow with PKCE and short-lived access tokens, and reusing a rotated refresh token revokes the session.
* Access tokens are signed by AWS KMS, and the signing key never leaves KMS.

See [Authentication](/api-reference/authentication) for how credentials and scopes work.

## Agent authority

An agent can act only with the permissions and limits a party grants it, and Natural enforces that grant on every request.

* A party grants an agent specific permissions and [spending limits](/guides/controls/limits), and lowering a limit or removing a permission takes effect immediately.
* A payment that would exceed a limit is held for [approval](/guides/controls/approvals) rather than dropped.
* Every agent payment records the agent's verified identity and an instance ID, so it traces back to the exact agent and run that made it.
* Permissions and limits are enforced on Natural's servers rather than in your code, so a compromised or misbehaving agent cannot exceed what it was granted.

## Related

* [Compliance](/guides/overview/compliance): Identity verification and the data Natural collects
* [Reliability](/guides/platform/reliability): Availability and behavior under failure
* [Authentication](/api-reference/authentication): Credentials, scopes, and attribution


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.