Access Token Refresh API
Refresh Access Token
Once the Access Token expires, the Partner application must follow one of two paths:
- If a Refresh Token was issued on the previous Access Token call, the Refresh Token can be used to request a new Access Token.
- If no Refresh Token was issued or the Refresh Token has expired, the Partner application will need to restart the Grant Access Journey by prompting the Card Member to re-authenticate with American Express using the Grant Access URL.
Refresh Access Token Resource URLs
Environment Endpoint Sandbox https://openamex-qa.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac Production https://openamex.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac
Each Access Token refresh call must include the following header parameters:
Header Parameter Value Description Content-Type application/x-www-form-urlencoded Authentication MAC id=“aabc17cb-89a3-4bea-9e98-7d030132efb0”, ts=“1366711099”, nonce=“1366711099:AMEX”, mac=“RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ==”
A comma-delimited (no space) list containing: MAC id=“<client_id>”, ts=“A time stamp generated by the Client (in UNIX Epoch time format)”, nonce=“unique identifier string”, mac=“authentication MAC generated using HMAC SHA256 algorithm” See the OAuth APIs MAC Generation section above to learn how to generate the Authentication value.
x-amex-api-key <client_id> The client_id assigned to the Partner (available on the My Keys dashboard)
Each Access Token refresh call must include the following information in the body of the call:
Post Body Value Description grant_type refresh_token The type of grant for post. refresh_token <refresh_token> The refresh token received as part of the Access Token response.
IMPORTANT: Make sure to use grant_type="refresh_token".
Refresh Token Response
A successful call will return the following: Response Field Name Description access_token The access token (expires one day after retrieval). token_type The type of the token (MAC). expires_in The validity of the token in seconds. refresh_token The refresh token (expires 90 days after retrieval). scope The Card Member-authorized scope. mac_key The MAC key. mac_algorithm The MAC algorithm.

