> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Request payment credentials

POST https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials
Content-Type: application/json

\<p class='pad-2-b'>Generates tokenized payment credentials associated with an approved intent. This API supports a multi-step flow when additional authentication is required:\</p>\<ul class='pad-3-l'\<li>The initial request generates payment credentials for validation and risk assessment.\</li>\<li>If step-up authentication is required, a follow-up request must be made with the proof of intent and step-up verification details.\</li>\</ul>\<p class='pad-2-b'>\</p>\<p class='pad-2-b'>The response of the API will have the payment credentials. If step-up authentication is completed asynchronously and if applicable, American Express will notify the partner via the notification API. The partner can then call payment credentials API again to retrieve the payment credentials.\</p>

Reference: https://developer.americanexpress.ferndocs.com/payment-services/agentic-commerce/api-reference/paymentcredentials/create

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://apisandboxm.americanexpress.com` (sandbox, default)
- `https://apigwm.americanexpress.com` (production)

## Request

### Headers

- `Authorization` (string, required) — The OAuth authorization header generated as prescribed in the Oauth 2.0 guide
- `trackingId` (string, required) — A unique identifier for request tracking.
- `agentId` (string, required) — Agent's unique identifier.

### Body (application/json)

This endpoint expects a PaymentCredentialsRequest.

- `PaymentCredentialsRequest`

## Response

### 200

Successful response

- `PaymentCredentialsResponse`

## Errors

### 400 Bad Request Error

Bad request

- `error` (ErrorInvalidFieldsResponseError, required)

### 401 Unauthorized Error

Unauthorized

- `any`

### 404 Not Found Error

Resource not found

- `any`

### 422 Unprocessable Entity Error

Unprocessable entity

- `error` (ErrorBusinessExceptionResponseError, required)

### 500 Internal Server Error

Service error

- `error` (ErrorSystemDownResponseError, required)

## Types

### The initial request to obtain payment credentials for an approved intent.

The initial request to obtain payment credentials for an approved intent.

- `agent` (Agent, required) — Information about the agent facilitating the commerce transaction.
- `shipment` (PaymentCredentialsShipmentDetails, required) — The shipping and delivery details associated with the purchase. Use deliveryEmail for digital goods and shippingAddress with postalCode for physical goods.
- `orderContext` (PaymentCredentialsOrderContext, required) — Order details used to generate payment credentials, including merchants and associated items.
- `risk` (Risk, optional) — Risk and device context associated with the request.
- `user` (PaymentCredentialsUser, optional) — The Customer's identity information associated with the request.
- `purchaseDecision` (enum, optional) — Indicates whether a purchase is executed with explicit Card Member approval at the time of transaction or delegated to an Agent for autonomous execution.
  - Allowed values: `NON-DELEGATED`, `DELEGATED`
- `requestedPaymentCredentialsCount` (integer, optional) — The number of payment credentials the Partner is requesting for the order context. Default value is 1.

### The follow-up request after step-up verification.

The follow-up request after step-up verification.

- `proofOfIntent` (string, required) — A signed JSON web token received part of create intent response.
- `stepUpVerification` (StepUpVerification, required) — The step-up verification details for completing authentication. Required when submitting a step-up challenge response. This object will depend on the challenge type returned in the initial API response when the step-up flow is initiated.

### PaymentCredentialsWithStepUpResponse

The response returned when additional authentication is required to obtain payment credentials.The response payload will be JWE-encrypted as seen in the model [EncryptedRequestResponse](#components-schemas-EncryptedRequestResponse)

- `stepUpAuthenticationRequired` (enum, required) — Indicates whether additional authentication is required.
  - Allowed values: `YES`, `NO`
- `enrollmentId` (string, required) — A unique identifier for the enrolled account.
- `paymentCredentialId` (string, required) — A unique identifier for the payment credential.
- `paymentCredentialStatus` (enum, required) — The current status of the payment credential.
  - Allowed values: `PENDING_STEP_UP`
- `stepUpSessionId` (string, required) — The identifier for the step-up session associated with the request.
- `availableChallenges` (list of AvailableChallengesItems, required) — The authentication challenges available for completing step-up verification.

### PaymentCredentialsWithoutStepUpResponse

The response returned when payment credentials are successfully generated. The response payload will be JWE-encrypted as seen in the model [EncryptedRequestResponse](#components-schemas-EncryptedRequestResponse)

- `paymentCredentials` (list of PaymentCredentialsWithoutStepUpResponsePaymentCredentialsItems, required) — The payment credentials associated with the order.

### ErrorInvalidFieldsResponseError

- `code` (string, required) — An error code that is returned when request validation fails.
- `description` (string, required) — An error description that is returned when request validation fails.
- `type` (enum, required)
  - Allowed values: `USER_EXCEPTION`
- `param` (string, optional) — The parameter that caused the error, if applicable

### ErrorBusinessExceptionResponseError

- `code` (string, required) — An error code returned when a business rule validation fails.
- `description` (string, required) — An error description returned when a business rule validation fails.
- `type` (enum, required)
  - Allowed values: `BUSINESS_EXCEPTION`

### ErrorSystemDownResponseError

- `code` (enum, required)
  - Allowed values: `20001`
- `description` (enum, required)
  - Allowed values: `Internal server error`
- `type` (enum, required)
  - Allowed values: `SYSTEM_EXCEPTION`

### Agent

Information about the agent facilitating the commerce transaction.

- `llmVersion` (string, required) — The version of the language model used by the agent.
- `llmPlatform` (enum, required) — The platform hosting the language model used by the agent.
  - Allowed values: `OPEN_AI`
- `agentName` (string, required) — The name of the agent or application initiating the request.

### PaymentCredentialsShipmentDetails

The shipping and delivery details associated with the purchase. Use deliveryEmail for digital goods and shippingAddress with postalCode for physical goods.

- `shippingEmail` (string, optional) — The email address associated with the order.
- `shippingMethod` (enum, optional) — The shipping method selected for the order.
  - Allowed values: `SAME_DAY`, `OVERNIGHT`, `EXPEDITED`, `STANDARD`
- `shippingPhoneNumber` (string, optional) — The contact phone number associated with the order.
- `shippingAddress` (PaymentCredentialsAddress, optional) — The shipping address for physical goods. Required when the item is classified as a physical good.
- `deliveryEmail` (string, optional) — The email address for delivery notifications and confirmations. Required when the item is classified as a digital good.

### PaymentCredentialsOrderContext

Order details used to generate payment credentials, including merchants and associated items.

### Risk

Risk and device context associated with the request.

- `account` (PaymentCredentialsAccountRisk, optional) — Account-level risk signals associated with the request.
- `device` (PaymentCredentialsDeviceRisk, optional) — Device-level risk signals associated with the request.
- `order` (PaymentCredentialsOrderRisk, optional) — Order-level risk signals associated with the request.
- `metadata` (RiskMetadata, optional) — A generic risk metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### PaymentCredentialsUser

The Customer's identity information associated with the request.

- `firstName` (string, optional) — The Customer's first name.
- `lastName` (string, optional) — The Customer's last name.
- `billingAddress` (PaymentCredentialsBillingAddress, optional) — The enrolling user's billing address
- `userEmailHash` (string, optional) — A hashed representation of the email address generated using the PBKDF2WithHmacSHA256 algorithm with 10 iterations.
- `userPhoneNumberHash` (string, optional) — A hashed representation of the phone number generated using the PBKDF2WithHmacSHA256 algorithm with 10 iterations.
- `email` (string, optional) — The Customer's email address in RFC 5322 format.
- `phone` (string, optional) — The Customer's phone number in international format, starting with + followed by a string of digits between zero and nine with a minimum length of 11 digits

### StepUpVerification

The step-up verification details for completing authentication. Required when submitting a step-up challenge response. This object will depend on the challenge type returned in the initial API response when the step-up flow is initiated.

### AvailableChallengesItems

### PaymentCredentialsWithoutStepUpResponsePaymentCredentialsItems

The payment credential details for a specific merchant.

- `tokenNumber` (string, required) — The tokenized account number issued for the payment.
- `expiryMonth` (string, required) — Expiry month of the token, in MM format.The month must be between 01 and 12.
- `expiryYear` (string, required) — The expiry year of the token, in YYYY format.
- `dcsc` (string, required) — A four-digit Dynamic Card Security Code (DCSC) associated with the token.
- `merchantId` (integer, optional) — The identifier of the Merchant.

### PaymentCredentialsAddress

The shipping address associated with the purchase. Required when the item is classified as a physical good.

- `postalCode` (string, required) — The Postal Code associated with the address.
- `firstName` (string, optional) — The Customer's first name.
- `lastName` (string, optional) — The Customer's last name.
- `addressLine1` (string, optional) — The first line of the address.
- `addressLine2` (string, optional) — The second line of the address.
- `city` (string, optional) — The city associated with the address.
- `state` (string, optional) — The state or region associated with the address.
- `country` (string, optional) — The country code for the address, in ISO 3166-1 alpha-2 format.

### PaymentCredentialsOrderContext0

- `items` (list of ItemsItems, optional) — Line items associated with the order. Typically used for merchandise, retail, or electronics purchases.

### PaymentCredentialsOrderContext1

- `airlineItems` (list of AirlineItems, optional) — Line items associated with airline bookings.

### PaymentCredentialsAccountRisk

Account-level risk signals associated with the request.

- `panTenureOnFile` (double, optional) — The number of weeks since the card account was first stored on file with the Partner.
- `accountRiskScore` (string, optional) — A risk score provided by the Partner for the account, on a scale of 1-5 (1 = Very Low, 2 = Low, 3 = Medium, 4 = High, 5 = Very High).
- `recentSecurityActivity` (string, optional) — The number of days since the most recent password or two-factor authentication change.
- `mostRecentAccountPaymentMethodChangeActivity` (double, optional) — The number of days since the most recent change to the account's payment method.
- `partnerStepUp` (enum, optional) — Indicates whether the user has already completed step-up authentication with the Partner.
  - Allowed values: `YES`, `NO`
- `agentAccountLocale` (string, optional) — The locale associated with the agent's account, used for regional formatting and compliance behavior.

### PaymentCredentialsDeviceRisk

Device-level risk signals associated with the request.

- `deviceId` (string, optional) — A stable identifier for the device associated with the account.
- `deviceName` (string, optional) — Recognizable name assigned to the device.
- `deviceType` (enum, optional) — The category of the device used.
  - Allowed values: `Phone`, `Tablet`, `Watch`, `Wearable`, `Other`
- `ipAddress` (string, optional) — The IP address observed for the device at the time of the request.
- `deviceRiskScore` (string, optional) — A risk score provided by the Partner for the device, on a scale of 1-5 (1 = Very Low, 2 = Low, 3 = Medium, 4 = High, 5 = Very High).
- `deviceTenure` (double, optional) — The number of weeks since the device was first associated with the account.
- `tlsFingerprint` (string, optional) — The TLS fingerprint associated with the device connection.
- `location` (PaymentCredentialsDeviceRiskLocation, optional) — The geographic coordinates of the device at the time of the request.

### PaymentCredentialsOrderRisk

Order-level risk signals associated with the request.

- `includesGiftCard` (enum, optional) — Indicates whether the purchase includes at least one gift card item.
  - Allowed values: `YES`, `NO`

### RiskMetadata

A generic risk metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### PaymentCredentialsBillingAddress

The enrolling user's billing address

- `addressLine1` (string, optional) — The first line of the address.
- `addressLine2` (string, optional) — The second line of the address.
- `city` (string, optional) — The city of the address.
- `state` (string, optional) — The state of the address.
- `country` (string, optional) — The country of the address in ISO 3166-1 alpha-2 format.
- `postalCode` (string, optional) — The Postal Code of the address.

### The response object for SafeKey<sup>&reg;</sup> authentication challenge

This object will depend on the challenge type returned in the initial API response when the step-up flow is initiated.

- `safeKeyAuthenticationResponse` (StepUpVerificationOneOf0SafeKeyAuthenticationResponse, required) — The result of SafeKey® authentication.

### The response object for issuer surface authentication challenge

- `issuerSurfaceAuthenticationResponse` (StepUpVerificationOneOf1IssuerSurfaceAuthenticationResponse, required) — The result of issuer surface authentication for step-up integration.

### The response object for SECURE_PUSH authentication challenge

- `securePushAuthenticationResponse` (StepUpVerificationOneOf2SecurePushAuthenticationResponse, required) — Confirmation when authentication is complete using SECURE_PUSH

### The response object for SMS_OTP or EMAIL_OTP authentication challenge

- `validateAuthenticationCode` (StepUpVerificationOneOf3ValidateAuthenticationCode, required) — The one-time passcode entered by the user for step-up verification using SMS_OTP or EMAIL_OTP.

### AvailableChallengesItems0

- `type` (enum, required) — The authentication method.
  - Allowed values: `ISSUER_SURFACE`
- `issuerSurface` (AvailableChallengesItemsOneOf0IssuerSurface, required) — Issuer surface authentication details.

### AvailableChallengesItems1

- `type` (enum, required) — The authentication method.
  - Allowed values: `SECURE_PUSH`
- `securePushAuthentication` (AvailableChallengesItemsOneOf1SecurePushAuthentication, required) — Secure push authentication details.

### AvailableChallengesItems2

- `type` (enum, required) — The authentication method.
  - Allowed values: `SAFEKEY`
- `safeKeyAuthentication` (AvailableChallengesItemsOneOf2SafeKeyAuthentication, required) — SafeKey® authentication details.

### AvailableChallengesItems3

- `type` (enum, required) — The authentication method.
  - Allowed values: `SMS_OTP`
- `channelId` (string, required) — A unique identifier of the phone channel to deliver OTP.
- `value` (string, required) — The masked phone number where the OTP will be delivered.

### AvailableChallengesItems4

- `type` (enum, required) — The authentication method.
  - Allowed values: `EMAIL_OTP`
- `channelId` (string, required) — A unique identifier of the email channel to deliver OTP.
- `value` (string, required) — The masked email address where the OTP will be delivered.

### ItemsItems

The details of an individual item in the order.

- `itemId` (string, required) — A unique identifier for the item within the order.
- `name` (string, required) — The name of the item.
- `isGiftCard` (enum, required) — Indicates whether the item is a gift card.
  - Allowed values: `YES`, `NO`
- `merchantId` (integer, optional) — The identifier of the Merchant associated with the item.
- `unitAmount` (string, optional) — The unit price of the item.
- `currency` (string, optional) — The currency code for the item price, in ISO 4217 format. Required when \<samp>unitAmount\<samp> is provided.
- `quantity` (integer, optional) — The quantity of the item.
- `condition` (string, optional) — The condition of the item, such as new, refurbished, or used.
- `category` (string, optional) — The category associated with the item.
- `brand` (string, optional) — The brand associated with the item.
- `imageLink` (string, optional) — The main product image URL.
- `isRefundable` (enum, optional) — Indicates whether the item is refundable.
  - Allowed values: `YES`, `NO`
- `isRecurBill` (enum, optional) — Indicates whether the item represents a recurring purchase.
  - Allowed values: `YES`, `NO`
- `purchaseCriteria` (list of PurchaseCriteriaItems, optional) — Constraints or preferences associated with the item.
- `metadata` (ItemsItemsMetadata, optional) — A generic item metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### AirlineItems

The details of an individual airline booking.

- `itemId` (string, required) — A unique identifier for the item within the order.
- `passengerName` (string, required) — The name of the passenger associated with the booking.
- `origin` (string, optional) — The origin airport, represented as a three-letter IATA code.
- `destination` (string, optional) — The destination airport, represented as a three-letter IATA code.
- `carrier` (string, optional) — The airline carrier for the booking.
- `isInsuranceOpted` (enum, optional) — Indicates whether travel insurance has been selected.
  - Allowed values: `YES`, `NO`
- `isRefundable` (enum, optional) — Indicates whether the booking is refundable.
  - Allowed values: `YES`, `NO`
- `unitAmount` (string, optional) — The price of the booking, per unit.
- `currency` (string, optional) — The currency code for the amount, in ISO 4217 format.
- `purchaseCriteria` (list of PurchaseCriteriaItems, optional) — Constraints or preferences associated with the booking.
- `metadata` (AirlineItemsMetadata, optional) — A generic airlineItem metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### PaymentCredentialsDeviceRiskLocation

The geographic coordinates of the device at the time of the request.

- `longitude` (string, optional) — The longitude coordinates of the device.
- `latitude` (string, optional) — The latitude coordinates of the device.

### StepUpVerificationOneOf0SafeKeyAuthenticationResponse

The result of SafeKey® authentication.

- `riskToken` (string, required) — The encrypted risk token used for SafeKey® authentication.

### StepUpVerificationOneOf1IssuerSurfaceAuthenticationResponse

The result of issuer surface authentication for step-up integration.

- `authenticationToken` (string, required) — The encrypted authentication token used for authentication using ISSUER_SURFACE.

### StepUpVerificationOneOf2SecurePushAuthenticationResponse

Confirmation when authentication is complete using SECURE_PUSH

- `authenticationToken` (string, required) — The encrypted authentication token used for authentication using SECURE_PUSH

### StepUpVerificationOneOf3ValidateAuthenticationCode

The one-time passcode entered by the user for step-up verification using SMS_OTP or EMAIL_OTP.

- `value` (string, required) — The one-time passcode entered by the user

### AvailableChallengesItemsOneOf0IssuerSurface

Issuer surface authentication details.

- `url` (string, required) — URL for initiating issuer surface authentication.
- `authenticationToken` (string, required) — The encrypted authentication token associated with the authentication request.

### AvailableChallengesItemsOneOf1SecurePushAuthentication

Secure push authentication details.

- `authenticationToken` (string, optional) — The encrypted authentication token associated with the authentication request.

### AvailableChallengesItemsOneOf2SafeKeyAuthentication

SafeKey® authentication details.

- `riskToken` (string, required) — The encrypted risk token associated with the authentication request.
- `messageCategory` (enum, required) — SafeKey® message category.
  - Allowed values: `01`, `02`
- `threeDSRequestorAuthenticationInd` (enum, required) — SafeKey® authentication indicator.
  - Allowed values: `81`, `82`

### PurchaseCriteriaItems

- `type` (enum, optional) — The type of criteria applied to the item.
  - Allowed values: `PRICE`, `DATE`
- `fromDate` (datetime, optional) — Start of the date range for fulfillment. Required when the type is DATE.
- `toDate` (datetime, optional) — End of the date range for fulfillment. Required when the type is DATE.
- `pricePreference` (enum, optional) — Price preference for the item. Required when the type is PRICE.
  - Allowed values: `MINIMUM_PRICE`, `BETWEEN_RANGE`, `MAXIMUM_PRICE`
- `maxAmount` (string, optional) — Maximum price for the item. Required when the pricePreference is BETWEEN\_RANGE.
- `minAmount` (string, optional) — Minimum price for the item. Required when the pricePreference is BETWEEN\_RANGE.
- `currency` (string, optional) — The currency code for the price values, in ISO 4217 format.
- `isShippingIncluded` (enum, optional) — Indicates whether shipping cost is included in the price.
  - Allowed values: `YES`, `NO`
- `dependentItems` (list of DependentItemsItems, optional) — Dependencies that must be satisfied before the item can be purchased.

### ItemsItemsMetadata

A generic item metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### AirlineItemsMetadata

A generic airlineItem metadata container allowing arbitrary string key-value pairs. Keys must be strings and values must be strings.

### DependentItemsItems

- `dependentItemId` (string, optional) — The identifier of the item that this item depends on.

## Examples

### The payment credentials response after completing step-up verification.

**Response**

```json
{
  "availableChallenges": [
    {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  ],
  "enrollmentId": "string",
  "paymentCredentialId": "string",
  "paymentCredentialStatus": "PENDING_STEP_UP",
  "paymentCredentials": [
    {
      "dcsc": "0000",
      "expiryMonth": "09",
      "expiryYear": "2026",
      "merchantId": "abc12345",
      "tokenNumber": "000000000000000"
    }
  ],
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python The payment credentials response after completing step-up verification.
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId"
}

response = requests.post(url, headers=headers)

print(response.json())
```

```javascript The payment credentials response after completing step-up verification.
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', agentId: 'agentId', trackingId: 'trackingId'}
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The payment credentials response after completing step-up verification.
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The payment credentials response after completing step-up verification.
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'

response = http.request(request)
puts response.read_body
```

```java The payment credentials response after completing step-up verification.
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .asString();
```

```php The payment credentials response after completing step-up verification.
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The payment credentials response after completing step-up verification.
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
IRestResponse response = client.Execute(request);
```

```swift The payment credentials response after completing step-up verification.
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### The initial request for generating payment credentials (before step-up verification)

**Request**

```json
{
  "agent": {
    "agentName": "NexusAI",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "gpt-4.1"
  },
  "orderContext": {
    "allowPartialOrder": "NO",
    "currency": "USD",
    "items": [
      {
        "brand": "Example Brand",
        "category": "Smartphones",
        "condition": "new",
        "currency": "USD",
        "imageLink": "https://example.com/images/product-image",
        "isGiftCard": "NO",
        "isRecurBill": "NO",
        "isRefundable": "YES",
        "itemId": "item_001",
        "merchantId": 987654,
        "metadata": {
          "additionalProperty": "string",
          "color": "Black Titanium",
          "modelNumber": "A3101",
          "releaseYear": "2025"
        },
        "name": "Premium Smartphone 256GB",
        "purchaseCriteria": {
          "0": {
            "currency": "USD",
            "fromDate": "2026-03-20T18:30:00Z",
            "isShippingIncluded": "YES",
            "maxAmount": "1200",
            "pricePreference": "MAXIMUM_PRICE",
            "toDate": "2026-03-22T18:30:00Z",
            "type": "PRICE"
          }
        },
        "quantity": 1,
        "unitAmount": "1099"
      }
    ],
    "merchants": [
      {
        "categoryName": "Electronics",
        "merchantId": 987654,
        "metadata": {
          "additionalProperty": "string",
          "fulfillmentModel": "first_party",
          "region": "US",
          "storeType": "official"
        },
        "name": "Example Store",
        "policies": {
          "returnPolicy": "https://www.example.com/returns",
          "returnWindow": "14",
          "termsOfService": "https://www.example.com/terms"
        },
        "seNumber": "123456789012",
        "sellerId": "seller_example_official",
        "url": "https://www.example.com"
      }
    ],
    "orderId": "order_789456123",
    "totalAmount": "1099",
    "type": "CART"
  },
  "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
  "purchaseDecision": "NON-DELEGATED",
  "requestedPaymentCredentialsCount": 1,
  "risk": {
    "account": {
      "accountRiskScore": "2",
      "agentAccountLocale": "en-US",
      "mostRecentAccountPaymentMethodChangeActivity": 30,
      "panTenureOnFile": 24,
      "partnerStepUp": "YES",
      "recentSecurityActivity": "10"
    },
    "device": {
      "deviceId": "device_abc123",
      "deviceName": "John's Phone",
      "deviceRiskScore": "3",
      "deviceTenure": 12,
      "deviceType": "Phone",
      "ipAddress": "192.0.2.1",
      "location": {
        "latitude": "40.7128",
        "longitude": "-74.0060"
      },
      "tlsFingerprint": "771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0"
    },
    "metadata": {
      "additionalProperty": "string",
      "ipReputation": "low_risk"
    }
  },
  "shipment": {
    "shippingAddress": {
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "firstName": "Jane",
      "lastName": "Jones",
      "postalCode": "12345",
      "state": "NY"
    },
    "shippingEmail": "someone@example.com",
    "shippingMethod": "EXPEDITED",
    "shippingPhoneNumber": "+14155552671"
  },
  "user": {
    "billingAddress": {
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "postalCode": "12345",
      "state": "NY"
    },
    "email": "someone@example.com",
    "firstName": "Jane",
    "lastName": "Jones",
    "userEmailHash": "b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5",
    "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
  }
}
```

**Response**

```json
{
  "availableChallenges": [
    {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  ],
  "enrollmentId": "string",
  "paymentCredentialId": "string",
  "paymentCredentialStatus": "PENDING_STEP_UP",
  "paymentCredentials": [
    {
      "dcsc": "0000",
      "expiryMonth": "09",
      "expiryYear": "2026",
      "merchantId": "abc12345",
      "tokenNumber": "000000000000000"
    }
  ],
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python The initial request for generating payment credentials (before step-up verification)
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

payload = {
    "agent": {
        "agentName": "NexusAI",
        "llmPlatform": "OPEN_AI",
        "llmVersion": "gpt-4.1"
    },
    "orderContext": {
        "allowPartialOrder": "NO",
        "currency": "USD",
        "items": [
            {
                "brand": "Example Brand",
                "category": "Smartphones",
                "condition": "new",
                "currency": "USD",
                "imageLink": "https://example.com/images/product-image",
                "isGiftCard": "NO",
                "isRecurBill": "NO",
                "isRefundable": "YES",
                "itemId": "item_001",
                "merchantId": 987654,
                "metadata": {
                    "additionalProperty": "string",
                    "color": "Black Titanium",
                    "modelNumber": "A3101",
                    "releaseYear": "2025"
                },
                "name": "Premium Smartphone 256GB",
                "purchaseCriteria": { "0": {
                        "currency": "USD",
                        "fromDate": "2026-03-20T18:30:00Z",
                        "isShippingIncluded": "YES",
                        "maxAmount": "1200",
                        "pricePreference": "MAXIMUM_PRICE",
                        "toDate": "2026-03-22T18:30:00Z",
                        "type": "PRICE"
                    } },
                "quantity": 1,
                "unitAmount": "1099"
            }
        ],
        "merchants": [
            {
                "categoryName": "Electronics",
                "merchantId": 987654,
                "metadata": {
                    "additionalProperty": "string",
                    "fulfillmentModel": "first_party",
                    "region": "US",
                    "storeType": "official"
                },
                "name": "Example Store",
                "policies": {
                    "returnPolicy": "https://www.example.com/returns",
                    "returnWindow": "14",
                    "termsOfService": "https://www.example.com/terms"
                },
                "seNumber": "123456789012",
                "sellerId": "seller_example_official",
                "url": "https://www.example.com"
            }
        ],
        "orderId": "order_789456123",
        "totalAmount": "1099",
        "type": "CART"
    },
    "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
    "purchaseDecision": "NON-DELEGATED",
    "requestedPaymentCredentialsCount": 1,
    "risk": {
        "account": {
            "accountRiskScore": "2",
            "agentAccountLocale": "en-US",
            "mostRecentAccountPaymentMethodChangeActivity": 30,
            "panTenureOnFile": 24,
            "partnerStepUp": "YES",
            "recentSecurityActivity": "10"
        },
        "device": {
            "deviceId": "device_abc123",
            "deviceName": "John's Phone",
            "deviceRiskScore": "3",
            "deviceTenure": 12,
            "deviceType": "Phone",
            "ipAddress": "192.0.2.1",
            "location": {
                "latitude": "40.7128",
                "longitude": "-74.0060"
            },
            "tlsFingerprint": "771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0"
        },
        "metadata": {
            "additionalProperty": "string",
            "ipReputation": "low_risk"
        }
    },
    "shipment": {
        "shippingAddress": {
            "addressLine1": "300 Juniper Lane",
            "addressLine2": "Apt 4B",
            "city": "New York",
            "country": "US",
            "firstName": "Jane",
            "lastName": "Jones",
            "postalCode": "12345",
            "state": "NY"
        },
        "shippingEmail": "someone@example.com",
        "shippingMethod": "EXPEDITED",
        "shippingPhoneNumber": "+14155552671"
    },
    "user": {
        "billingAddress": {
            "addressLine1": "300 Juniper Lane",
            "addressLine2": "Apt 4B",
            "city": "New York",
            "country": "US",
            "postalCode": "12345",
            "state": "NY"
        },
        "email": "someone@example.com",
        "firstName": "Jane",
        "lastName": "Jones",
        "userEmailHash": "b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5",
        "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript The initial request for generating payment credentials (before step-up verification)
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    agentId: 'agentId',
    trackingId: 'trackingId',
    'Content-Type': 'application/json'
  },
  body: '{"agent":{"agentName":"NexusAI","llmPlatform":"OPEN_AI","llmVersion":"gpt-4.1"},"orderContext":{"allowPartialOrder":"NO","currency":"USD","items":[{"brand":"Example Brand","category":"Smartphones","condition":"new","currency":"USD","imageLink":"https://example.com/images/product-image","isGiftCard":"NO","isRecurBill":"NO","isRefundable":"YES","itemId":"item_001","merchantId":987654,"metadata":{"additionalProperty":"string","color":"Black Titanium","modelNumber":"A3101","releaseYear":"2025"},"name":"Premium Smartphone 256GB","purchaseCriteria":{"0":{"currency":"USD","fromDate":"2026-03-20T18:30:00Z","isShippingIncluded":"YES","maxAmount":"1200","pricePreference":"MAXIMUM_PRICE","toDate":"2026-03-22T18:30:00Z","type":"PRICE"}},"quantity":1,"unitAmount":"1099"}],"merchants":[{"categoryName":"Electronics","merchantId":987654,"metadata":{"additionalProperty":"string","fulfillmentModel":"first_party","region":"US","storeType":"official"},"name":"Example Store","policies":{"returnPolicy":"https://www.example.com/returns","returnWindow":"14","termsOfService":"https://www.example.com/terms"},"seNumber":"123456789012","sellerId":"seller_example_official","url":"https://www.example.com"}],"orderId":"order_789456123","totalAmount":"1099","type":"CART"},"proofOfIntent":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy","purchaseDecision":"NON-DELEGATED","requestedPaymentCredentialsCount":1,"risk":{"account":{"accountRiskScore":"2","agentAccountLocale":"en-US","mostRecentAccountPaymentMethodChangeActivity":30,"panTenureOnFile":24,"partnerStepUp":"YES","recentSecurityActivity":"10"},"device":{"deviceId":"device_abc123","deviceName":"John\'s Phone","deviceRiskScore":"3","deviceTenure":12,"deviceType":"Phone","ipAddress":"192.0.2.1","location":{"latitude":"40.7128","longitude":"-74.0060"},"tlsFingerprint":"771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0"},"metadata":{"additionalProperty":"string","ipReputation":"low_risk"}},"shipment":{"shippingAddress":{"addressLine1":"300 Juniper Lane","addressLine2":"Apt 4B","city":"New York","country":"US","firstName":"Jane","lastName":"Jones","postalCode":"12345","state":"NY"},"shippingEmail":"someone@example.com","shippingMethod":"EXPEDITED","shippingPhoneNumber":"+14155552671"},"user":{"billingAddress":{"addressLine1":"300 Juniper Lane","addressLine2":"Apt 4B","city":"New York","country":"US","postalCode":"12345","state":"NY"},"email":"someone@example.com","firstName":"Jane","lastName":"Jones","userEmailHash":"b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5","userPhoneNumberHash":"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The initial request for generating payment credentials (before step-up verification)
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

	payload := strings.NewReader("{\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"orderContext\": {\n    \"allowPartialOrder\": \"NO\",\n    \"currency\": \"USD\",\n    \"items\": [\n      {\n        \"brand\": \"Example Brand\",\n        \"category\": \"Smartphones\",\n        \"condition\": \"new\",\n        \"currency\": \"USD\",\n        \"imageLink\": \"https://example.com/images/product-image\",\n        \"isGiftCard\": \"NO\",\n        \"isRecurBill\": \"NO\",\n        \"isRefundable\": \"YES\",\n        \"itemId\": \"item_001\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"color\": \"Black Titanium\",\n          \"modelNumber\": \"A3101\",\n          \"releaseYear\": \"2025\"\n        },\n        \"name\": \"Premium Smartphone 256GB\",\n        \"purchaseCriteria\": {\n          \"0\": {\n            \"currency\": \"USD\",\n            \"fromDate\": \"2026-03-20T18:30:00Z\",\n            \"isShippingIncluded\": \"YES\",\n            \"maxAmount\": \"1200\",\n            \"pricePreference\": \"MAXIMUM_PRICE\",\n            \"toDate\": \"2026-03-22T18:30:00Z\",\n            \"type\": \"PRICE\"\n          }\n        },\n        \"quantity\": 1,\n        \"unitAmount\": \"1099\"\n      }\n    ],\n    \"merchants\": [\n      {\n        \"categoryName\": \"Electronics\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"fulfillmentModel\": \"first_party\",\n          \"region\": \"US\",\n          \"storeType\": \"official\"\n        },\n        \"name\": \"Example Store\",\n        \"policies\": {\n          \"returnPolicy\": \"https://www.example.com/returns\",\n          \"returnWindow\": \"14\",\n          \"termsOfService\": \"https://www.example.com/terms\"\n        },\n        \"seNumber\": \"123456789012\",\n        \"sellerId\": \"seller_example_official\",\n        \"url\": \"https://www.example.com\"\n      }\n    ],\n    \"orderId\": \"order_789456123\",\n    \"totalAmount\": \"1099\",\n    \"type\": \"CART\"\n  },\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"purchaseDecision\": \"NON-DELEGATED\",\n  \"requestedPaymentCredentialsCount\": 1,\n  \"risk\": {\n    \"account\": {\n      \"accountRiskScore\": \"2\",\n      \"agentAccountLocale\": \"en-US\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 30,\n      \"panTenureOnFile\": 24,\n      \"partnerStepUp\": \"YES\",\n      \"recentSecurityActivity\": \"10\"\n    },\n    \"device\": {\n      \"deviceId\": \"device_abc123\",\n      \"deviceName\": \"John's Phone\",\n      \"deviceRiskScore\": \"3\",\n      \"deviceTenure\": 12,\n      \"deviceType\": \"Phone\",\n      \"ipAddress\": \"192.0.2.1\",\n      \"location\": {\n        \"latitude\": \"40.7128\",\n        \"longitude\": \"-74.0060\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"shipment\": {\n    \"shippingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"firstName\": \"Jane\",\n      \"lastName\": \"Jones\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"shippingEmail\": \"someone@example.com\",\n    \"shippingMethod\": \"EXPEDITED\",\n    \"shippingPhoneNumber\": \"+14155552671\"\n  },\n  \"user\": {\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The initial request for generating payment credentials (before step-up verification)
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"orderContext\": {\n    \"allowPartialOrder\": \"NO\",\n    \"currency\": \"USD\",\n    \"items\": [\n      {\n        \"brand\": \"Example Brand\",\n        \"category\": \"Smartphones\",\n        \"condition\": \"new\",\n        \"currency\": \"USD\",\n        \"imageLink\": \"https://example.com/images/product-image\",\n        \"isGiftCard\": \"NO\",\n        \"isRecurBill\": \"NO\",\n        \"isRefundable\": \"YES\",\n        \"itemId\": \"item_001\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"color\": \"Black Titanium\",\n          \"modelNumber\": \"A3101\",\n          \"releaseYear\": \"2025\"\n        },\n        \"name\": \"Premium Smartphone 256GB\",\n        \"purchaseCriteria\": {\n          \"0\": {\n            \"currency\": \"USD\",\n            \"fromDate\": \"2026-03-20T18:30:00Z\",\n            \"isShippingIncluded\": \"YES\",\n            \"maxAmount\": \"1200\",\n            \"pricePreference\": \"MAXIMUM_PRICE\",\n            \"toDate\": \"2026-03-22T18:30:00Z\",\n            \"type\": \"PRICE\"\n          }\n        },\n        \"quantity\": 1,\n        \"unitAmount\": \"1099\"\n      }\n    ],\n    \"merchants\": [\n      {\n        \"categoryName\": \"Electronics\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"fulfillmentModel\": \"first_party\",\n          \"region\": \"US\",\n          \"storeType\": \"official\"\n        },\n        \"name\": \"Example Store\",\n        \"policies\": {\n          \"returnPolicy\": \"https://www.example.com/returns\",\n          \"returnWindow\": \"14\",\n          \"termsOfService\": \"https://www.example.com/terms\"\n        },\n        \"seNumber\": \"123456789012\",\n        \"sellerId\": \"seller_example_official\",\n        \"url\": \"https://www.example.com\"\n      }\n    ],\n    \"orderId\": \"order_789456123\",\n    \"totalAmount\": \"1099\",\n    \"type\": \"CART\"\n  },\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"purchaseDecision\": \"NON-DELEGATED\",\n  \"requestedPaymentCredentialsCount\": 1,\n  \"risk\": {\n    \"account\": {\n      \"accountRiskScore\": \"2\",\n      \"agentAccountLocale\": \"en-US\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 30,\n      \"panTenureOnFile\": 24,\n      \"partnerStepUp\": \"YES\",\n      \"recentSecurityActivity\": \"10\"\n    },\n    \"device\": {\n      \"deviceId\": \"device_abc123\",\n      \"deviceName\": \"John's Phone\",\n      \"deviceRiskScore\": \"3\",\n      \"deviceTenure\": 12,\n      \"deviceType\": \"Phone\",\n      \"ipAddress\": \"192.0.2.1\",\n      \"location\": {\n        \"latitude\": \"40.7128\",\n        \"longitude\": \"-74.0060\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"shipment\": {\n    \"shippingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"firstName\": \"Jane\",\n      \"lastName\": \"Jones\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"shippingEmail\": \"someone@example.com\",\n    \"shippingMethod\": \"EXPEDITED\",\n    \"shippingPhoneNumber\": \"+14155552671\"\n  },\n  \"user\": {\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java The initial request for generating payment credentials (before step-up verification)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .header("Content-Type", "application/json")
  .body("{\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"orderContext\": {\n    \"allowPartialOrder\": \"NO\",\n    \"currency\": \"USD\",\n    \"items\": [\n      {\n        \"brand\": \"Example Brand\",\n        \"category\": \"Smartphones\",\n        \"condition\": \"new\",\n        \"currency\": \"USD\",\n        \"imageLink\": \"https://example.com/images/product-image\",\n        \"isGiftCard\": \"NO\",\n        \"isRecurBill\": \"NO\",\n        \"isRefundable\": \"YES\",\n        \"itemId\": \"item_001\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"color\": \"Black Titanium\",\n          \"modelNumber\": \"A3101\",\n          \"releaseYear\": \"2025\"\n        },\n        \"name\": \"Premium Smartphone 256GB\",\n        \"purchaseCriteria\": {\n          \"0\": {\n            \"currency\": \"USD\",\n            \"fromDate\": \"2026-03-20T18:30:00Z\",\n            \"isShippingIncluded\": \"YES\",\n            \"maxAmount\": \"1200\",\n            \"pricePreference\": \"MAXIMUM_PRICE\",\n            \"toDate\": \"2026-03-22T18:30:00Z\",\n            \"type\": \"PRICE\"\n          }\n        },\n        \"quantity\": 1,\n        \"unitAmount\": \"1099\"\n      }\n    ],\n    \"merchants\": [\n      {\n        \"categoryName\": \"Electronics\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"fulfillmentModel\": \"first_party\",\n          \"region\": \"US\",\n          \"storeType\": \"official\"\n        },\n        \"name\": \"Example Store\",\n        \"policies\": {\n          \"returnPolicy\": \"https://www.example.com/returns\",\n          \"returnWindow\": \"14\",\n          \"termsOfService\": \"https://www.example.com/terms\"\n        },\n        \"seNumber\": \"123456789012\",\n        \"sellerId\": \"seller_example_official\",\n        \"url\": \"https://www.example.com\"\n      }\n    ],\n    \"orderId\": \"order_789456123\",\n    \"totalAmount\": \"1099\",\n    \"type\": \"CART\"\n  },\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"purchaseDecision\": \"NON-DELEGATED\",\n  \"requestedPaymentCredentialsCount\": 1,\n  \"risk\": {\n    \"account\": {\n      \"accountRiskScore\": \"2\",\n      \"agentAccountLocale\": \"en-US\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 30,\n      \"panTenureOnFile\": 24,\n      \"partnerStepUp\": \"YES\",\n      \"recentSecurityActivity\": \"10\"\n    },\n    \"device\": {\n      \"deviceId\": \"device_abc123\",\n      \"deviceName\": \"John's Phone\",\n      \"deviceRiskScore\": \"3\",\n      \"deviceTenure\": 12,\n      \"deviceType\": \"Phone\",\n      \"ipAddress\": \"192.0.2.1\",\n      \"location\": {\n        \"latitude\": \"40.7128\",\n        \"longitude\": \"-74.0060\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"shipment\": {\n    \"shippingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"firstName\": \"Jane\",\n      \"lastName\": \"Jones\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"shippingEmail\": \"someone@example.com\",\n    \"shippingMethod\": \"EXPEDITED\",\n    \"shippingPhoneNumber\": \"+14155552671\"\n  },\n  \"user\": {\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}")
  .asString();
```

```php The initial request for generating payment credentials (before step-up verification)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials', [
  'body' => '{
  "agent": {
    "agentName": "NexusAI",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "gpt-4.1"
  },
  "orderContext": {
    "allowPartialOrder": "NO",
    "currency": "USD",
    "items": [
      {
        "brand": "Example Brand",
        "category": "Smartphones",
        "condition": "new",
        "currency": "USD",
        "imageLink": "https://example.com/images/product-image",
        "isGiftCard": "NO",
        "isRecurBill": "NO",
        "isRefundable": "YES",
        "itemId": "item_001",
        "merchantId": 987654,
        "metadata": {
          "additionalProperty": "string",
          "color": "Black Titanium",
          "modelNumber": "A3101",
          "releaseYear": "2025"
        },
        "name": "Premium Smartphone 256GB",
        "purchaseCriteria": {
          "0": {
            "currency": "USD",
            "fromDate": "2026-03-20T18:30:00Z",
            "isShippingIncluded": "YES",
            "maxAmount": "1200",
            "pricePreference": "MAXIMUM_PRICE",
            "toDate": "2026-03-22T18:30:00Z",
            "type": "PRICE"
          }
        },
        "quantity": 1,
        "unitAmount": "1099"
      }
    ],
    "merchants": [
      {
        "categoryName": "Electronics",
        "merchantId": 987654,
        "metadata": {
          "additionalProperty": "string",
          "fulfillmentModel": "first_party",
          "region": "US",
          "storeType": "official"
        },
        "name": "Example Store",
        "policies": {
          "returnPolicy": "https://www.example.com/returns",
          "returnWindow": "14",
          "termsOfService": "https://www.example.com/terms"
        },
        "seNumber": "123456789012",
        "sellerId": "seller_example_official",
        "url": "https://www.example.com"
      }
    ],
    "orderId": "order_789456123",
    "totalAmount": "1099",
    "type": "CART"
  },
  "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
  "purchaseDecision": "NON-DELEGATED",
  "requestedPaymentCredentialsCount": 1,
  "risk": {
    "account": {
      "accountRiskScore": "2",
      "agentAccountLocale": "en-US",
      "mostRecentAccountPaymentMethodChangeActivity": 30,
      "panTenureOnFile": 24,
      "partnerStepUp": "YES",
      "recentSecurityActivity": "10"
    },
    "device": {
      "deviceId": "device_abc123",
      "deviceName": "John\'s Phone",
      "deviceRiskScore": "3",
      "deviceTenure": 12,
      "deviceType": "Phone",
      "ipAddress": "192.0.2.1",
      "location": {
        "latitude": "40.7128",
        "longitude": "-74.0060"
      },
      "tlsFingerprint": "771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0"
    },
    "metadata": {
      "additionalProperty": "string",
      "ipReputation": "low_risk"
    }
  },
  "shipment": {
    "shippingAddress": {
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "firstName": "Jane",
      "lastName": "Jones",
      "postalCode": "12345",
      "state": "NY"
    },
    "shippingEmail": "someone@example.com",
    "shippingMethod": "EXPEDITED",
    "shippingPhoneNumber": "+14155552671"
  },
  "user": {
    "billingAddress": {
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "postalCode": "12345",
      "state": "NY"
    },
    "email": "someone@example.com",
    "firstName": "Jane",
    "lastName": "Jones",
    "userEmailHash": "b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5",
    "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The initial request for generating payment credentials (before step-up verification)
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"agent\": {\n    \"agentName\": \"NexusAI\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"gpt-4.1\"\n  },\n  \"orderContext\": {\n    \"allowPartialOrder\": \"NO\",\n    \"currency\": \"USD\",\n    \"items\": [\n      {\n        \"brand\": \"Example Brand\",\n        \"category\": \"Smartphones\",\n        \"condition\": \"new\",\n        \"currency\": \"USD\",\n        \"imageLink\": \"https://example.com/images/product-image\",\n        \"isGiftCard\": \"NO\",\n        \"isRecurBill\": \"NO\",\n        \"isRefundable\": \"YES\",\n        \"itemId\": \"item_001\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"color\": \"Black Titanium\",\n          \"modelNumber\": \"A3101\",\n          \"releaseYear\": \"2025\"\n        },\n        \"name\": \"Premium Smartphone 256GB\",\n        \"purchaseCriteria\": {\n          \"0\": {\n            \"currency\": \"USD\",\n            \"fromDate\": \"2026-03-20T18:30:00Z\",\n            \"isShippingIncluded\": \"YES\",\n            \"maxAmount\": \"1200\",\n            \"pricePreference\": \"MAXIMUM_PRICE\",\n            \"toDate\": \"2026-03-22T18:30:00Z\",\n            \"type\": \"PRICE\"\n          }\n        },\n        \"quantity\": 1,\n        \"unitAmount\": \"1099\"\n      }\n    ],\n    \"merchants\": [\n      {\n        \"categoryName\": \"Electronics\",\n        \"merchantId\": 987654,\n        \"metadata\": {\n          \"additionalProperty\": \"string\",\n          \"fulfillmentModel\": \"first_party\",\n          \"region\": \"US\",\n          \"storeType\": \"official\"\n        },\n        \"name\": \"Example Store\",\n        \"policies\": {\n          \"returnPolicy\": \"https://www.example.com/returns\",\n          \"returnWindow\": \"14\",\n          \"termsOfService\": \"https://www.example.com/terms\"\n        },\n        \"seNumber\": \"123456789012\",\n        \"sellerId\": \"seller_example_official\",\n        \"url\": \"https://www.example.com\"\n      }\n    ],\n    \"orderId\": \"order_789456123\",\n    \"totalAmount\": \"1099\",\n    \"type\": \"CART\"\n  },\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"purchaseDecision\": \"NON-DELEGATED\",\n  \"requestedPaymentCredentialsCount\": 1,\n  \"risk\": {\n    \"account\": {\n      \"accountRiskScore\": \"2\",\n      \"agentAccountLocale\": \"en-US\",\n      \"mostRecentAccountPaymentMethodChangeActivity\": 30,\n      \"panTenureOnFile\": 24,\n      \"partnerStepUp\": \"YES\",\n      \"recentSecurityActivity\": \"10\"\n    },\n    \"device\": {\n      \"deviceId\": \"device_abc123\",\n      \"deviceName\": \"John's Phone\",\n      \"deviceRiskScore\": \"3\",\n      \"deviceTenure\": 12,\n      \"deviceType\": \"Phone\",\n      \"ipAddress\": \"192.0.2.1\",\n      \"location\": {\n        \"latitude\": \"40.7128\",\n        \"longitude\": \"-74.0060\"\n      },\n      \"tlsFingerprint\": \"771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0\"\n    },\n    \"metadata\": {\n      \"additionalProperty\": \"string\",\n      \"ipReputation\": \"low_risk\"\n    }\n  },\n  \"shipment\": {\n    \"shippingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"firstName\": \"Jane\",\n      \"lastName\": \"Jones\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"shippingEmail\": \"someone@example.com\",\n    \"shippingMethod\": \"EXPEDITED\",\n    \"shippingPhoneNumber\": \"+14155552671\"\n  },\n  \"user\": {\n    \"billingAddress\": {\n      \"addressLine1\": \"300 Juniper Lane\",\n      \"addressLine2\": \"Apt 4B\",\n      \"city\": \"New York\",\n      \"country\": \"US\",\n      \"postalCode\": \"12345\",\n      \"state\": \"NY\"\n    },\n    \"email\": \"someone@example.com\",\n    \"firstName\": \"Jane\",\n    \"lastName\": \"Jones\",\n    \"userEmailHash\": \"b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5\",\n    \"userPhoneNumberHash\": \"a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift The initial request for generating payment credentials (before step-up verification)
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId",
  "Content-Type": "application/json"
]
let parameters = [
  "agent": [
    "agentName": "NexusAI",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "gpt-4.1"
  ],
  "orderContext": [
    "allowPartialOrder": "NO",
    "currency": "USD",
    "items": [
      [
        "brand": "Example Brand",
        "category": "Smartphones",
        "condition": "new",
        "currency": "USD",
        "imageLink": "https://example.com/images/product-image",
        "isGiftCard": "NO",
        "isRecurBill": "NO",
        "isRefundable": "YES",
        "itemId": "item_001",
        "merchantId": 987654,
        "metadata": [
          "additionalProperty": "string",
          "color": "Black Titanium",
          "modelNumber": "A3101",
          "releaseYear": "2025"
        ],
        "name": "Premium Smartphone 256GB",
        "purchaseCriteria": ["0": [
            "currency": "USD",
            "fromDate": "2026-03-20T18:30:00Z",
            "isShippingIncluded": "YES",
            "maxAmount": "1200",
            "pricePreference": "MAXIMUM_PRICE",
            "toDate": "2026-03-22T18:30:00Z",
            "type": "PRICE"
          ]],
        "quantity": 1,
        "unitAmount": "1099"
      ]
    ],
    "merchants": [
      [
        "categoryName": "Electronics",
        "merchantId": 987654,
        "metadata": [
          "additionalProperty": "string",
          "fulfillmentModel": "first_party",
          "region": "US",
          "storeType": "official"
        ],
        "name": "Example Store",
        "policies": [
          "returnPolicy": "https://www.example.com/returns",
          "returnWindow": "14",
          "termsOfService": "https://www.example.com/terms"
        ],
        "seNumber": "123456789012",
        "sellerId": "seller_example_official",
        "url": "https://www.example.com"
      ]
    ],
    "orderId": "order_789456123",
    "totalAmount": "1099",
    "type": "CART"
  ],
  "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
  "purchaseDecision": "NON-DELEGATED",
  "requestedPaymentCredentialsCount": 1,
  "risk": [
    "account": [
      "accountRiskScore": "2",
      "agentAccountLocale": "en-US",
      "mostRecentAccountPaymentMethodChangeActivity": 30,
      "panTenureOnFile": 24,
      "partnerStepUp": "YES",
      "recentSecurityActivity": "10"
    ],
    "device": [
      "deviceId": "device_abc123",
      "deviceName": "John's Phone",
      "deviceRiskScore": "3",
      "deviceTenure": 12,
      "deviceType": "Phone",
      "ipAddress": "192.0.2.1",
      "location": [
        "latitude": "40.7128",
        "longitude": "-74.0060"
      ],
      "tlsFingerprint": "771,4865-4866-4867-49195-49196,0-11-10-35,29-23-24,0"
    ],
    "metadata": [
      "additionalProperty": "string",
      "ipReputation": "low_risk"
    ]
  ],
  "shipment": [
    "shippingAddress": [
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "firstName": "Jane",
      "lastName": "Jones",
      "postalCode": "12345",
      "state": "NY"
    ],
    "shippingEmail": "someone@example.com",
    "shippingMethod": "EXPEDITED",
    "shippingPhoneNumber": "+14155552671"
  ],
  "user": [
    "billingAddress": [
      "addressLine1": "300 Juniper Lane",
      "addressLine2": "Apt 4B",
      "city": "New York",
      "country": "US",
      "postalCode": "12345",
      "state": "NY"
    ],
    "email": "someone@example.com",
    "firstName": "Jane",
    "lastName": "Jones",
    "userEmailHash": "b4c9a289323b21a01c3e940f150eb9b8b6c8f0d3a9a5f8c2e5d7f6a1b2c3d4e5",
    "userPhoneNumberHash": "a3f5c2e9d4b7c1a8f6e2d3c4b5a6978877665544332211ffeeddccbbaa998877"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### The follow-up request after completing step-up verification.

**Request**

```json
{
  "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
  "stepUpVerification": {
    "issuerSurfaceAuthenticationResponse": {
      "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"
    },
    "safeKeyAuthenticationResponse": {
      "riskToken": "eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature"
    },
    "securePushAuthenticationResponse": {
      "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"
    },
    "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f",
    "validateAuthenticationCode": {
      "value": "482913"
    }
  }
}
```

**Response**

```json
{
  "availableChallenges": [
    {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  ],
  "enrollmentId": "string",
  "paymentCredentialId": "string",
  "paymentCredentialStatus": "PENDING_STEP_UP",
  "paymentCredentials": [
    {
      "dcsc": "0000",
      "expiryMonth": "09",
      "expiryYear": "2026",
      "merchantId": "abc12345",
      "tokenNumber": "000000000000000"
    }
  ],
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python The follow-up request after completing step-up verification.
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

payload = {
    "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
    "stepUpVerification": {
        "issuerSurfaceAuthenticationResponse": { "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e" },
        "safeKeyAuthenticationResponse": { "riskToken": "eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature" },
        "securePushAuthenticationResponse": { "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e" },
        "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f",
        "validateAuthenticationCode": { "value": "482913" }
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript The follow-up request after completing step-up verification.
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    agentId: 'agentId',
    trackingId: 'trackingId',
    'Content-Type': 'application/json'
  },
  body: '{"proofOfIntent":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy","stepUpVerification":{"issuerSurfaceAuthenticationResponse":{"authenticationToken":"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"},"safeKeyAuthenticationResponse":{"riskToken":"eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature"},"securePushAuthenticationResponse":{"authenticationToken":"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"},"stepUpSessionId":"sess_9f3a7c2d8b6e4a1f","validateAuthenticationCode":{"value":"482913"}}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go The follow-up request after completing step-up verification.
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

	payload := strings.NewReader("{\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"safeKeyAuthenticationResponse\": {\n      \"riskToken\": \"eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature\"\n    },\n    \"securePushAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\",\n    \"validateAuthenticationCode\": {\n      \"value\": \"482913\"\n    }\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby The follow-up request after completing step-up verification.
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"safeKeyAuthenticationResponse\": {\n      \"riskToken\": \"eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature\"\n    },\n    \"securePushAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\",\n    \"validateAuthenticationCode\": {\n      \"value\": \"482913\"\n    }\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java The follow-up request after completing step-up verification.
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .header("Content-Type", "application/json")
  .body("{\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"safeKeyAuthenticationResponse\": {\n      \"riskToken\": \"eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature\"\n    },\n    \"securePushAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\",\n    \"validateAuthenticationCode\": {\n      \"value\": \"482913\"\n    }\n  }\n}")
  .asString();
```

```php The follow-up request after completing step-up verification.
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials', [
  'body' => '{
  "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
  "stepUpVerification": {
    "issuerSurfaceAuthenticationResponse": {
      "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"
    },
    "safeKeyAuthenticationResponse": {
      "riskToken": "eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature"
    },
    "securePushAuthenticationResponse": {
      "authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"
    },
    "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f",
    "validateAuthenticationCode": {
      "value": "482913"
    }
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp The follow-up request after completing step-up verification.
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"proofOfIntent\": \"eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy\",\n  \"stepUpVerification\": {\n    \"issuerSurfaceAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"safeKeyAuthenticationResponse\": {\n      \"riskToken\": \"eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature\"\n    },\n    \"securePushAuthenticationResponse\": {\n      \"authenticationToken\": \"rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e\"\n    },\n    \"stepUpSessionId\": \"sess_9f3a7c2d8b6e4a1f\",\n    \"validateAuthenticationCode\": {\n      \"value\": \"482913\"\n    }\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift The follow-up request after completing step-up verification.
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId",
  "Content-Type": "application/json"
]
let parameters = [
  "proofOfIntent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImludGVudC1rZXktMSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhbWV4LXRzcCIsInN1YiI6ImVucm9sbG1lbnRfOGYzYTljMmQ3YjZlNGExZiIsImludGVudElkIjoiaW50ZW50Xzg3NjU0MzIxIiwibWVyY2hhbnRJZCI6Ijk4NzY1NCIsImFtb3VudCI6IjEwOTkiLCJjdXJyZW5jeSI6IlVTRCIsInNjb3BlIjoiaW50ZW50IiwiaWF0IjoxNzQyMzQyMjAwLCJleHAiOjE3NDIzNDU4MDB9.c2lnbmF0dXJlX3BsYWNlaG9sZGVy",
  "stepUpVerification": [
    "issuerSurfaceAuthenticationResponse": ["authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"],
    "safeKeyAuthenticationResponse": ["riskToken": "eyJraWQiOiIxMjM0NTY3ODkwIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiJ1c2VyX2lkIn0.signature"],
    "securePushAuthenticationResponse": ["authenticationToken": "rt_7a9c3d5e8f1b4a2c9d0e6f3a1b2c4d5e"],
    "stepUpSessionId": "sess_9f3a7c2d8b6e4a1f",
    "validateAuthenticationCode": ["value": "482913"]
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Encrypted payload (on the wire)

**Request**

```json
{
  "agent": {
    "agentName": "string",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "string"
  },
  "encryptedPayload": "<jwe-payload>",
  "orderContext": {
    "currency": "string",
    "merchants": [
      {
        "url": "string"
      }
    ],
    "totalAmount": "string"
  }
}
```

**Response**

```json
{
  "availableChallenges": [
    {
      "issuerSurface": {
        "authenticationToken": "string",
        "url": "string"
      },
      "type": "ISSUER_SURFACE"
    }
  ],
  "enrollmentId": "string",
  "paymentCredentialId": "string",
  "paymentCredentialStatus": "PENDING_STEP_UP",
  "paymentCredentials": [
    {
      "dcsc": "0000",
      "expiryMonth": "09",
      "expiryYear": "2026",
      "merchantId": "abc12345",
      "tokenNumber": "000000000000000"
    }
  ],
  "stepUpAuthenticationRequired": "YES",
  "stepUpSessionId": "string"
}
```

**SDK Code**

```python Encrypted payload (on the wire)
import requests

url = "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

payload = {
    "agent": {
        "agentName": "string",
        "llmPlatform": "OPEN_AI",
        "llmVersion": "string"
    },
    "encryptedPayload": "<jwe-payload>",
    "orderContext": {
        "currency": "string",
        "merchants": [{ "url": "string" }],
        "totalAmount": "string"
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "agentId": "agentId",
    "trackingId": "trackingId",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Encrypted payload (on the wire)
const url = 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    agentId: 'agentId',
    trackingId: 'trackingId',
    'Content-Type': 'application/json'
  },
  body: '{"agent":{"agentName":"string","llmPlatform":"OPEN_AI","llmVersion":"string"},"encryptedPayload":"<jwe-payload>","orderContext":{"currency":"string","merchants":[{"url":"string"}],"totalAmount":"string"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Encrypted payload (on the wire)
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials"

	payload := strings.NewReader("{\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"orderContext\": {\n    \"currency\": \"string\",\n    \"merchants\": [\n      {\n        \"url\": \"string\"\n      }\n    ],\n    \"totalAmount\": \"string\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("agentId", "agentId")
	req.Header.Add("trackingId", "trackingId")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Encrypted payload (on the wire)
require 'uri'
require 'net/http'

url = URI("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["agentId"] = 'agentId'
request["trackingId"] = 'trackingId'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"orderContext\": {\n    \"currency\": \"string\",\n    \"merchants\": [\n      {\n        \"url\": \"string\"\n      }\n    ],\n    \"totalAmount\": \"string\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java Encrypted payload (on the wire)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")
  .header("Authorization", "Bearer <token>")
  .header("agentId", "agentId")
  .header("trackingId", "trackingId")
  .header("Content-Type", "application/json")
  .body("{\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"orderContext\": {\n    \"currency\": \"string\",\n    \"merchants\": [\n      {\n        \"url\": \"string\"\n      }\n    ],\n    \"totalAmount\": \"string\"\n  }\n}")
  .asString();
```

```php Encrypted payload (on the wire)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials', [
  'body' => '{
  "agent": {
    "agentName": "string",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "string"
  },
  "encryptedPayload": "<jwe-payload>",
  "orderContext": {
    "currency": "string",
    "merchants": [
      {
        "url": "string"
      }
    ],
    "totalAmount": "string"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'agentId' => 'agentId',
    'trackingId' => 'trackingId',
  ],
]);

echo $response->getBody();
```

```csharp Encrypted payload (on the wire)
using RestSharp;

var client = new RestClient("https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("agentId", "agentId");
request.AddHeader("trackingId", "trackingId");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"agent\": {\n    \"agentName\": \"string\",\n    \"llmPlatform\": \"OPEN_AI\",\n    \"llmVersion\": \"string\"\n  },\n  \"encryptedPayload\": \"<jwe-payload>\",\n  \"orderContext\": {\n    \"currency\": \"string\",\n    \"merchants\": [\n      {\n        \"url\": \"string\"\n      }\n    ],\n    \"totalAmount\": \"string\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Encrypted payload (on the wire)
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "agentId": "agentId",
  "trackingId": "trackingId",
  "Content-Type": "application/json"
]
let parameters = [
  "agent": [
    "agentName": "string",
    "llmPlatform": "OPEN_AI",
    "llmVersion": "string"
  ],
  "encryptedPayload": "<jwe-payload>",
  "orderContext": [
    "currency": "string",
    "merchants": [["url": "string"]],
    "totalAmount": "string"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://apisandboxm.americanexpress.com/payments/digital/v1/agentic-commerce/paymentcredentials")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```