Skip to navigation

Access Token Refresh API

Refresh Access Token

Once the Access Token expires, the Partner application must follow one of two paths:

  1. If a Refresh Token was issued on the previous Access Token call, the Refresh Token can be used to request a new Access Token.
  2. If no Refresh Token was issued or the Refresh Token has expired, the Partner application will need to restart the Grant Access Journey by prompting the Card Member to re-authenticate with American Express using the Grant Access URL.
Refresh Access Token Resource URLs

Environment Endpoint Sandbox https://openamex-qa.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac Production https://openamex.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac

Each Access Token refresh call must include the following header parameters:

Header Parameter Value Description Content-Type application/x-www-form-urlencoded Authentication MAC id=“aabc17cb-89a3-4bea-9e98-7d030132efb0”, ts=“1366711099”, nonce=“1366711099:AMEX”, mac=“RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ==”

A comma-delimited (no space) list containing: MAC id=“<client_id>”, ts=“A time stamp generated by the Client (in UNIX Epoch time format)”, nonce=“unique identifier string”, mac=“authentication MAC generated using HMAC SHA256 algorithm” See the OAuth APIs MAC Generation section above to learn how to generate the Authentication value.

x-amex-api-key <client_id> The client_id assigned to the Partner (available on the My Keys dashboard)

Each Access Token refresh call must include the following information in the body of the call:

Post Body Value Description grant_type refresh_token The type of grant for post. refresh_token <refresh_token> The refresh token received as part of the Access Token response.

IMPORTANT: Make sure to use grant_type="refresh_token".

Refresh Token Response

A successful call will return the following: Response Field Name Description access_token The access token (expires one day after retrieval). token_type The type of the token (MAC). expires_in The validity of the token in seconds. refresh_token The refresh token (expires 90 days after retrieval). scope The Card Member-authorized scope. mac_key The MAC key. mac_algorithm The MAC algorithm.