> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Online Purchase

POST https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase
Content-Type: application/json

The /online_purchases resource supports general web and mobile purchases.

Reference: https://developer.americanexpress.ferndocs.com/fraud-prevention/enhanced-authorization-v-2/api-reference/online-purchase

## Authentication

- `Authorization` header (required) — HMAC (one-way TLS). A `MAC` authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac

## Servers

- `https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations` (Sandbox, default)
- `https://api.qa.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations` (Qa)
- `https://api.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations` (Production)

## Request

### Headers

- `x-amex-request-id` (string, required) — A Unique Identifier. Typically, a GUID is displayed as 32 hexadecimal digits, grouped and separated by hyphens and left-aligned.e.g., 30c0fda8-a834-4de8-80b35-bad8f5a1986.A GUID will be used for tracking purposes and the same GUID will be echoed back in the response.
- `x-amex-api-key` (string, required) — This is the key that will be provided once the Consumer is onboarded.

### Body (application/json)

This endpoint expects an enhanced_auth_online_request.

- `timestamp` (datetime, required) — The originating timestamp of the API Call from the Merchant. The format is: yyyy-MM-ddTHH:mm:ss.SSSZ.e.g., 2018-03-01T11:23:10.791-0700
- `transaction_data` (transaction_data, required) — The following fields are specific to the transaction.
- `purchaser_information` (purchaser_information, optional) — Details that are specific to the Purchaser.
- `registration_details` (registration_details, optional) — The Customer's registration details with the Merchant.e.g., You are a major online retailer and a Customer who is registered with you is about to make a purchase. The following details refer to the Customer's registration details with you.
- `registration_details_change_history` (registration_details_change_history, optional) — This is historical information referencing the Customer's registration details with your company.e.g., You are a major online retailer and a Customer that is registered with you is about to make a purchase. The following details refer to the Customer's registration details with you. For each property (unless otherwise indicated), the value is the number of days between the purchase date and the last Update of the registration information. If you do not have tracking at the field level for changes, please use the last update date for the appropriate record.
- `seller_information` (seller_information, optional) — The following Seller details are needed in a situation where your company is submitting the transaction details on behalf of another entity.e.g., A taxi company in which each driver is an independent online marketplace where small vendors can sell their goods leveraging a common infrastructure payment processing center that enables individual Merchants to accept cards. In these situations, the Seller information refers to:the location of the seller;tenure for which they have used your services;details about their business.

## Response

### 200

Successfully processed the Enhanced Authorization request.

- `status` (string, optional) — The API status, displayed as either success or failure.e.g., success
- `timestamp` (datetime, optional) — The originating timestamp from the Merchant request. The format is: yyyy-MM-ddTHH:mm:ss.SSSZ.e.g., 2018-03-06T11:23:10.791-0700
- `resp_code` (string, optional) — The response code which will describe the response received.e.g., ENAUTH000
- `resp_msg` (string, optional) — The detailed response message.e.g., Successfully processed the Enhanced Authorization request.
- `aav_results` (aav_results, optional) — Indicates whether the American Express Authorization System found a match for the individual elements name, phone, address, email and ZIP Code that is passed in the Enhanced Authorization request. Possible values for each element include:Y = The information provided matched with the information on file.N = The information provided does not match with the information on file.U = The information is unavailable to check.R = System unavailable; retry.
- `additional_response` (additional_response, optional) — The additional response requested by the Consumer will be sent in this section.

## Errors

### 400 Bad Request Error

Bad Request.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 401 Unauthorized Error

Unauthorized. Indicates a failure within the security credentials.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 405 Method Not Allowed Error

Method Not Allowed. Operation not allowed. The error message will have an exception string.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 406 Not Acceptable Error

Not Acceptable. The server cannot serve a representation that meets the Client's preferences. The error message will have an exception string.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 415 Unsupported Media Type Error

Unsupported Media Type. The Client sends the message body in a format that the server does not understand. The error message will have an exception string.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 429 Too Many Requests Error

Too many requests.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 500 Internal Server Error

Internal Error. An error has occurred within the American Express systems.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 503 Service Unavailable Error

Service unavailable.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

### 504 Gateway Timeout Error

Timeout Error. The error message will have an exception string.

- `error_code` (string, optional) — The detailed error code. For additional details, please see the Common Error Codes.e.g., EAPERR003
- `error_type` (string, optional) — A short description of the error type.
- `error_description` (string, optional) — A detailed description and/or explanation of the error.

## Types

### transaction_data

The following fields are specific to the transaction.

- `card_number` (string, required) — The 15-digit Primary Account Number (PAN) of the Customer's Card.e.g., 371270025401043Masked Card Numbers are allowed, which are the first six digits of the Card Number, followed by five zeros, and the last four digits, (e.g., 123456000001234). If a Merchant sends masked Card Numbers, then the billing_address and billing_postal_code are additionally required variables for the process in order to match the Enhanced Authorization call to the Authorization message.
- `amount` (double, required) — The amount for the transaction in decimal format.e.g., 100
- `transaction_timestamp` (datetime, required) — The timestamp of the transaction itself. The format is: yyyy-MM-ddTHH:mm:ss.SSSZ.e.g., 2018-03-01T11:23:10.791-0700
- `currency_code` (string, optional) — The currency used for the transaction. Use the three-letter alphabetic or three-digit numeric <a href='[https://www.iso.org/iso-4217-currency-codes.html'&gt;ISO](https://www.iso.org/iso-4217-currency-codes.html'&gt;ISO) 4217 Currency Code.e.g., For the United States dollar, use 840 or USD.
- `card_acceptor_id` (string, optional) — A 10-digit number which represents your Merchant code or SE number.e.g., 1234567890
- `is_coupon_used` (enum, optional) — Indicates whether a coupon is being used as part of the transaction.
  - Allowed values: `Y`, `N`
- `electronic_delivery_email` (string, optional) — If the purchase is for an item that can be electronically delivered, such as an eBook or software, please include the email address associated with the delivery.e.g., [someone@example.com](mailto:someone@example.com)
- `top5_items_in_cart` (string, optional) — Please match up to five (5) items from the purchase against defined categories. For each match, concatenate the four-digit codes together as seen in the example.e.g., 00010002000300040005
- `merchant_product_sku` (string, optional) — The unique Stock Keeping Unit (SKU) inventory reference number of the product associated with this purchase. For multiple items, enter the SKU for the single, most-expensive item.e.g., TKDC315U
- `shipping_method` (string, optional) — Two-byte, shipment-type code:01 = Same Day02 = Overnight/Next Day03 = 2-3 Day Priority04 = Ground (4 or more days)05 = Electronic Delivery06 = Ship-to-Storee.g., 02
- `number_of_gift_cards_in_cart` (integer, optional) — If purchasing gift cards, this reflects the number of cards being purchased.e.g., 2
- `additional_information` (additional_information, optional)

### purchaser_information

Details that are specific to the Purchaser.

- `billing_address` (string, required) — The billing address of the Card Member.e.g., 400 Maple Court
- `billing_postal_code` (string, required) — The billing Postal Code of the Card Member.e.g., 12345
- `customer_email` (string, optional) — The email address of the Purchaser.e.g., [someone@example.com](mailto:someone@example.com)
- `billing_first_name` (string, optional) — The first name of the Card Member.e.g., Adam
- `billing_last_name` (string, optional) — The last name of the Card Member.e.g., Underhill
- `billing_phone_number` (string, optional) — The phone number of the Card Member.e.g., (555) 555-2222
- `shipto_address` (string, optional) — The shipping address for the purchase.e.g., 400 Maple Court
- `shipto_postal_code` (string, optional) — The Postal Code for the purchase.e.g., 12345
- `shipto_first_name` (string, optional) — The Ship-to first name.e.g., Adam
- `shipto_last_name` (string, optional) — The Ship-to last name.e.g., Underhill
- `shipto_phone_number` (string, optional) — The Ship-to phone number.e.g., (555) 555-2222
- `shipto_country_code` (string, optional) — \<p>The country on the Shipping information, represent by a three-digit \<a href='[https://www.iso.org/iso-3166-country-codes.html>ISO](https://www.iso.org/iso-3166-country-codes.html>ISO) 3166 Numeric Country Code.\</p>\<p>e.g., For the United States, use \<samp>840\</samp>.\</p>\<p>Do not use characters such as "US", which will fail validation.\</p>
- `latitude_of_customers_device` (double, optional) — The latitude of the device used to make the purchase at the time of the purchase.e.g., -1.5459487
- `longitude_of_customers_device` (double, optional) — The longitude of the device used to make the purchase at the time of the purchase.e.g., 52.2768309
- `device_id` (string, optional) — A unique ID of the device is used to make the purchase. At your discretion, determine the appropriate ID to use. Consistancy in which IDs you use is the most important aspect of Enhanced Authorizations. Examples of potential IDs include:iPhone UUID Network MACANDRIOD_IDIMEIMEIDIMSIe.g., 2b6f0cc904d137be2e1730235f5664094b83
- `device_type` (string, optional) — An indicator of the type of device used for the purchase:01 = Phone02 = Tablet03 = Computer04 = Othere.g., 01
- `device_timezone` (string, optional) — The time zone of the device at the time of purchase, in UTC time format.e.g., UTC-07:00
- `cookie` (string, optional) — e.g., USER1
- `device_ip` (string, optional) — The network IP address of the device used for the purchase.e.g., 934.002.050.999
- `host_name` (string, optional) — The host name of the server on which the Customer placed their purchase.e.g., phx.qw.aol.com
- `user_agent` (string, optional) — The User Agent information provided by the browser of the Purchaser.e.g., MOZILLA/4.0~(COMPATIBLE;~~MSIE~~5.0;~~WINDOWS~~95)
- `customer_ani` (string, optional) — The Automatic Number Identification (ANI) specified 10-digit phone number that the Customer used to place the order. The USA, Canada and other countries that follow the North American Numbering Plan (NANP) phone numbering system should send all 10-digits of the phone number, including the area code. For countries that do not follow this system, send the last 10-digits:A USA phone number '(555) 555-2222' would be entered as '5555552222'.A United Kingdom (UK) phone number '44-1234-123456' would be entered as '1234123456'.If the order was not placed over the phone, the Primary Contact Number (PCN) for the Customer can be substituted.e.g., 5555551111
- `customer_II_digits` (string, optional) — The telephone company-provided ANI Information Identifier (II) digits associated with the Customer's ANI. Value ranges include:Cellular = 61-63Payphone = 27Toll-free = 24, 25e.g., 27

### registration_details

The Customer's registration details with the Merchant.e.g., You are a major online retailer and a Customer who is registered with you is about to make a purchase. The following details refer to the Customer's registration details with you.

- `is_registered` (enum, optional) — Indicates whether the Purchaser is a registered member of your company:Y = The Purchaser is currently registeredN = The Purchaser is a guest.
  - Allowed values: `Y`, `N`
- `registered_name` (string, optional) — The name of the Card Member as registered with your company.e.g., Jane Smith
- `registered_email` (string, optional) — The registered email address of the Card Member.e.g., [someone@example.com](mailto:someone@example.com)
- `registered_postal_code` (string, optional) — The registered Postal Code for the Card Member.e.g., 32121
- `registered_address` (string, optional) — The registered address of the Card Member.NOTE: The address does not include city or state/provincial information.e.g., 400 Maple Court
- `registered_phone` (string, optional) — The registered phone number of the Card Member. If multiple phone numbers are available, use the Primary Contact Number (PCN).e.g., 5555551111
- `count_of_shipto_addresses_on_file` (integer, optional) — The number of ship-to addresses registered with your company.e.g., 2
- `registered_account_tenure` (integer, optional) — The number of days in which the Card Member has been registered with your company.e.g., 720

### registration_details_change_history

This is historical information referencing the Customer's registration details with your company.e.g., You are a major online retailer and a Customer that is registered with you is about to make a purchase. The following details refer to the Customer's registration details with you. For each property (unless otherwise indicated), the value is the number of days between the purchase date and the last Update of the registration information. If you do not have tracking at the field level for changes, please use the last update date for the appropriate record.

- `is_registration_updated` (enum, optional) — Indicates whether any registration information has been updated or changed since the original inception of the registration.YN
  - Allowed values: `Y`, `N`
- `registered_name` (integer, optional) — The number of days between the last update of the registered name and the purchase date.e.g., 31
- `registered_email` (integer, optional) — The number of days between the last update of the registered email and the purchase date.e.g., 31
- `registered_password` (integer, optional) — The number of days between the last update of the registered password and the purchase date.e.g., 31
- `registered_postal_code` (integer, optional) — The number of days between the last update of the registered Postal Code and the purchase date.e.g., 31
- `registered_address` (integer, optional) — The number of days between the last update of the registered address and the purchase date.e.g., 31
- `registered_phone` (integer, optional) — The number of days between the last update of the registered phone number and the purchase date.e.g., 31
- `shipto_address` (integer, optional) — The number of days between the last update of the registered ship-to address and the purchase date.e.g., 31
- `shipto_name` (integer, optional) — The number of days between the last update of the registered ship-to name and the purchase date.e.g., 31

### seller_information

The following Seller details are needed in a situation where your company is submitting the transaction details on behalf of another entity.e.g., A taxi company in which each driver is an independent online marketplace where small vendors can sell their goods leveraging a common infrastructure payment processing center that enables individual Merchants to accept cards. In these situations, the Seller information refers to:the location of the seller;tenure for which they have used your services;details about their business.

- `latitude` (double, optional) — The location of where the purchase was made. For example, for a taxi driver, the location of the taxi when the fare was paid.e.g., -1.5459487
- `longitude` (double, optional) — The location of where the purchase was made. For example, for the taxi driver, the location of the taxi when the fare was paid.e.g., 52.2768309
- `owner_name` (string, optional) — The Seller's name.e.g., Betty Smith
- `seller_id` (string, optional) — Your company's ID for the Seller.e.g., 1234567890
- `business_name` (string, optional) — The business name of the Seller.e.g., American Express
- `tenure` (integer, optional) — The number of months that the Seller has been using your services.e.g., 36
- `transaction_type_indicator` (string, optional) — Indicates the type of the Seller using the following types:P2P = Person to PersonP2M = Person to MerchantCSH = Cashe.g., P2M
- `address` (string, optional) — The Business or Contact address of the Seller.e.g., 400 Maple Court
- `phone` (string, optional) — The primary phone number of the Seller.e.g., (555) 555-2222
- `email` (string, optional) — The primary email address of the Seller.e.g., [someone@example.com](mailto:someone@example.com)
- `postal_code` (string, optional) — The Postal Code of the primary address of the Seller.e.g., 12345
- `region` (string, optional) — The region of the Seller:APA = Asia Pacific and Australia;Canada = Canada;EMEA = Europe, Middle East and Africa;LA/C = Latin America and Caribbean;USA = United States.e.g., USA
- `country_code` (string, optional) — The country of the Seller. Uses the ISO 3166 Numeric Country Code.e.g., For the United States, use 840.Do not use characters such as "US", which will fail validation.

### aav_results

Indicates whether the American Express Authorization System found a match for the individual elements name, phone, address, email and ZIP Code that is passed in the Enhanced Authorization request. Possible values for each element include:Y = The information provided matched with the information on file.N = The information provided does not match with the information on file.U = The information is unavailable to check.R = System unavailable; retry.

- `zip` (enum, optional) — The ZIP Code matches the result.
  - Allowed values: `Y`, `N`, `U`, `R`
- `address` (enum, optional) — The address matches the result.
  - Allowed values: `Y`, `N`, `U`, `R`
- `name` (enum, optional) — The name matches the result.
  - Allowed values: `Y`, `N`, `U`, `R`
- `phone` (enum, optional) — The phone number matches the result.
  - Allowed values: `Y`, `N`, `U`, `R`
- `email` (enum, optional) — The email matches the result.
  - Allowed values: `Y`, `N`, `U`, `R`

### additional_response

The additional response requested by the Consumer will be sent in this section.

- `risk_score_range` (integer, optional) — The range of the risk score. The higher the category number, the higher the risk.The response values include: null, 01, 02, 03, 04, 05, 06, 07 and 08.
- `ip_address_match_results` (enum, optional) — The IP address matches the result.
  - Allowed values: `Y`, `N`, `U`

### additional_information

- `need_authorization_results` (boolean, optional, default: true) — If the Merchant wants to get an immediate response that the API request is received, and the American Express results (i.e., individual element match results and/or risk score) are not needed, then set this variable to 'false'.If the Merchant wants American Express results (i.e., element match results and/or risk score), then set this variable to 'true'.NOTE: By default, this indicator is set to 'true'.
- `risk_score` (boolean, optional, default: false) — If the Merchant wants the risk_score of the transaction to be returned, set this indicator to 'true'.NOTE: This indicator cannot be 'true' if the variable need_authorization_results is set to 'false'.

## Examples

**Request**

```json
{
  "timestamp": "2024-01-15T09:30:00Z",
  "transaction_data": {
    "card_number": "string",
    "amount": 1.1,
    "transaction_timestamp": "2024-01-15T09:30:00Z"
  }
}
```

**Response**

```json
{
  "status": "string",
  "timestamp": "2024-01-15T09:30:00Z",
  "resp_code": "string",
  "resp_msg": "string",
  "aav_results": {
    "zip": "Y",
    "address": "Y",
    "name": "Y",
    "phone": "Y",
    "email": "Y"
  },
  "additional_response": {
    "risk_score_range": 1,
    "ip_address_match_results": "Y"
  }
}
```

**SDK Code**

```python
import requests

url = "https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase"

payload = {
    "timestamp": "2024-01-15T09:30:00Z",
    "transaction_data": {
        "card_number": "string",
        "amount": 1.1,
        "transaction_timestamp": "2024-01-15T09:30:00Z"
    }
}
headers = {
    "x-amex-api-key": "x-amex-api-key",
    "x-amex-request-id": "x-amex-request-id",
    "Authorization": "<apiKey>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase';
const options = {
  method: 'POST',
  headers: {
    'x-amex-api-key': 'x-amex-api-key',
    'x-amex-request-id': 'x-amex-request-id',
    Authorization: '<apiKey>',
    'Content-Type': 'application/json'
  },
  body: '{"timestamp":"2024-01-15T09:30:00Z","transaction_data":{"card_number":"string","amount":1.1,"transaction_timestamp":"2024-01-15T09:30:00Z"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase"

	payload := strings.NewReader("{\n  \"timestamp\": \"2024-01-15T09:30:00Z\",\n  \"transaction_data\": {\n    \"card_number\": \"string\",\n    \"amount\": 1.1,\n    \"transaction_timestamp\": \"2024-01-15T09:30:00Z\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("x-amex-api-key", "x-amex-api-key")
	req.Header.Add("x-amex-request-id", "x-amex-request-id")
	req.Header.Add("Authorization", "<apiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["x-amex-api-key"] = 'x-amex-api-key'
request["x-amex-request-id"] = 'x-amex-request-id'
request["Authorization"] = '<apiKey>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"timestamp\": \"2024-01-15T09:30:00Z\",\n  \"transaction_data\": {\n    \"card_number\": \"string\",\n    \"amount\": 1.1,\n    \"transaction_timestamp\": \"2024-01-15T09:30:00Z\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase")
  .header("x-amex-api-key", "x-amex-api-key")
  .header("x-amex-request-id", "x-amex-request-id")
  .header("Authorization", "<apiKey>")
  .header("Content-Type", "application/json")
  .body("{\n  \"timestamp\": \"2024-01-15T09:30:00Z\",\n  \"transaction_data\": {\n    \"card_number\": \"string\",\n    \"amount\": 1.1,\n    \"transaction_timestamp\": \"2024-01-15T09:30:00Z\"\n  }\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase', [
  'body' => '{
  "timestamp": "2024-01-15T09:30:00Z",
  "transaction_data": {
    "card_number": "string",
    "amount": 1.1,
    "transaction_timestamp": "2024-01-15T09:30:00Z"
  }
}',
  'headers' => [
    'Authorization' => '<apiKey>',
    'Content-Type' => 'application/json',
    'x-amex-api-key' => 'x-amex-api-key',
    'x-amex-request-id' => 'x-amex-request-id',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase");
var request = new RestRequest(Method.POST);
request.AddHeader("x-amex-api-key", "x-amex-api-key");
request.AddHeader("x-amex-request-id", "x-amex-request-id");
request.AddHeader("Authorization", "<apiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"timestamp\": \"2024-01-15T09:30:00Z\",\n  \"transaction_data\": {\n    \"card_number\": \"string\",\n    \"amount\": 1.1,\n    \"transaction_timestamp\": \"2024-01-15T09:30:00Z\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "x-amex-api-key": "x-amex-api-key",
  "x-amex-request-id": "x-amex-request-id",
  "Authorization": "<apiKey>",
  "Content-Type": "application/json"
]
let parameters = [
  "timestamp": "2024-01-15T09:30:00Z",
  "transaction_data": [
    "card_number": "string",
    "amount": 1.1,
    "transaction_timestamp": "2024-01-15T09:30:00Z"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.qasb.americanexpress.com/risk/fraud/v2/apiplatform/enhanced_authorizations/online_purchase")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```