Skip to navigation
API Reference

Online Purchase

The /online_purchases resource supports general web and mobile purchases.

Authentication

Authorizationstring

HMAC (one-way TLS). A MAC authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac

Headers

x-amex-request-idstringRequiredformat: "string"<=36 characters

A Unique Identifier. Typically, a GUID is displayed as 32 hexadecimal digits, grouped and separated by hyphens and left-aligned.

e.g., 30c0fda8-a834-4de8-80b35-bad8f5a1986.

A GUID will be used for tracking purposes and the same GUID will be echoed back in the response.

x-amex-api-keystringRequiredformat: "string"

This is the key that will be provided once the Consumer is onboarded.

Request

Request body for enhanced_auth_request.

timestampdatetimeRequired

The originating timestamp of the API Call from the Merchant. The format is: yyyy-MM-ddTHH:mm:ss.SSSZ.

e.g., 2018-03-01T11:23:10.791-0700

transaction_dataobjectRequired

The following fields are specific to the transaction.

purchaser_informationobjectOptional

Details that are specific to the Purchaser.

registration_detailsobjectOptional

The Customer's registration details with the Merchant.

e.g., You are a major online retailer and a Customer who is registered with you is about to make a purchase. The following details refer to the Customer's registration details with you.

registration_details_change_historyobjectOptional

This is historical information referencing the Customer's registration details with your company.

e.g., You are a major online retailer and a Customer that is registered with you is about to make a purchase. The following details refer to the Customer's registration details with you. For each property (unless otherwise indicated), the value is the number of days between the purchase date and the last Update of the registration information. If you do not have tracking at the field level for changes, please use the last update date for the appropriate record.

seller_informationobjectOptional

The following Seller details are needed in a situation where your company is submitting the transaction details on behalf of another entity.

e.g., A taxi company in which each driver is an independent online marketplace where small vendors can sell their goods leveraging a common infrastructure payment processing center that enables individual Merchants to accept cards. In these situations, the Seller information refers to:

  • the location of the seller;
  • tenure for which they have used your services;
  • details about their business.

Response headers

x-amex-request-idstringOptional

A Unique Identifier. Typically, a GUID is displayed as 32 hexadecimal digits, grouped and separated by hyphens and left-aligned.

e.g., 30c0fda8-a834-4de8-80b35-bad8f5a1986.

A GUID will be used for tracking purposes and the same GUID will be echoed back in the response.

Response

Successfully processed the Enhanced Authorization request.

statusstringOptionalformat: "string"

The API status, displayed as either success or failure.

e.g., success

timestampdatetimeOptional

The originating timestamp from the Merchant request. The format is: yyyy-MM-ddTHH:mm:ss.SSSZ.

e.g., 2018-03-06T11:23:10.791-0700

resp_codestringOptionalformat: "string"

The response code which will describe the response received.

e.g., ENAUTH000

resp_msgstringOptionalformat: "string"

The detailed response message.

e.g., Successfully processed the Enhanced Authorization request.

aav_resultsobjectOptional

Indicates whether the American Express Authorization System found a match for the individual elements name, phone, address, email and ZIP Code that is passed in the Enhanced Authorization request. Possible values for each element include:

  • Y = The information provided matched with the information on file.
  • N = The information provided does not match with the information on file.
  • U = The information is unavailable to check.
  • R = System unavailable; retry.

additional_responseobjectOptional

The additional response requested by the Consumer will be sent in this section.

Errors

400
Bad Request Error
401
Unauthorized Error
405
Method Not Allowed Error
406
Not Acceptable Error
415
Unsupported Media Type Error
429
Too Many Requests Error
500
Internal Server Error
503
Service Unavailable Error
504
Gateway Timeout Error