> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.americanexpress.ferndocs.com/open-banking/confirmation-of-funds/guide/access-token-retrieval-api/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server. # Access Token Retrieval API ##### Retrieve initial Access Tokens Leveraging the one-time authorization code returned from the Grant Access Journey, the Partner application must request the Access Token and Refresh Token by using the OAuth API Access Token endpoint. ##### Retrieve Access Token Resource URLs Environment Endpoint Sandbox [https://openamex-qa.americanexpress.com/apiplatform/v2/oauth/token/mac](https://openamex-qa.americanexpress.com/apiplatform/v2/oauth/token/mac) Production [https://openamex.americanexpress.com/apiplatform/v2/oauth/token/mac](https://openamex.americanexpress.com/apiplatform/v2/oauth/token/mac) The following header information must be provided: Header Parameter Value / Example Description `Content-Type` application/x-www-form-urlencoded `Authentication` MAC id="aabc17cb-89a3-4bea-9e98-7d030132efb0", ts="1366711099", nonce="1366711099:AMEX", mac="RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ==" A comma-delimited (no space) list containing: MAC id="\", ts="A time stamp generated by the Client (in UNIX Epoch time format)", nonce="unique identifier string", mac="authentication MAC generated using HMAC SHA256 algorithm" See the OAuth APIs MAC Generation section below to learn how to generate the authentication value. `x-amex-api-key` \ The `client_id` assigned to the Partner (available on the My Keys dashboard) The following information must be provided in the POST body: Post Body Value Description `grant_type` authorization\_code The `authorization_code` is the only supported grant type for this product. `code` \ Authorization code returned as part of the redirect URI during authorization process. `scope` FINS\_CONF\_FUND The `FINS_CONF_FUND` is the scope string you should use. A space-delimited list of business approved scopes assigned to the Partner application as part of registration process. `redirect_uri` \ The redirect URI provided during the registration process. ##### Access Token Response A successful call will return the following: Response Field Name Description `access_token` The access token (expires one day after retrieval). `token_type` The type of the token (`MAC`). `expires_in` The validity of the token in seconds. `refresh_token` The refresh token (expires 90 days after retrieval). `scope` The Card Member-authorized scope. `mac_key` The MAC key. `mac_algorithm` The MAC algorithm. Example Access Token response: ``` { "access_token": "00000000-d8v7-262f-33ot-9vh35dsj8x8m", "token_type": "mac", "expires_in": 2592000, "refresh_token": "00000000-cfe6-495d-98cc-7fb1be768a3d", "scope": "FINS_CONF_FUND", "mac_key": "33f48435-06ae-42e1-816a-b80653562a56", "mac_algorithm": "hmac-sha-256" } ``` IMPORTANT: The `access_token`, `refresh_token`, and `mac_key` must be safely stored. If any of these are lost, your ability to call any of the APIs will be lost. The remedy is for the Card Member to go through the Grant Access Journey again.