Access Token Retrieval API
Retrieve initial Access Tokens
Leveraging the one-time authorization code returned from the Grant Access Journey, the Partner application must request the Access Token and Refresh Token by using the OAuth API Access Token endpoint.
Retrieve Access Token Resource URLs
Environment Endpoint Sandbox https://openamex-qa.americanexpress.com/apiplatform/v2/oauth/token/mac Production https://openamex.americanexpress.com/apiplatform/v2/oauth/token/mac
The following header information must be provided:
Header Parameter Value / Example Description Content-Type application/x-www-form-urlencoded Authentication MAC id=“aabc17cb-89a3-4bea-9e98-7d030132efb0”, ts=“1366711099”, nonce=“1366711099:AMEX”, mac=“RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ==”
A comma-delimited (no space) list containing: MAC id=“<client_id>”, ts=“A time stamp generated by the Client (in UNIX Epoch time format)”, nonce=“unique identifier string”, mac=“authentication MAC generated using HMAC SHA256 algorithm” See the OAuth APIs MAC Generation section below to learn how to generate the authentication value.
x-amex-api-key <client_id> The client_id assigned to the Partner (available on the My Keys dashboard)
The following information must be provided in the POST body:
Post Body Value Description grant_type authorization_code The authorization_code is the only supported grant type for this product. code <authorization_code> Authorization code returned as part of the redirect URI during authorization process. scope FINS_CONF_FUND
The FINS_CONF_FUND is the scope string you should use.
A space-delimited list of business approved scopes assigned to the Partner application as part of registration process.
redirect_uri <redirect_uri> The redirect URI provided during the registration process.
Access Token Response
A successful call will return the following: Response Field Name Description access_token The access token (expires one day after retrieval). token_type The type of the token (MAC). expires_in The validity of the token in seconds. refresh_token The refresh token (expires 90 days after retrieval). scope The Card Member-authorized scope. mac_key The MAC key. mac_algorithm The MAC algorithm. Example Access Token response:
IMPORTANT: The access_token, refresh_token, and mac_key must be safely stored. If any of these are lost, your ability to call any of the APIs will be lost. The remedy is for the Card Member to go through the Grant Access Journey again.

