> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Access Token Refresh API

##### Refresh Access Token

Once the Access Token expires, the Partner application must follow one of two paths:

1. If a Refresh Token was issued on the previous Access Token call, the Refresh Token can be used to request a new Access Token.
2. If no Refresh Token was issued or the Refresh Token has expired, the Partner application will need to restart the Grant Access Journey by prompting the Card Member to re-authenticate with American Express using the Grant Access URL.

##### Refresh Access Token Resource URLs

Environment Endpoint Sandbox [https://openamex-qa.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac](https://openamex-qa.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac) Production [https://openamex.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac](https://openamex.americanexpress.com/apiplatform/v1/oauth/token/refresh/mac)

Each Access Token refresh call must include the following header parameters:

Header Parameter Value Description `Content-Type` application/x-www-form-urlencoded `Authentication` MAC id="aabc17cb-89a3-4bea-9e98-7d030132efb0", ts="1366711099", nonce="1366711099:AMEX", mac="RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ=="

A comma-delimited (no space) list containing: MAC id="\<client\_id>", ts="A time stamp generated by the Client (in UNIX Epoch time format)", nonce="unique identifier string", mac="authentication MAC generated using HMAC SHA256 algorithm" See the OAuth APIs MAC Generation section above to learn how to generate the Authentication value.

`x-amex-api-key` \<client\_id> The `client_id` assigned to the Partner (available on the My Keys dashboard)

Each Access Token refresh call must include the following information in the body of the call:

Post Body Value Description `grant_type` refresh\_token The type of grant for post. `refresh_token` \<refresh\_token> The refresh token received as part of the Access Token response.

IMPORTANT: Make sure to use `grant_type="refresh_token"`.

##### Refresh Token Response

A successful call will return the following: Response Field Name Description `access_token` The access token (expires one day after retrieval). `token_type` The type of the token (`MAC`). `expires_in` The validity of the token in seconds. `refresh_token` The refresh token (expires 90 days after retrieval). `scope` The Card Member-authorized scope. `mac_key` The MAC key. `mac_algorithm` The MAC algorithm.