> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.americanexpress.ferndocs.com/open-banking/confirmation-of-funds/guide/oauth-apis-mac-generation/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server. # OAuth APIs MAC Generation ##### MAC Generation Steps Follow these steps to generate the MAC: 1. The HMAC SHA256 algorithm must be used. 2. The base string should be constructed using the following parameters in the listed order with each followed by a newline "`\n`" character (%x0A): * `client_id` * `ts` (timestamp in Unix Epoch format) * `nonce` * `grant_type` 3. Use `client_secret` as the key (available on the My Keys dashboard). 4. Base-64 encode the output of the raw data. ##### Sample Code to Generate the OAuth APIs MAC ``` import javax.crypto.Mac; import javax.crypto.spec.SecretKeySpec; import java.util.*; public class OAuthAuthenticationHeaderGenerator { private static final String HMAC_SHA256_ALGORITHM = "HmacSHA256"; private static final String NONCE_SUFFIX = ":AMEX"; private static final String UTF_8_ENC = "UTF-8"; public static void main(String[] args) throws Exception { String clientId = "(client_id_shared_by_API_provider)"; String clientSecret = "(client_secret_shared_by_API_provider)"; String grantType = "authorization_code"; String authenticationMacToken = generateAuthenticationMacToken(clientId, clientSecret, grantType); System.out.println(authenticationMacToken); } } public static String generateAuthenticationMacToken(String clientId, String clientSecret, String grantType) throws Exception { String nonce = UUID.randomUUID().toString() + NONCE_SUFFIX; String timeInMillis = String.valueOf((System.currentTimeMillis())); StringBuilder baseStringBuilder = new StringBuilder(); baseStringBuilder.append(clientId); baseStringBuilder.append("\n"); baseStringBuilder.append(timeInMillis); baseStringBuilder.append("\n"); baseStringBuilder.append(nonce); baseStringBuilder.append("\n"); baseStringBuilder.append(grantType); baseStringBuilder.append("\n"); String baseString = baseStringBuilder.toString(); Mac mac = Mac.getInstance(HMAC_SHA256_ALGORITHM); mac.init(new SecretKeySpec(clientSecret.getBytes(UTF_8_ENC), HMAC_SHA256_ALGORITHM)); String signatureStr = Base64.getEncoder().encodeToString(mac.doFinal(baseString.getBytes(UTF_8_ENC))); StringBuilder macTokenBuilder = new StringBuilder(); macTokenBuilder.append("MAC id=\""); macTokenBuilder.append(clientId); macTokenBuilder.append("\",ts=\""); macTokenBuilder.append(timeInMillis); macTokenBuilder.append("\",nonce=\""); macTokenBuilder.append(nonce); macTokenBuilder.append("\",mac=\""); macTokenBuilder.append(signatureStr); macTokenBuilder.append("\""); return macTokenBuilder.toString(); } } ```