> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# OAuth APIs MAC Generation

##### MAC Generation Steps

Follow these steps to generate the MAC:

1. The HMAC SHA256 algorithm must be used.
2. The base string should be constructed using the following parameters in the listed order with each followed by a newline "`\n`" character (%x0A):

* `client_id`
* `ts` (timestamp in Unix Epoch format)
* `nonce`
* `grant_type`

3. Use `client_secret` as the key (available on the My Keys dashboard).
4. Base-64 encode the output of the raw data.

##### Sample Code to Generate the OAuth APIs MAC

```

import javax.crypto.Mac;
import javax.crypto.spec.SecretKeySpec;
import java.util.*;

public class OAuthAuthenticationHeaderGenerator &#123;
	private static final String HMAC_SHA256_ALGORITHM = "HmacSHA256";
	private static final String NONCE_SUFFIX = ":AMEX";
	private static final String UTF_8_ENC = "UTF-8";
	public static void main(String[] args) throws Exception &#123;
 String clientId = "(client_id_shared_by_API_provider)";
 String clientSecret = "(client_secret_shared_by_API_provider)";
 String grantType = "authorization_code";
 String authenticationMacToken = generateAuthenticationMacToken(clientId, clientSecret, grantType);
 System.out.println(authenticationMacToken);
	&#125;
&#125;
	public static String generateAuthenticationMacToken(String clientId, String clientSecret, String grantType) throws Exception &#123;
 String nonce = UUID.randomUUID().toString() + NONCE_SUFFIX;
 String timeInMillis = String.valueOf((System.currentTimeMillis()));

 StringBuilder baseStringBuilder = new StringBuilder();

 baseStringBuilder.append(clientId);
 baseStringBuilder.append("\n");

 baseStringBuilder.append(timeInMillis);
 baseStringBuilder.append("\n");

 baseStringBuilder.append(nonce);
 baseStringBuilder.append("\n");

 baseStringBuilder.append(grantType);
 baseStringBuilder.append("\n");

 String baseString = baseStringBuilder.toString();
 Mac mac = Mac.getInstance(HMAC_SHA256_ALGORITHM);
 mac.init(new SecretKeySpec(clientSecret.getBytes(UTF_8_ENC), HMAC_SHA256_ALGORITHM));
 String signatureStr = Base64.getEncoder().encodeToString(mac.doFinal(baseString.getBytes(UTF_8_ENC)));

 StringBuilder macTokenBuilder = new StringBuilder();

 macTokenBuilder.append("MAC id=\"");
 macTokenBuilder.append(clientId);

 macTokenBuilder.append("\",ts=\"");
 macTokenBuilder.append(timeInMillis);

 macTokenBuilder.append("\",nonce=\"");
 macTokenBuilder.append(nonce);

 macTokenBuilder.append("\",mac=\"");
 macTokenBuilder.append(signatureStr);
 macTokenBuilder.append("\"");

 return macTokenBuilder.toString();
	&#125;
&#125;
```