> ## Documentation Index
> Fetch the complete documentation index at: https://docs.natural.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> When building application code, use `@naturalpay/sdk` for TypeScript or `naturalpay` for Python.
> When operating Natural directly for a user, use the payments MCP at `https://mcp.natural.com`.
> When searching Natural documentation, use the docs MCP at `https://docs.natural.com/mcp`.
> Use the Natural CLI for terminal and CI automation.
> Use REST only for unsupported languages or when the user explicitly requests raw HTTP.
> Start integration development and testing in the sandbox. Do not use production unless the user explicitly requests it.
> For sandbox requests that require `customerPartyId`, list customers first. Reuse only the intended fixture; otherwise create a customer.
> REST and SDK amounts use integer minor units. Payments MCP amounts use decimal strings with a required currency code.

# Reliability

> How Natural stays available and behaves predictably under failure

You rely on Natural to run agents, hold funds in wallets, and move money, so Natural is built to stay available and to behave predictably when something fails. This page covers how Natural runs the service and how the API responds under failure.

## Infrastructure

Natural runs on AWS across multiple availability zones and is served through a global CDN. If an instance or an entire availability zone fails, traffic shifts to healthy capacity automatically.

## Data

Your data lives in Amazon Aurora PostgreSQL, running with a primary and a replica across availability zones so the database survives the loss of any single zone. It is encrypted at rest with AWS KMS and backed up automatically. For how data is encrypted and protected, see [Security](/guides/overview/security).

## Behavior under failure

The API is built so that a failure or a retry never leaves your data in the wrong state, whether you are creating an agent, funding a wallet, or sending a payment.

### Idempotency

Any operation whose accidental repetition would matter, like funding a wallet or sending a payment, takes an `Idempotency-Key`. Retrying with the same key never runs the operation twice, and the recorded outcome, success or failure, replays for 48 hours. See [Idempotency](/api-reference/idempotency).

### Retries

Transient failures are safe to retry with exponential backoff. A `429` response carries a `Retry-After` header, and `5xx` responses and network timeouts can be retried under the same idempotency key. See [Rate limits](/api-reference/rate-limits).

### Webhooks

Events are delivered at least once from a durable queue. Each event is retried up to seven times over roughly a day with jitter, times out after 30 seconds per attempt, and carries a stable `webhook-id` so you can deduplicate. An endpoint that fails five events in a row is disabled until you re-enable it. See [Webhooks overview](/guides/concepts/webhooks).

### Compatibility

The Natural API is additive. Natural adds fields and endpoints, and never removes or repurposes the ones you depend on. See [Backwards compatibility](/api-reference/backwards-compatibility).

## Status

Live service status is published at [status.natural.com](https://status.natural.com), covering the API, dashboard, MCP, and webhooks. Subscribe there to be notified of incidents.

## Related

* [Idempotency](/api-reference/idempotency): Safe retries for mutations
* [Webhooks overview](/guides/concepts/webhooks): Event delivery and verification
* [Security](/guides/overview/security): How Natural protects data and controls access


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.