> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Response Status Codes

**Error Code** **Error Type** **Error Description** **Description** **Status** `104000` `mandatory_data_missing` `missing_&#123;fieldname&#125;` Provided when any of the mandatory input data elements are not sent in the request. `400` `104000` `invalid_request_error` `invalid_&#123;fieldname&#125;` Provided when any input data elements do not follow the required schema for that field. `400` `104000` `invalid_request_error` `invalid_token_ref_id` The token reference ID does not exist. Either the `token_ref_id` string is entered incorrectly, or the associated token is inactive (cancelled and to be considered deleted). `400` `104001` `card_error` `card_market_not_supported` The market of the Card provided is not supported. `400` `104001` `card_error` `issuer_not_supported` The Issuer of the Card provided does not support provisioning for cards they issue. `400` `104001` `card_error` `card_not_eligible` The Card provided is not eligible for tokenization. `400` `104001` `card_error` `card_cannot_be_tokenized` The Card is ineligible for tokenization due to an ongoing issue such as fraud. `400` `104001` `card_error` `card_cancelled` The Card provided has been cancelled. `400` `104000` `invalid_request_error` `encrypted_payload_decryption_failed` Decryption of the request's payload failed. `400` `104000` `invalid_json_error` `request_body_not_parseable_json` The JSON payload sent does not follow established JSON formatting (e.g., missing a curly brace). `400` `104000` `invalid_request_error` `crypto_validation_failed` The `value` field within the `authentication_method` JSON object is invalid for the provided Card. `400` `104001` `card_error` `unauthorized_operation` The token reference ID cannot have its `status` changed as the token has been deleted. `401` `104010` `invalid_hmac` `invalid_hmac` The HMAC provided is invalid. `401` `104290` `rate_limit_violation` `rate_limit_exceeded` The request count to the server has exceeded its configured limitations. `429` `105000` `system_error` `internal_api_error` The Token Service Provider (TSP) system errors. These errors can be retried by the Token Requester (TR) based on the aligned retry policy. `500` `105040` `connection_timeout` `connection_timeout` The API gateway has experienced a connection timeout. `504`