> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Important Items

##### Timing

* There should be a small time gap (e.g., `200 milliseconds`) between the Enhanced Authorization API call and the Authorization message, where the Enhanced Authorization API call should be first.
* The Enhanced Authorization call must be received before the Authorization message. If this doesn't happen, then the Enhanced Authorization data may not be available to be used in the American Express authorization decisioning.

##### Merchant Data

It is important that the Merchant data provided is in sync with the formats in Specification. For example, the variable shipto\_country\_code needs to be the three digit [ISO 3166 Numeric Country code](https://www.iso.org/iso-3166-country-codes.html). If the `shipto_country_code` is the United States, then the correct data would be `"840"`. If the Merchant sends `"US"` instead of `"840"`, then the data will fail the American Express data validation check.

##### American Express results are optional

As an option, the Enhanced Authorization API can provide American Express results to the Merchant, as shown in the Specification. However, this is optional and not a pre-requisite to submit the Authorization message. The Enhanced Authorization call can be a fire-and-forget call with no return results from American Express.

##### Masked account number

The Enhanced Authorization API does accommodate masked card account numbers. Masked card account numbers are the first six digits of the card number, followed by five zeros, and finally the last four digits of the card number (e.g, `123456000001234`). If a Merchant sends masked account numbers, then the `billing_address` and `billing_postal_code` are additionally required variables for the process in order to match the Enhanced Authorization call and the Authorization message.