Skip to navigation

Update a token's state.

Allows the Token Requester to update the state of a token.

Authentication

Authorizationstring

HMAC (one-way TLS). A MAC authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac

Headers

Accept-LanguagestringRequired<=36 characters

This is en-US.

Content-LanguagestringRequired<=36 characters

This is en-US.

AuthorizationstringRequired<=256 characters

The HMAC authorization header generated as prescribed by American Express API security.

e.g., MAC id="OLQkWT14WtLR0aE63AqtkW2DJppMviSk", ts="1548353658039", nonce="18036bb8-a100-4e02-ab93-328abd67acf2", bodyhash="uRphuQfK6igW44z4Ns/Bo9XdiXlsCdEzTsxdeUBu9j8=", mac="yJ70ObsprC2ygCjzq88Lq0QTKPqlLMIPYpR4O1DBg+Y="

x-amex-api-keystringRequired<=64 characters

The Client ID displayed on the American Express Token Service dashboard.

e.g., OLQkWT14WtLR0aE63AqtkW2DJppMviSk

x-amex-token-requester-idstringRequired<=64 characters

The unique identifier as a Token Requester. Available on the American Express Token Service dashboard.

e.g., devportalTest

x-amex-request-idstringRequired<=64 characters

The unique identifier for the API request to be returned in the response headers.

It is set by the API caller, and it should never be re-used across different transactions.

e.g., AA3434342323

Request

This endpoint expects an object.
token_ref_idstringOptional<=64 characters

The unique reference identifier for a token.

NOTE: This data needs to be stored by the Token Requester for the life cycle API calls, such as /notifications, /status, and /metadata.

notification_typestringOptional<=128 characters

The desired end state of the token specified by the token_ref_id field in the request.

The allowed values are:

  • resume: If the token should be in an active state. An active token can be used for transactions and /metadata endpoint calls.
  • suspend: If the token should be in a suspended state. A suspended token cannot be used for transactions or /metadata endpoint calls.
  • delete: If the token should be permanently deleted. Similar to a suspended token, a deleted token cannot be used for transactions or /metadata endpoint calls. Unlike a suspended token, a deleted token cannot have its state changed.

Response headers

x-amex-request-idstringOptional
The unique identifier sent with the request.
session_idstringOptional
The unique identifier of the session generated by the TSP.

Response

The request has been processed successfully.

Upon a 200 response, the state of the token was successfully changed. No response body is provided when the token state is changed.

Errors

400
Bad Request Error
401
Unauthorized Error
429
Too Many Requests Error
500
Internal Server Error
504
Gateway Timeout Error