> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Create an account enrollment for agent-executed commerce

POST https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments
Content-Type: application/json

Enrolls an account for agent-executed commerce. This API supports a two-phase enrollment flow when additional verification is required.The initial call is used to submit enrollment details for validation and risk assessment.If the response indicates that step-up authentication is required, call the enrollments API again with the issued enrollmentId and step-up verification result to complete enrollment.

Reference: https://developer.americanexpress.ferndocs.com/payment-services/agentic-commerce/api-reference/enrollments/enroll

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://apisandboxm.americanexpress.com` (sandbox, default)
- `https://apigwm.americanexpress.com` (production)

## Request

### Headers

- `Authorization` (string, required) — The OAuth authorization header generated as prescribed in the Oauth 2.0 guide
- `trackingId` (string, required) — A unique identifier for request tracking.
- `agentId` (string, required) — Agent's unique identifier.

### Body (application/json)

This endpoint expects an EnrollmentsRequest.

- `EnrollmentsRequest`

## Response

### 200

Successful response

- `EnrollmentsResponse`

## Errors

### 400 Bad Request Error

Bad request

- `error` (ErrorInvalidFieldsResponseError, required)

### 401 Unauthorized Error

Unauthorized

- `any`

### 404 Not Found Error

Resource not found

- `any`

### 422 Unprocessable Entity Error

Unprocessable entity

- `error` (ErrorBusinessExceptionResponseError, required)

### 500 Internal Server Error

Service error

- `error` (ErrorSystemDownResponseError, required)

## Types

### The initial request used for account validation and risk assessment (before step-up authentication).

The initial request used for account validation and risk assessment.

- `account` (Account, required) — Account details for the enrollment.
- `risk` (EnrollmentsRisk, required) — Risk and device context associated with the request.
- `user` (User, required) — The Customer's information associated with the enrollment.
- `agent` (Agent, required) — The metadata describing the agent initiating the request.
- `termsAndConditions` (TermsAndConditions, optional) — Terms and conditions accepted by the Customer.

### The follow-up request used to complete enrollment after step-up authentication

The Follow-up request used to complete enrollment after step-up authentication.

- `enrollmentId` (string, required) — A unique identifier for the enrolled account. Required when submitting step-up verification. Returned in the initial enrollment response.
- `stepUpVerification` (StepUpVerification, required) — The step-up verification details for completing authentication.

### EnrollmentsResponseBeforeStepUp

The response returned when enrollment is pending additional authentication. Includes details required to complete step-up verification.

- `stepUpAuthenticationRequired` (enum, required) — Indicates whether additional authentication is required to complete enrollment. When YES, the stepUpSessionId and availableChallenges fields will be populated.
  - Allowed values: `YES`, `NO`
- `enrollmentId` (string, required) — A unique identifier for the enrolled account.
- `enrollmentStatus` (enum, required) — The current status of the enrollment.
  - Allowed values: `PENDING_STEP_UP`
- `stepUpSessionId` (string, required) — An identifier for the step-up session associated with the enrollment.
- `accountMetadata` (AccountMetadata, required) — The metadata associated with the enrolled account.
- `issuer` (Issuer, required) — The issuer details associated with the enrolled account.
- `availableChallenges` (list of AvailableChallengesItems, required) — A list of available authentication challenges for completing step-up verification.

### EnrollmentsResponseAfterStepUp

The response returned after enrollment is successfully completed following step-up authentication. Includes account details associated with the enrollment.

- `enrollmentId` (string, required) — A unique identifier for the enrolled account.
- `enrollmentStatus` (enum, required) — The current status of the enrollment.
  - Allowed values: `ACTIVE`
- `accountMetadata` (AccountMetadata, required) — The metadata associated with the enrolled account.
- `issuer` (Issuer, required) — Issuer details associated with the account.

### ErrorInvalidFieldsResponseError

- `code` (string, required) — An error code that is returned when request validation fails.
- `description` (string, required) — An error description that is returned when request validation fails.
- `type` (enum, required)
  - Allowed values: `USER_EXCEPTION`
- `param` (string, optional) — The parameter that caused the error, if applicable

### ErrorBusinessExceptionResponseError

- `code` (string, required) — An error code returned when a business rule validation fails.
- `description` (string, required) — An error description returned when a business rule validation fails.
- `type` (enum, required)
  - Allowed values: `BUSINESS_EXCEPTION`

### ErrorSystemDownResponseError

- `code` (enum, required)
  - Allowed values: `20001`
- `description` (enum, required)
  - Allowed values: `Internal server error`
- `type` (enum, required)
  - Allowed values: `SYSTEM_EXCEPTION`

### Account

The PAN details needed to enroll in agent-executed commerce.

- `type` (enum, required) — Specifies the type of the account identifier provided in the request. Use CARD\_NUMBER for a Primary Account Number (PAN)
  - Allowed values: `CARD_NUMBER`
- `panNumber` (string, required) — The American Express Credit Card Number. The PAN must be 15 digits as per the ISO/IEC 7812 standard.
- `expiryMonth` (string, required) — The expiry month of the account in MM format. The month must be between 01 and 12.
- `expiryYear` (string, required) — The expiry year of the account in YYYY format. The year must be the current year or later.
- `cid` (string, optional) — A four-digit Card Identification Number (CID) associated with the Primary Account Number (PAN). Required when the type is CARD\_NUMBER and the risk.account.fpanSource is USER\_INPUT, indicating that the Card details were manually entered by the user.

### EnrollmentsRisk

Risk signals related to enrollments. These signals are used to assess the risk of enrolling a card into agent-executed commerce. The risk assessment can be used by the Agent to determine whether to allow the enrollment, require additional verification, or block the enrollment altogether.

- `account` (AccountRisk, required) — Risk signals related to the account being enrolled.
- `device` (DeviceRisk, required) — Risk signals related to the device on which the account is being enrolled.
- `metadata` (Metadata, optional) — A generic enrollmentRisk metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### User

The Customer's identity information associated with the enrollment.

### Agent

Information about the agent facilitating the commerce transaction.

- `llmVersion` (string, required) — The version of the language model used by the agent.
- `llmPlatform` (enum, required) — The platform hosting the language model used by the agent.
  - Allowed values: `OPEN_AI`
- `agentName` (string, required) — The name of the agent or application initiating the request.

### TermsAndConditions

Details of the terms and conditions accepted by the Customer.

- `version` (string, optional) — The version identifier of the terms and conditions accepted.
- `acceptanceTs` (datetime, optional) — The timestamp indicating when the terms and conditions were accepted, in ISO 8601 format.

### StepUpVerification

The step-up verification details for completing authentication. Required when submitting a step-up challenge response. This object will depend on the challenge type returned in the initial API response when the step-up flow is initiated.

### AccountMetadata

The metadata associated with the enrolled account.

- `displayPanNumber` (string, required) — Last four digits of the Primary Account Number (PAN).
- `productName` (string, required) — The product name associated with the account.
- `cardArt` (CardArt, required) — A visual representation of the Card associated with the account.
- `paymentAccountReference` (string, required) — A non-financial reference assigned to each unique Primary Account Number (PAN) and used to link a Payment Account represented by that PAN to affiliated Payment Tokens. The value is a 29-character uppercase alphanumeric string.

### Issuer

Issuer details associated with the account.

- `issuerLogoUrl` (string, required) — The URL for the Issuer logo.
- `issuerName` (string, required) — The name of the Issuer.
- `issuerContactNumber` (string, required) — The Customer's support contact number for the Issuer.
- `issuerTermsUrl` (string, optional) — The URL for the Issuer terms and conditions.

### AvailableChallengesItems

### AccountRisk

Risk signals related to the account being enrolled.

- `actionChannel` (enum, required) — The client platform from which the enrollment request originated. WEB indicates a browser-based flow, IOS and ANDROID indicate native mobile applications. This field is used for channel-specific processing and risk evaluation.
  - Allowed values: `WEB`, `IOS`, `ANDROID`, `OTHER`
- `fpanSource` (enum, required) — The source from which the Primary Account Number (FPAN) was obtained.
  - Allowed values: `USERINPUT`, `ONFILE`, `OTHER`
- `panTenureOnFile` (double, optional) — The number of weeks since the card account was first stored on file with the Partner. Represents the tenure of the account and may be used as a risk signal.
- `accountRiskScore` (string, optional) — A risk score provided by the Partner for the account. Values range from 1 (Very Low) to 5 (Very High)., on a scale of 1-5 (1 = Very Low, 2 = Low, 3 = Medium, 4 = High, 5 = Very High).
- `distinctBillingLastNameCount` (string, optional) — The number of distinct billing last names associated with the account.
- `recentSecurityActivity` (string, optional) — The number of days since the most recent password or two-factor authentication change.
- `emailTenure` (double, optional) — The number of weeks since the email address was first associated with the account.
- `mostRecentAccountPaymentMethodChangeActivity` (double, optional) — The number of days since the most recent change to the account's payment method.
- `accountAndCardNameMatch` (enum, optional) — Indicates whether the account holder name matches the cardholder name.
  - Allowed values: `YES`, `NO`
- `agentAccountLocale` (string, optional) — The locale of the Agent's account, used for regional formatting and compliance behavior.

### DeviceRisk

- `deviceId` (string, optional) — A stable identifier for the device associated with the account.
- `devicePlatform` (enum, optional) — The operating platform of the device.
  - Allowed values: `IOS`, `ANDROID`, `OTHER`
- `ipAddress` (string, optional) — The IP address observed for the device at the time of the request.
- `deviceRiskScore` (string, optional) — A risk score provided by the Partner for the device, on a scale of 1-5 (1 = Very Low, 2 = Low, 3 = Medium, 4 = High, 5 = Very High).
- `deviceTenure` (double, optional) — The number of weeks since the device was first associated with the account.
- `browserUserAgent` (string, optional) — The user agent string reported by the device or browser.
- `deviceCountry` (string, optional) — The country associated with the device, in ISO 3166-1 alpha-2 format.
- `tlsFingerprint` (string, optional) — The TLS fingerprint associated with the device connection.
- `location` (DeviceRiskLocation, optional) — The geographic coordinates of the device at the time of the request.

### Metadata

### Email Address

- `email` (string, required) — The Customer's email address in RFC 5322 format.

### Phone Number

- `phone` (string, required) — The Customer's phone number in international format, starting with '+' followed by digits.

### The response object for SafeKey<sup>&reg;</sup> authentication challenge

This object will depend on the challenge type returned in the initial API response when the step-up flow is initiated.

- `safeKeyAuthenticationResponse` (StepUpVerificationOneOf0SafeKeyAuthenticationResponse, required) — The result of SafeKey® authentication.

### The response object for issuer surface authentication challenge

- `issuerSurfaceAuthenticationResponse` (StepUpVerificationOneOf1IssuerSurfaceAuthenticationResponse, required) — The result of issuer surface authentication for step-up integration.

### The response object for SECURE_PUSH authentication challenge

- `securePushAuthenticationResponse` (StepUpVerificationOneOf2SecurePushAuthenticationResponse, required) — Confirmation when authentication is complete using SECURE_PUSH

### The response object for SMS_OTP or EMAIL_OTP authentication challenge

- `validateAuthenticationCode` (StepUpVerificationOneOf3ValidateAuthenticationCode, required) — The one-time passcode entered by the user for step-up verification using SMS_OTP or EMAIL_OTP.

### CardArt

- `cardArtUrl` (string, required) — The URL for the card artwork.
- `foregroundColor` (string, required) — The foreground color associated with the card artwork.

### AvailableChallengesItems0

- `type` (enum, required) — The authentication method.
  - Allowed values: `ISSUER_SURFACE`
- `issuerSurface` (AvailableChallengesItemsOneOf0IssuerSurface, required) — Issuer surface authentication details.

### AvailableChallengesItems1

- `type` (enum, required) — The authentication method.
  - Allowed values: `SECURE_PUSH`
- `securePushAuthentication` (AvailableChallengesItemsOneOf1SecurePushAuthentication, required) — Secure push authentication details.

### AvailableChallengesItems2

- `type` (enum, required) — The authentication method.
  - Allowed values: `SAFEKEY`
- `safeKeyAuthentication` (AvailableChallengesItemsOneOf2SafeKeyAuthentication, required) — SafeKey® authentication details.

### AvailableChallengesItems3

- `type` (enum, required) — The authentication method.
  - Allowed values: `SMS_OTP`
- `channelId` (string, required) — A unique identifier of the phone channel to deliver OTP.
- `value` (string, required) — The masked phone number where the OTP will be delivered.

### AvailableChallengesItems4

- `type` (enum, required) — The authentication method.
  - Allowed values: `EMAIL_OTP`
- `channelId` (string, required) — A unique identifier of the email channel to deliver OTP.
- `value` (string, required) — The masked email address where the OTP will be delivered.

### DeviceRiskLocation

The geographic coordinates of the device at the time of the request.

- `longitude` (string, optional) — The longitude coordinates of the device.
- `latitude` (string, optional) — The latitude coordinates of the device.

### StepUpVerificationOneOf0SafeKeyAuthenticationResponse

The result of SafeKey® authentication.

- `riskToken` (string, required) — The encrypted risk token used for SafeKey® authentication.

### StepUpVerificationOneOf1IssuerSurfaceAuthenticationResponse

The result of issuer surface authentication for step-up integration.

- `authenticationToken` (string, required) — The encrypted authentication token used for authentication using ISSUER_SURFACE.

### StepUpVerificationOneOf2SecurePushAuthenticationResponse

Confirmation when authentication is complete using SECURE_PUSH

- `authenticationToken` (string, required) — The encrypted authentication token used for authentication using SECURE_PUSH

### StepUpVerificationOneOf3ValidateAuthenticationCode

The one-time passcode entered by the user for step-up verification using SMS_OTP or EMAIL_OTP.

- `value` (string, required) — The one-time passcode entered by the user

### AvailableChallengesItemsOneOf0IssuerSurface

Issuer surface authentication details.

- `url` (string, required) — URL for initiating issuer surface authentication.
- `authenticationToken` (string, required) — The encrypted authentication token associated with the authentication request.

### AvailableChallengesItemsOneOf1SecurePushAuthentication

Secure push authentication details.

- `authenticationToken` (string, optional) — The encrypted authentication token associated with the authentication request.

### AvailableChallengesItemsOneOf2SafeKeyAuthentication

SafeKey® authentication details.

- `riskToken` (string, required) — The encrypted risk token associated with the authentication request.
- `messageCategory` (enum, required) — SafeKey® message category.
  - Allowed values: `01`, `02`
- `threeDSRequestorAuthenticationInd` (enum, required) — SafeKey® authentication indicator.
  - Allowed values: `81`, `82`

## Examples

### The enrollments response before completing step-up verification.

**Response**

```json
{
  "accountMetadata": {
    "cardArt": {
      "cardArtUrl": "string",
      "foregroundColor": "string"
    },
    "displayPanNumber": "string",
    "paymentAccountReference": "string",
    "productName": "string"
  },
  "availableChallenges": {
    "0": {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  },
  "enrollmentId": "string",
  "enrollmentStatus": "PENDING_STEP_UP",
  "issuer": {
    "issuerContactNumber": "string",
    "issuerLogoUrl": "string",
    "issuerName": "string",
    "issuerTermsUrl": "string"
  },
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python The enrollments response before completing step-up verification.
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId"
}

response = requests.post(url, headers=headers)

print(response.json())
```

```javascript The enrollments response before completing step-up verification.
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', agentId: 'agentId', trackingId: 'trackingId'}
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The enrollments response before completing step-up verification.
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The enrollments response before completing step-up verification.
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'

response = http.request(request)
puts response.read_body
```

```java The enrollments response before completing step-up verification.
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .asString();
```

```php The enrollments response before completing step-up verification.
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The enrollments response before completing step-up verification.
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
IRestResponse response = client.Execute(request);
```

```swift The enrollments response before completing step-up verification.
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### The enrollments response after completing step-up verification.

**Response**

```json
{
  "accountMetadata": {
    "cardArt": {
      "cardArtUrl": "string",
      "foregroundColor": "string"
    },
    "displayPanNumber": "string",
    "paymentAccountReference": "string",
    "productName": "string"
  },
  "enrollmentId": "string",
  "enrollmentStatus": "ACTIVE",
  "issuer": {
    "issuerContactNumber": "string",
    "issuerLogoUrl": "string",
    "issuerName": "string",
    "issuerTermsUrl": "string"
  }
}
```

**SDK Code**

```python The enrollments response after completing step-up verification.
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId"
}

response = requests.post(url, headers=headers)

print(response.json())
```

```javascript The enrollments response after completing step-up verification.
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', agentId: 'agentId', trackingId: 'trackingId'}
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The enrollments response after completing step-up verification.
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The enrollments response after completing step-up verification.
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'

response = http.request(request)
puts response.read_body
```

```java The enrollments response after completing step-up verification.
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .asString();
```

```php The enrollments response after completing step-up verification.
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The enrollments response after completing step-up verification.
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
IRestResponse response = client.Execute(request);
```

```swift The enrollments response after completing step-up verification.
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### The initial request for validation and risk assessment (before step-up verification)

**Request**

```json
{
  "account": {
    "cid": "1234",
    "expiryMonth": "12",
    "expiryYear": "2030",
    "panNumber": "122000000000003",
    "type": "CARD_NUMBER"
  },
  "agent": {
    "agentName": "NexusAI",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "gpt-4.1"
  },
  "risk": {
    "account": {
      "accountAndCardNameMatch": "YES",
      "accountRiskScore": "3",
      "actionChannel": "WEB",
      "agentAccountLocale": "en-US",
      "distinctBillingLastNameCount": "2",
      "emailTenure": 5,
      "fpanSource": "USERINPUT",
      "mostRecentAccountPaymentMethodChangeActivity": 24,
      "panTenureOnFile": 25,
      "recentSecurityActivity": "30"
    },
    "device": {
      "browserUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)",
      "deviceCountry": "US",
      "deviceId": "565266",
      "devicePlatform": "IOS",
      "deviceRiskScore": "4",
      "deviceTenure": 26,
      "ipAddress": "192.168.1.1",
      "location": {
        "latitude": "+025.3191",
        "longitude": "-084.0606"
      },
      "tlsFingerprint": "771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0"
    },
    "metadata": {
      "additionalProperty": "string",
      "ipReputation": "low_risk"
    }
  },
  "termsAndConditions": {
    "acceptanceTs": "2026-03-18T14:32:45Z",
    "version": "v2.1"
  },
  "user": {
    "accountId": "user-12345",
    "billingAddress": {
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "postalCode": "12345",
      "state": "NY"
    },
    "email": "someone@example.com",
    "firstName": "Jane",
    "lastName": "Jones",
    "userEmailHash": "5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a",
    "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
  }
}
```

**Response**

```json
{
  "accountMetadata": {
    "cardArt": {
      "cardArtUrl": "string",
      "foregroundColor": "string"
    },
    "displayPanNumber": "string",
    "paymentAccountReference": "string",
    "productName": "string"
  },
  "availableChallenges": {
    "0": {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  },
  "enrollmentId": "string",
  "enrollmentStatus": "PENDING_STEP_UP",
  "issuer": {
    "issuerContactNumber": "string",
    "issuerLogoUrl": "string",
    "issuerName": "string",
    "issuerTermsUrl": "string"
  },
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python The initial request for validation and risk assessment (before step-up verification)
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

payload = {
    "account": {
        "cid": "1234",
        "expiryMonth": "12",
        "expiryYear": "2030",
        "panNumber": "122000000000003",
        "type": "CARD_NUMBER"
    },
    "agent": {
        "agentName": "NexusAI",
        "llmPlatform": "OPEN_AI",
        "llmVersion": "gpt-4.1"
    },
    "risk": {
        "account": {
            "accountAndCardNameMatch": "YES",
            "accountRiskScore": "3",
            "actionChannel": "WEB",
            "agentAccountLocale": "en-US",
            "distinctBillingLastNameCount": "2",
            "emailTenure": 5,
            "fpanSource": "USERINPUT",
            "mostRecentAccountPaymentMethodChangeActivity": 24,
            "panTenureOnFile": 25,
            "recentSecurityActivity": "30"
        },
        "device": {
            "browserUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)",
            "deviceCountry": "US",
            "deviceId": "565266",
            "devicePlatform": "IOS",
            "deviceRiskScore": "4",
            "deviceTenure": 26,
            "ipAddress": "192.168.1.1",
            "location": {
                "latitude": "+025.3191",
                "longitude": "-084.0606"
            },
            "tlsFingerprint": "771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0"
        },
        "metadata": {
            "additionalProperty": "string",
            "ipReputation": "low_risk"
        }
    },
    "termsAndConditions": {
        "acceptanceTs": "2026-03-18T14:32:45Z",
        "version": "v2.1"
    },
    "user": {
        "accountId": "user-12345",
        "billingAddress": {
            "addressLine1": "300 Juniper Lane",
            "addressLine2": "Apt 4B",
            "city": "New York",
            "country": "US",
            "postalCode": "12345",
            "state": "NY"
        },
        "email": "someone@example.com",
        "firstName": "Jane",
        "lastName": "Jones",
        "userEmailHash": "5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a",
        "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript The initial request for validation and risk assessment (before step-up verification)
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    agentId: 'agentId',
    trackingId: 'trackingId',
    'Content-Type': 'application/json'
  },
  body: '{"account":{"cid":"1234","expiryMonth":"12","expiryYear":"2030","panNumber":"122000000000003","type":"CARD_NUMBER"},"agent":{"agentName":"NexusAI","llmPlatform":"OPEN_AI","llmVersion":"gpt-4.1"},"risk":{"account":{"accountAndCardNameMatch":"YES","accountRiskScore":"3","actionChannel":"WEB","agentAccountLocale":"en-US","distinctBillingLastNameCount":"2","emailTenure":5,"fpanSource":"USERINPUT","mostRecentAccountPaymentMethodChangeActivity":24,"panTenureOnFile":25,"recentSecurityActivity":"30"},"device":{"browserUserAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)","deviceCountry":"US","deviceId":"565266","devicePlatform":"IOS","deviceRiskScore":"4","deviceTenure":26,"ipAddress":"192.168.1.1","location":{"latitude":"+025.3191","longitude":"-084.0606"},"tlsFingerprint":"771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0"},"metadata":{"additionalProperty":"string","ipReputation":"low_risk"}},"termsAndConditions":{"acceptanceTs":"2026-03-18T14:32:45Z","version":"v2.1"},"user":{"accountId":"user-12345","billingAddress":{"addressLine1":"300 Juniper Lane","addressLine2":"Apt 4B","city":"New York","country":"US","postalCode":"12345","state":"NY"},"email":"someone@example.com","firstName":"Jane","lastName":"Jones","userEmailHash":"5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a","userPhoneNumberHash":"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The initial request for validation and risk assessment (before step-up verification)
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

	payload := strings.NewReader("{\n  \"account\": {\n    \"cid\": \"1234\",\n    \"expiryMonth\": \"12\",\n    \"expiryYear\": \"2030\",\n    \"panNumber\": \"122000000000003\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"risk\": {\n    \"account\": {\n      \"accountAndCardNameMatch\": \"YES\",\n      \"accountRiskScore\": \"3\",\n      \"actionChannel\": \"WEB\",\n      \"agentAccountLocale\": \"en-US\",\n      \"distinctBillingLastNameCount\": \"2\",\n      \"emailTenure\": 5,\n      \"fpanSource\": \"USERINPUT\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 24,\n      \"panTenureOnFile\": 25,\n      \"recentSecurityActivity\": \"30\"\n    },\n    \"device\": {\n      \"browserUserAgent\": \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)\",\n      \"deviceCountry\": \"US\",\n      \"deviceId\": \"565266\",\n      \"devicePlatform\": \"IOS\",\n      \"deviceRiskScore\": \"4\",\n      \"deviceTenure\": 26,\n      \"ipAddress\": \"192.168.1.1\",\n      \"location\": {\n        \"latitude\": \"+025.3191\",\n        \"longitude\": \"-084.0606\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"termsAndConditions\": {\n    \"acceptanceTs\": \"2026-03-18T14:32:45Z\",\n    \"version\": \"v2.1\"\n  },\n  \"user\": {\n    \"accountId\": \"user-12345\",\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The initial request for validation and risk assessment (before step-up verification)
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"account\": {\n    \"cid\": \"1234\",\n    \"expiryMonth\": \"12\",\n    \"expiryYear\": \"2030\",\n    \"panNumber\": \"122000000000003\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"risk\": {\n    \"account\": {\n      \"accountAndCardNameMatch\": \"YES\",\n      \"accountRiskScore\": \"3\",\n      \"actionChannel\": \"WEB\",\n      \"agentAccountLocale\": \"en-US\",\n      \"distinctBillingLastNameCount\": \"2\",\n      \"emailTenure\": 5,\n      \"fpanSource\": \"USERINPUT\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 24,\n      \"panTenureOnFile\": 25,\n      \"recentSecurityActivity\": \"30\"\n    },\n    \"device\": {\n      \"browserUserAgent\": \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)\",\n      \"deviceCountry\": \"US\",\n      \"deviceId\": \"565266\",\n      \"devicePlatform\": \"IOS\",\n      \"deviceRiskScore\": \"4\",\n      \"deviceTenure\": 26,\n      \"ipAddress\": \"192.168.1.1\",\n      \"location\": {\n        \"latitude\": \"+025.3191\",\n        \"longitude\": \"-084.0606\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"termsAndConditions\": {\n    \"acceptanceTs\": \"2026-03-18T14:32:45Z\",\n    \"version\": \"v2.1\"\n  },\n  \"user\": {\n    \"accountId\": \"user-12345\",\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java The initial request for validation and risk assessment (before step-up verification)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .header("Content-Type", "application/json")
  .body("{\n  \"account\": {\n    \"cid\": \"1234\",\n    \"expiryMonth\": \"12\",\n    \"expiryYear\": \"2030\",\n    \"panNumber\": \"122000000000003\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"risk\": {\n    \"account\": {\n      \"accountAndCardNameMatch\": \"YES\",\n      \"accountRiskScore\": \"3\",\n      \"actionChannel\": \"WEB\",\n      \"agentAccountLocale\": \"en-US\",\n      \"distinctBillingLastNameCount\": \"2\",\n      \"emailTenure\": 5,\n      \"fpanSource\": \"USERINPUT\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 24,\n      \"panTenureOnFile\": 25,\n      \"recentSecurityActivity\": \"30\"\n    },\n    \"device\": {\n      \"browserUserAgent\": \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)\",\n      \"deviceCountry\": \"US\",\n      \"deviceId\": \"565266\",\n      \"devicePlatform\": \"IOS\",\n      \"deviceRiskScore\": \"4\",\n      \"deviceTenure\": 26,\n      \"ipAddress\": \"192.168.1.1\",\n      \"location\": {\n        \"latitude\": \"+025.3191\",\n        \"longitude\": \"-084.0606\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"termsAndConditions\": {\n    \"acceptanceTs\": \"2026-03-18T14:32:45Z\",\n    \"version\": \"v2.1\"\n  },\n  \"user\": {\n    \"accountId\": \"user-12345\",\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}")
  .asString();
```

```php The initial request for validation and risk assessment (before step-up verification)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments', [
  'body' => '{
  "account": {
    "cid": "1234",
    "expiryMonth": "12",
    "expiryYear": "2030",
    "panNumber": "122000000000003",
    "type": "CARD_NUMBER"
  },
  "agent": {
    "agentName": "NexusAI",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "gpt-4.1"
  },
  "risk": {
    "account": {
      "accountAndCardNameMatch": "YES",
      "accountRiskScore": "3",
      "actionChannel": "WEB",
      "agentAccountLocale": "en-US",
      "distinctBillingLastNameCount": "2",
      "emailTenure": 5,
      "fpanSource": "USERINPUT",
      "mostRecentAccountPaymentMethodChangeActivity": 24,
      "panTenureOnFile": 25,
      "recentSecurityActivity": "30"
    },
    "device": {
      "browserUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)",
      "deviceCountry": "US",
      "deviceId": "565266",
      "devicePlatform": "IOS",
      "deviceRiskScore": "4",
      "deviceTenure": 26,
      "ipAddress": "192.168.1.1",
      "location": {
        "latitude": "+025.3191",
        "longitude": "-084.0606"
      },
      "tlsFingerprint": "771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0"
    },
    "metadata": {
      "additionalProperty": "string",
      "ipReputation": "low_risk"
    }
  },
  "termsAndConditions": {
    "acceptanceTs": "2026-03-18T14:32:45Z",
    "version": "v2.1"
  },
  "user": {
    "accountId": "user-12345",
    "billingAddress": {
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "postalCode": "12345",
      "state": "NY"
    },
    "email": "someone@example.com",
    "firstName": "Jane",
    "lastName": "Jones",
    "userEmailHash": "5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a",
    "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The initial request for validation and risk assessment (before step-up verification)
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"account\": {\n    \"cid\": \"1234\",\n    \"expiryMonth\": \"12\",\n    \"expiryYear\": \"2030\",\n    \"panNumber\": \"122000000000003\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"risk\": {\n    \"account\": {\n      \"accountAndCardNameMatch\": \"YES\",\n      \"accountRiskScore\": \"3\",\n      \"actionChannel\": \"WEB\",\n      \"agentAccountLocale\": \"en-US\",\n      \"distinctBillingLastNameCount\": \"2\",\n      \"emailTenure\": 5,\n      \"fpanSource\": \"USERINPUT\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 24,\n      \"panTenureOnFile\": 25,\n      \"recentSecurityActivity\": \"30\"\n    },\n    \"device\": {\n      \"browserUserAgent\": \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)\",\n      \"deviceCountry\": \"US\",\n      \"deviceId\": \"565266\",\n      \"devicePlatform\": \"IOS\",\n      \"deviceRiskScore\": \"4\",\n      \"deviceTenure\": 26,\n      \"ipAddress\": \"192.168.1.1\",\n      \"location\": {\n        \"latitude\": \"+025.3191\",\n        \"longitude\": \"-084.0606\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"termsAndConditions\": {\n    \"acceptanceTs\": \"2026-03-18T14:32:45Z\",\n    \"version\": \"v2.1\"\n  },\n  \"user\": {\n    \"accountId\": \"user-12345\",\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift The initial request for validation and risk assessment (before step-up verification)
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId",
  "Content-Type": "application/json"
]
let parameters = [
  "account": [
    "cid": "1234",
    "expiryMonth": "12",
    "expiryYear": "2030",
    "panNumber": "122000000000003",
    "type": "CARD_NUMBER"
  ],
  "agent": [
    "agentName": "NexusAI",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "gpt-4.1"
  ],
  "risk": [
    "account": [
      "accountAndCardNameMatch": "YES",
      "accountRiskScore": "3",
      "actionChannel": "WEB",
      "agentAccountLocale": "en-US",
      "distinctBillingLastNameCount": "2",
      "emailTenure": 5,
      "fpanSource": "USERINPUT",
      "mostRecentAccountPaymentMethodChangeActivity": 24,
      "panTenureOnFile": 25,
      "recentSecurityActivity": "30"
    ],
    "device": [
      "browserUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)",
      "deviceCountry": "US",
      "deviceId": "565266",
      "devicePlatform": "IOS",
      "deviceRiskScore": "4",
      "deviceTenure": 26,
      "ipAddress": "192.168.1.1",
      "location": [
        "latitude": "+025.3191",
        "longitude": "-084.0606"
      ],
      "tlsFingerprint": "771,4865-4866-4867-49195-49196-49199-49200,0-11-10-35-16-5-13-18-51,29-23-24,0"
    ],
    "metadata": [
      "additionalProperty": "string",
      "ipReputation": "low_risk"
    ]
  ],
  "termsAndConditions": [
    "acceptanceTs": "2026-03-18T14:32:45Z",
    "version": "v2.1"
  ],
  "user": [
    "accountId": "user-12345",
    "billingAddress": [
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "postalCode": "12345",
      "state": "NY"
    ],
    "email": "someone@example.com",
    "firstName": "Jane",
    "lastName": "Jones",
    "userEmailHash": "5e884898da28047151d0e56f8dc6292773603d0d6aabbddc9b3e5f5c5a5a5a5a",
    "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### The follow-up request after completing step-up verification.

**Request**

```json
{
  "enrollmentId": "enr_8f3a9c2d7b6e4a1f",
  "stepUpVerification": {
    "issuerSurfaceAuthenticationResponse": {
      "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"
    },
    "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f"
  }
}
```

**Response**

```json
{
  "accountMetadata": {
    "cardArt": {
      "cardArtUrl": "string",
      "foregroundColor": "string"
    },
    "displayPanNumber": "string",
    "paymentAccountReference": "string",
    "productName": "string"
  },
  "availableChallenges": {
    "0": {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  },
  "enrollmentId": "string",
  "enrollmentStatus": "PENDING_STEP_UP",
  "issuer": {
    "issuerContactNumber": "string",
    "issuerLogoUrl": "string",
    "issuerName": "string",
    "issuerTermsUrl": "string"
  },
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python The follow-up request after completing step-up verification.
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

payload = {
    "enrollmentId": "enr_8f3a9c2d7b6e4a1f",
    "stepUpVerification": {
        "issuerSurfaceAuthenticationResponse": { "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e" },
        "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f"
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript The follow-up request after completing step-up verification.
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    agentId: 'agentId',
    trackingId: 'trackingId',
    'Content-Type': 'application/json'
  },
  body: '{"enrollmentId":"enr_8f3a9c2d7b6e4a1f","stepUpVerification":{"issuerSurfaceAuthenticationResponse":{"authenticationToken":"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"},"stepUpSessionId":"sess_9f3a7c2d8b6e4a1f"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The follow-up request after completing step-up verification.
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

	payload := strings.NewReader("{\n  \"enrollmentId\": \"enr_8f3a9c2d7b6e4a1f\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The follow-up request after completing step-up verification.
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"enrollmentId\": \"enr_8f3a9c2d7b6e4a1f\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java The follow-up request after completing step-up verification.
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .header("Content-Type", "application/json")
  .body("{\n  \"enrollmentId\": \"enr_8f3a9c2d7b6e4a1f\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\"\n  }\n}")
  .asString();
```

```php The follow-up request after completing step-up verification.
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments', [
  'body' => '{
  "enrollmentId": "enr_8f3a9c2d7b6e4a1f",
  "stepUpVerification": {
    "issuerSurfaceAuthenticationResponse": {
      "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"
    },
    "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The follow-up request after completing step-up verification.
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"enrollmentId\": \"enr_8f3a9c2d7b6e4a1f\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift The follow-up request after completing step-up verification.
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId",
  "Content-Type": "application/json"
]
let parameters = [
  "enrollmentId": "enr_8f3a9c2d7b6e4a1f",
  "stepUpVerification": [
    "issuerSurfaceAuthenticationResponse": ["authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"],
    "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Encrypted payload (on the wire)

**Request**

```json
{
  "account": {
    "expiryMonth": "string",
    "expiryYear": "string",
    "panNumber": "string",
    "type": "CARD_NUMBER"
  },
  "agent": {
    "agentName": "string",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "string"
  },
  "encryptedPayload": "<jwe-payload>",
  "risk": {
    "account": {
      "actionChannel": "WEB",
      "fpanSource": "USERINPUT"
    },
    "device": {
      "deviceId": "string",
      "ipAddress": "string"
    }
  },
  "user": {
    "accountId": "string",
    "billingAddress": {
      "addressLine1": "string",
      "addressLine2": "string",
      "city": "string",
      "country": "string",
      "postalCode": "string",
      "state": "string"
    },
    "email": "string",
    "firstName": "string",
    "lastName": "string"
  }
}
```

**Response**

```json
{
  "accountMetadata": {
    "cardArt": {
      "cardArtUrl": "string",
      "foregroundColor": "string"
    },
    "displayPanNumber": "string",
    "paymentAccountReference": "string",
    "productName": "string"
  },
  "availableChallenges": {
    "0": {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  },
  "enrollmentId": "string",
  "enrollmentStatus": "PENDING_STEP_UP",
  "issuer": {
    "issuerContactNumber": "string",
    "issuerLogoUrl": "string",
    "issuerName": "string",
    "issuerTermsUrl": "string"
  },
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python Encrypted payload (on the wire)
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

payload = {
    "account": {
        "expiryMonth": "string",
        "expiryYear": "string",
        "panNumber": "string",
        "type": "CARD_NUMBER"
    },
    "agent": {
        "agentName": "string",
        "llmPlatform": "OPEN_AI",
        "llmVersion": "string"
    },
    "encryptedPayload": "<jwe-payload>",
    "risk": {
        "account": {
            "actionChannel": "WEB",
            "fpanSource": "USERINPUT"
        },
        "device": {
            "deviceId": "string",
            "ipAddress": "string"
        }
    },
    "user": {
        "accountId": "string",
        "billingAddress": {
            "addressLine1": "string",
            "addressLine2": "string",
            "city": "string",
            "country": "string",
            "postalCode": "string",
            "state": "string"
        },
        "email": "string",
        "firstName": "string",
        "lastName": "string"
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Encrypted payload (on the wire)
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    agentId: 'agentId',
    trackingId: 'trackingId',
    'Content-Type': 'application/json'
  },
  body: '{"account":{"expiryMonth":"string","expiryYear":"string","panNumber":"string","type":"CARD_NUMBER"},"agent":{"agentName":"string","llmPlatform":"OPEN_AI","llmVersion":"string"},"encryptedPayload":"<jwe-payload>","risk":{"account":{"actionChannel":"WEB","fpanSource":"USERINPUT"},"device":{"deviceId":"string","ipAddress":"string"}},"user":{"accountId":"string","billingAddress":{"addressLine1":"string","addressLine2":"string","city":"string","country":"string","postalCode":"string","state":"string"},"email":"string","firstName":"string","lastName":"string"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Encrypted payload (on the wire)
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments"

	payload := strings.NewReader("{\n  \"account\": {\n    \"expiryMonth\": \"string\",\n    \"expiryYear\": \"string\",\n    \"panNumber\": \"string\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"risk\": {\n    \"account\": {\n      \"actionChannel\": \"WEB\",\n      \"fpanSource\": \"USERINPUT\"\n    },\n    \"device\": {\n      \"deviceId\": \"string\",\n      \"ipAddress\": \"string\"\n    }\n  },\n  \"user\": {\n    \"accountId\": \"string\",\n    \"billingAddress\": {\n      \"addressLine1\": \"string\",\n      \"addressLine2\": \"string\",\n      \"city\": \"string\",\n      \"country\": \"string\",\n      \"postalCode\": \"string\",\n      \"state\": \"string\"\n    },\n    \"email\": \"string\",\n    \"firstName\": \"string\",\n    \"lastName\": \"string\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Encrypted payload (on the wire)
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"account\": {\n    \"expiryMonth\": \"string\",\n    \"expiryYear\": \"string\",\n    \"panNumber\": \"string\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"risk\": {\n    \"account\": {\n      \"actionChannel\": \"WEB\",\n      \"fpanSource\": \"USERINPUT\"\n    },\n    \"device\": {\n      \"deviceId\": \"string\",\n      \"ipAddress\": \"string\"\n    }\n  },\n  \"user\": {\n    \"accountId\": \"string\",\n    \"billingAddress\": {\n      \"addressLine1\": \"string\",\n      \"addressLine2\": \"string\",\n      \"city\": \"string\",\n      \"country\": \"string\",\n      \"postalCode\": \"string\",\n      \"state\": \"string\"\n    },\n    \"email\": \"string\",\n    \"firstName\": \"string\",\n    \"lastName\": \"string\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java Encrypted payload (on the wire)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .header("Content-Type", "application/json")
  .body("{\n  \"account\": {\n    \"expiryMonth\": \"string\",\n    \"expiryYear\": \"string\",\n    \"panNumber\": \"string\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"risk\": {\n    \"account\": {\n      \"actionChannel\": \"WEB\",\n      \"fpanSource\": \"USERINPUT\"\n    },\n    \"device\": {\n      \"deviceId\": \"string\",\n      \"ipAddress\": \"string\"\n    }\n  },\n  \"user\": {\n    \"accountId\": \"string\",\n    \"billingAddress\": {\n      \"addressLine1\": \"string\",\n      \"addressLine2\": \"string\",\n      \"city\": \"string\",\n      \"country\": \"string\",\n      \"postalCode\": \"string\",\n      \"state\": \"string\"\n    },\n    \"email\": \"string\",\n    \"firstName\": \"string\",\n    \"lastName\": \"string\"\n  }\n}")
  .asString();
```

```php Encrypted payload (on the wire)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments', [
  'body' => '{
  "account": {
    "expiryMonth": "string",
    "expiryYear": "string",
    "panNumber": "string",
    "type": "CARD_NUMBER"
  },
  "agent": {
    "agentName": "string",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "string"
  },
  "encryptedPayload": "<jwe-payload>",
  "risk": {
    "account": {
      "actionChannel": "WEB",
      "fpanSource": "USERINPUT"
    },
    "device": {
      "deviceId": "string",
      "ipAddress": "string"
    }
  },
  "user": {
    "accountId": "string",
    "billingAddress": {
      "addressLine1": "string",
      "addressLine2": "string",
      "city": "string",
      "country": "string",
      "postalCode": "string",
      "state": "string"
    },
    "email": "string",
    "firstName": "string",
    "lastName": "string"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp Encrypted payload (on the wire)
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"account\": {\n    \"expiryMonth\": \"string\",\n    \"expiryYear\": \"string\",\n    \"panNumber\": \"string\",\n    \"type\": \"CARD_NUMBER\"\n  },\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"risk\": {\n    \"account\": {\n      \"actionChannel\": \"WEB\",\n      \"fpanSource\": \"USERINPUT\"\n    },\n    \"device\": {\n      \"deviceId\": \"string\",\n      \"ipAddress\": \"string\"\n    }\n  },\n  \"user\": {\n    \"accountId\": \"string\",\n    \"billingAddress\": {\n      \"addressLine1\": \"string\",\n      \"addressLine2\": \"string\",\n      \"city\": \"string\",\n      \"country\": \"string\",\n      \"postalCode\": \"string\",\n      \"state\": \"string\"\n    },\n    \"email\": \"string\",\n    \"firstName\": \"string\",\n    \"lastName\": \"string\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Encrypted payload (on the wire)
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId",
  "Content-Type": "application/json"
]
let parameters = [
  "account": [
    "expiryMonth": "string",
    "expiryYear": "string",
    "panNumber": "string",
    "type": "CARD_NUMBER"
  ],
  "agent": [
    "agentName": "string",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "string"
  ],
  "encryptedPayload": "<jwe-payload>",
  "risk": [
    "account": [
      "actionChannel": "WEB",
      "fpanSource": "USERINPUT"
    ],
    "device": [
      "deviceId": "string",
      "ipAddress": "string"
    ]
  ],
  "user": [
    "accountId": "string",
    "billingAddress": [
      "addressLine1": "string",
      "addressLine2": "string",
      "city": "string",
      "country": "string",
      "postalCode": "string",
      "state": "string"
    ],
    "email": "string",
    "firstName": "string",
    "lastName": "string"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/enrollments")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```