Skip to navigation
API Reference

Check a token's state.

Returns the current status of an existing token. The endpoint may be particularly helpful in diagnosing issues, such as a failure within a payment flow.

Authentication

Authorizationstring

HMAC (one-way TLS). A MAC authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac

Path parameters

token_ref_idstringRequired<=64 characters

The unique reference identifier for a token.

Headers

Accept-LanguagestringRequired<=36 characters

This is en-US.

Content-LanguagestringRequired<=36 characters

This is en-US.

AuthorizationstringRequired<=256 characters

The HMAC authorization header generated as prescribed by American Express API security.

e.g., MAC id="OLQkWT14WtLR0aE63AqtkW2DJppMviSk", ts="1548353658039", nonce="18036bb8-a100-4e02-ab93-328abd67acf2", bodyhash="uRphuQfK6igW44z4Ns/Bo9XdiXlsCdEzTsxdeUBu9j8=", mac="yJ70ObsprC2ygCjzq88Lq0QTKPqlLMIPYpR4O1DBg+Y="

x-amex-api-keystringRequired<=64 characters

The Client ID as shown on the American Express Token Service dashboard.

e.g., OLQkWT14WtLR0aE63AqtkW2DJppMviSk

x-amex-token-requester-idstringRequired<=64 characters

The unique identifier as the Token Requester. Available on the American Express Token Service dashboard.

e.g., devportalTest

x-amex-request-idstringRequired<=64 characters

The unique identifier for the API request to be returned in the response headers.

This is set by the API caller, and it should never be re-used across different transactions.

e.g., AA3434342323

Response headers

x-amex-request-idstringOptional
The unique identifier sent with the request.
session_idstringOptional
The unique identifier of the session generated by the TSP.

Response

The request has been processed successfully.

Upon a 200 response, the transaction was successfully processed and the token data and transaction data are returned in a response payload.

token_statusstringOptional<=128 characters

The token's status will be one of the following values:

  • Active: The token is active.
  • Suspended: The token has been temporarily suspended.
  • Cancelled: The token is no longer available.

Errors

400
Bad Request Error
401
Unauthorized Error
429
Too Many Requests Error
500
Internal Server Error
504
Gateway Timeout Error