> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# API Invocation: OAuth to Data flow

### API Invocation: OAuth to Confirmation of Funds API Flow

##### Step 1: Convert Authorization Code into an Access Token

Now that the Partner application has authorization to access the Card Member's data and has been provided a one-time authorization code, the application must request the Access Token, Refresh Token, and MAC Key by using the Access Token Retrieval API.

NOTE: The MAC generation logic is specific to the OAuth resources. See the OAuth APIs MAC Generation guide for specific details.

Example Access Token response:

```
&#123;
	"access_token": "00000000-d8v7-262f-33ot-9vh35dsj8x8m",
	"token_type": "mac",
	"expires_in": `2592000`,
	"refresh_token": "00000000-cfe6-495d-98cc-7fb1be768a3d",
	"scope": "FINS_CONF_FUND",
	"mac_key": "33f48435-06ae-42e1-816a-b80653562a56",
	"mac_algorithm": "hmac-sha-256"
&#125;
```

##### Step 2: Use the Access Token to call the Data APIs

When calling the Confirmation of Funds API, the `access_token` becomes your Client ID and the `mac_key` is used as the Secret in generating the MAC. For the details of the Confirmation of Funds API see the: API Specification

.

NOTE: The MAC generation logic is specific to the Confirmation of Funds API. See the Confirmation of Funds MAC Generation guide for specifics.

##### Example Sandbox resource

Method Endpoint `POST` [https://openamex-qa.americanexpress.com/servicing/v1/card\_member/funds/confirmations](https://openamex-qa.americanexpress.com/servicing/v1/card_member/funds/confirmations)