Revoke Token API
Revoke Card Member Token
When a Card Member no longer wishes to give a Partner application access to their American Express data, they can choose at any time to revoke access. If, in the future, the Card Member would like to grant access to the Partner application again, the Partner application can simply employ the Grant Access Journey.
NOTE: It is best practice to allow a Card Member the ability to revoke access to their data within the Partner application. When a Card Member re-grants access to the APIs, it is good practice to revoke any old tokens you might have for the Card Member.
Revoke Access Resource URLs
Environment Endpoint Sandbox https://openamex-qa.americanexpress.com/apiplatform/v2/oauth/token_revocation/mac Production https://openamex.americanexpress.com/apiplatform/v2/oauth/token_revocation/mac
The revoke access call must include the following header parameters:
Header Parameter Value Description Content-Type application/x-www-form-urlencoded Authentication MAC id=“aabc17cb-89a3-4bea-9e98-7d030132efb0”, ts=“1366711099”, nonce=“1366711099:AMEX”, mac=“RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ==”
A comma-delimited (no space) list containing: MAC id=“<client_id>”, ts=“A time stamp generated by the Client (in UNIX Epoch time format)”, >nonce=“unique identifier string”, mac=“authentication MAC generated using HMAC SHA256 algorithm” See the OAuth APIs MAC Generation section above to learn how to generate the Authentication value.
x-amex-api-key <client_id> The client_id assigned to the Partner (available on the My Keys dashboard).
The revoke access call must include the following information in the body of the call:
Post Body Value Description grant_type revoke The revoke is the only supported grant type. request_type single The request type, single. access_token <access_token | refresh_token> The Access or Refresh Tokens received as part of the Access Token or the Refresh Token response.
IMPORTANT: Make sure to use grant_type="revoke".
Revoke Access Response
If the call was successful, your response should return the following fields: Response Field Name Description result The status of the result. revoked_tokens Successfully revoked tokens. invalid_tokens The invalid tokens
Here is an example response:

