> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Revoke Token API

##### Revoke Card Member Token

When a Card Member no longer wishes to give a Partner application access to their American Express data, they can choose at any time to revoke access. If, in the future, the Card Member would like to grant access to the Partner application again, the Partner application can simply employ the Grant Access Journey.

NOTE: It is best practice to allow a Card Member the ability to revoke access to their data within the Partner application. When a Card Member re-grants access to the APIs, it is good practice to revoke any old tokens you might have for the Card Member.

##### Revoke Access Resource URLs

Environment Endpoint Sandbox [https://openamex-qa.americanexpress.com/apiplatform/v2/oauth/token\_revocation/mac](https://openamex-qa.americanexpress.com/apiplatform/v2/oauth/token_revocation/mac) Production [https://openamex.americanexpress.com/apiplatform/v2/oauth/token\_revocation/mac](https://openamex.americanexpress.com/apiplatform/v2/oauth/token_revocation/mac)

The `revoke access` call must include the following header parameters:

Header Parameter Value Description `Content-Type` application/x-www-form-urlencoded `Authentication` MAC id="aabc17cb-89a3-4bea-9e98-7d030132efb0", ts="1366711099", nonce="1366711099:AMEX", mac="RUNXQXRKeitOTERtR HhEcHdsUzl0ZkQ3aU5zPQ=="

A comma-delimited (no space) list containing: MAC id="\<client\_id>", ts="A time stamp generated by the Client (in UNIX Epoch time format)", >nonce="unique identifier string", mac="authentication MAC generated using HMAC SHA256 algorithm" See the OAuth APIs MAC Generation section above to learn how to generate the Authentication value.

`x-amex-api-key` \<client\_id> The `client_id` assigned to the Partner (available on the My Keys dashboard).

The `revoke access` call must include the following information in the body of the call:

Post Body Value Description `grant_type` revoke The `revoke` is the only supported grant type. `request_type` single The request type, `single`. `access_token` \<access\_token | refresh\_token> The Access or Refresh Tokens received as part of the Access Token or the Refresh Token response.

IMPORTANT: Make sure to use `grant_type="revoke"`.

##### Revoke Access Response

If the call was successful, your response should return the following fields: Response Field Name Description result The status of the result. revoked\_tokens Successfully revoked tokens. invalid\_tokens The invalid tokens

Here is an example response:

```
&#123;
	"result": "success",
	"revoked_tokens":
	[
	"00142369-3dda-49b4-8671-efaa9c7d3e91"
	],
	"invalid_tokens":
	[
	""
	]
&#125;
```