> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.americanexpress.ferndocs.com/open-banking/confirmation-of-funds/guide/authorization-flow/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server. # Authorization Flow American Express does not take security lightly. The Grant Access Journey integration will use the OAuth 2.0 security protocol to give Partners access to Card Member data. Before your application is able to access any Card Member data from American Express, the Card Member must first authorize your application. ##### OAuth 2.0 Roles * Partner (your app): The Partner application that is requesting access to American Express Card Member data. * Resource Owner: The American Express Card Member who is providing scope based authorization to the Partner application. * Resource Server: The American Express Application (API) providing the authorized data to the Partner application. ##### Allowed Grant Type * Authorization Code: The grant supported for this product. NOTE: The "Client Credentials" type is not supported for this product. ##### Token Types * Authorization Code: A short-lived token, expiring in 10 minutes and limited to a single use, that can be exchanged for both an Access and Refresh Token. NOTE: If not used, the Grant will expire and the Card Member will need to re-enter the Grant Access Journey to create a new Grant for the Partner application. * Access Token: A token that grants the Client access to a given resource (API). To limit exposure that could result from the loss of this token, it has a lifetime of seven days. * Refresh Token: A long-lived token (lifetime of 90 days) that can be exchanged for a new Access Token when an Access Token expires. ![Authorization Flow](/_fern-img/1256a49e101b89ecf10d29e84bc5ba28ff0ea53ae4e6758415729debcab5a286.webp) Step 1. Card Member Connect Action The Grant Access Journey starts from within the Partner's application when the Card Member invokes an action (e.g., clicks a "Connect with American Express" button/link/etc.). This action will use the Grant Access URL (provided by American Express) to display the American Express login screen to the Card Member. This could be performed in the current browser window, a pop-up window, or a web frame in a mobile application. Once navigated to American Express, the Card Member will authenticate themselves and grant data access to the Partner application. IMPORTANT NOTICE: The previous global.americanexpress.com base authorization URI will be decommissioned as of June 30th, 2020 in order to support SCA requirements for the PSD2 Legislation. If you have not received a m.amex/oauth URI, please reach out to the Open Banking support team for details. Sample Grant Access Journey URL (provided by American Express during environment configuration): `https://<base_authorization_url>?client_id=<client_id>&redirect_uri=<redirect_uri>&scope_list=<scope>` Query Parameters Description `base_authorization_url` The environment-specific URL for the Grant Access page (provided by American Express during environment configuration). `client_id` The `client_id` assigned to the Partner application during the environment configuration process. `redirect_uri` The URL the Card Member will be returned to after granting access to the Partner application. This value must match the redirect URI provided by the Partner application during the environment configuration process. `scope` The business-approved scope(s) assigned to the Partner application during the environment configuration process. For example: Upon clicking on the "Connect with American Express" button, the Partner application might display a pop-up window informing the Card Member that they are going to redirect the page to American Express. ![Leaving American Express warning](/_fern-img/5d0a3072c6a32217dbdbbe2964cd8630c206cfe393e25ebbb20ee8b08f2c4b35.webp) Step 2. Card Member Login To start the authorization process, the Card Member must authenticate with American Express. American Express validates all the query parameters provided within the Grant Access URL. If valid, the Card Member is asked to provide their login credentials. ![Provide credentials](/_fern-img/4372166d68277fe5acb6b3cd34c4c86242e88600624b10db2ac22e78c62e6e54.webp) NOTE: If there is a need to hide/show any link or content on the login page, please email your request to \[American Express Open Banking]\(mailto:[openbanking@devmail.americanexpress.com](mailto:openbanking@devmail.americanexpress.com)?subject=Login%20Page%20Customization-%20AF%20(EU)\&body=Hello,%0D%0A%0D%0AI would like to customize our login page as follows:%0D%0A%0D%0A   • Item 1: %0D%0A%0D%0A   • Item 2: %0D%0A%0D%0AThanks!). The request will be reviewed and addressed based on the nature of the request in compliance with the legal terms of use. Step 3. Card Member Authorization Upon successful login, the Card Member will be presented with a list of the data scopes that the Partner application is requesting to access. The Card Member must carefully verify the scope of the data and click the "Continue" button. ![Review scope and Authorize](/_fern-img/ae47d50f4697ce36b8f1b542918edec09798186b3c866dee0008c608a3fed9d7.webp) Step 4. Card Member Card Selection A list of American Express Cards for the Card Member will be displayed. The Card Member will be given the option to select one or more Cards to connect to the Partner application. If there is a need to filter out any Card type (e.g., show only Corporate Cards), please email your request to \[American Express Open Banking]\(mailto:[openbanking@devmail.americanexpress.com](mailto:openbanking@devmail.americanexpress.com)?subject=Card%20Selection%20Customization-%20AF%20(EU)\&body=Hello,%0D%0A%0D%0AI would like to customize the Card Selection page as follows:%0D%0A%0D%0A   • Item 1: %0D%0A%0D%0A   • Item 2: %0D%0A%0D%0AThanks!). The Card Member must click the "Authorize" button to authorize the Partner application. ![Select cards](/_fern-img/a39f84744e2af95b3cfbfdaf6fbc0f4692f0f800bd354016d45ff1828e4bcbc9.webp) NOTE: The Grant Access Journey supports internationalization. If there is a need to show the Grant Access Journey in a language of your preference, please email your request to \[American Express Open Banking]\(mailto:[openbanking@devmail.americanexpress.com](mailto:openbanking@devmail.americanexpress.com)?subject=Internationalization%20Customization-%20AF%20(EU)\&body=Hello,%0D%0A%0D%0AI would like to customize our login page to use the following language: \%0D%0A%0D%0AThanks!). Step 4 Alternative. Card Member Card Selection - No Available Cards If the Card Member has no available Cards, they will receive the following message. This message may appear if their Card is not eligible under the PSD2 regulations. The Card Member must click the "Return to Partner" button. Returning to the Partner application will skip Steps 5 and 6 without providing the `"authorization code"` to the Partner application. ![Select cards](/_fern-img/e6ede95ea387d704b94da2f9c224fad248ec339774819ce1dfef8655e443a17f.webp) NOTE: The Grant Access Journey cannot be used as third-party OAuth Login mechanism. Only the Grant Access Journey is allowed. Step 5. Partner Authorization Code American Express will verify and validate the authorization request. If valid, the user will receive a confirmation screen that access has been granted. ![Authorization code sent](/_fern-img/b2aa1af83f0f69caa4b6446ca2ea2b27368fd4d75af0f36ae21f1f3fb153d36d.webp) Step 6. Redirect to the Partner Application When the user selects the "Return to Partner" button, American Express will redirect the browser back to the Partner application using the configured redirect\_uri. A separate "authorization code" for each Card the Card Member selected in the authorization process will be added to the querystring of the redirect\_uri. The redirect URI format will look like the following: `https://<redirect_uri>?authtoken=authorization_code1,authorization_code2`