Skip to navigation

API Invocation: OAuth to Data flow

API Invocation: OAuth to Confirmation of Funds API Flow

Step 1: Convert Authorization Code into an Access Token

Now that the Partner application has authorization to access the Card Member’s data and has been provided a one-time authorization code, the application must request the Access Token, Refresh Token, and MAC Key by using the Access Token Retrieval API.

NOTE: The MAC generation logic is specific to the OAuth resources. See the OAuth APIs MAC Generation guide for specific details.

Example Access Token response:

{
"access_token": "00000000-d8v7-262f-33ot-9vh35dsj8x8m",
"token_type": "mac",
"expires_in": `2592000`,
"refresh_token": "00000000-cfe6-495d-98cc-7fb1be768a3d",
"scope": "FINS_CONF_FUND",
"mac_key": "33f48435-06ae-42e1-816a-b80653562a56",
"mac_algorithm": "hmac-sha-256"
}
Step 2: Use the Access Token to call the Data APIs

When calling the Confirmation of Funds API, the access_token becomes your Client ID and the mac_key is used as the Secret in generating the MAC. For the details of the Confirmation of Funds API see the: API Specification

.

NOTE: The MAC generation logic is specific to the Confirmation of Funds API. See the Confirmation of Funds MAC Generation guide for specifics.

Example Sandbox resource

Method Endpoint POST https://openamex-qa.americanexpress.com/servicing/v1/card_member/funds/confirmations