> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Create Authorizations

POST https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations
Content-Type: application/json

Simulates and retrieves Authorizations for Virtual Cards in the Sandbox environment for integration. This API is not available in the Staging or Production environments.

Reference: https://developer.americanexpress.ferndocs.com/payment-services/card-on-demand/api-reference/create-authorizations

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand` (Sandbox, default)
- `https://api.americanexpress.com/commercial/v1/card_on_demand` (Production)

## Request

### Body (application/json)

This endpoint expects an object.

- `cardId` (string, required) — A unique ID that is created for the Card.
- `authorizationDetails` (list of AuthorizationsPostRequestBodyContentApplicationJsonSchemaAuthorizationDetailsItems, required)

## Response

### 200

Successful operation

- `cardId` (string, required) — A unique ID that is created for the Card.
- `accountId` (string, required) — A unique ID that is created for the Account.
- `cardDetails` (AuthorizationsPostResponsesContentApplicationJsonSchemaCardDetails, required) — The details of the Card being created.
- `authorizationDetails` (list of AuthorizationsPostResponsesContentApplicationJsonSchemaAuthorizationDetailsItems, required)

## Errors

### 400 Bad Request Error

Bad Request

- `errors` (list of 400ErrorItems, required)

### 401 Unauthorized Error

Unauthorized

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 500 Internal Server Error

Service error

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 503 Service Unavailable Error

Service unavailable

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

## Types

### AuthorizationsPostRequestBodyContentApplicationJsonSchemaAuthorizationDetailsItems

- `authorizationAmount` (string, required) — The net amount authorized by the Supplier. The amount cannot be more than the balance on the Card and is controlled by the latest domain controls applied on the Card. In cases of credits, the amount will be represented as a negative value.
- `authorizationCurrency` (enum, required) — The currency of the Authorization by the Supplier. This field only supports USD.
  - Allowed values: `USD`
- `merchantNumber` (string, required) — The account number assigned to the Supplier within American Express.
- `merchantName` (string, required) — The Merchant's name linked to the Supplier's Merchant Number within American Express.
- `merchantCity` (string, required) — The city associated with the Supplier's Merchant Number within American Express.
- `merchantState` (string, required) — The state associated with the Supplier's Merchant Number within American Express. Only Two-digit ISO state codes are acceptable.
- `merchantCountry` (string, required) — The country associated with the Supplier's Merchant Number within American Express.
- `digitalWallet` (string, optional) — This field indicates if the transaction was made via a digital wallet. The only possible value can be Apple Pay for the Sandbox environment.

### AuthorizationsPostResponsesContentApplicationJsonSchemaCardDetails

The details of the Card being created.

- `cardReferenceId` (string, required) — A unique ID that can be assigned by the Buyer resource to each of the Cards requested. For instance, some Buyers use invoice numbers or employee codes to help match Cards within their systems. This field only accepts alphanumeric characters and hyphens ( - ).

### AuthorizationsPostResponsesContentApplicationJsonSchemaAuthorizationDetailsItems

- `authorizationAmount` (string, required) — The net amount authorized by the Supplier. The amount cannot be more than the balance on the Card and is controlled by the latest domain controls applied on the Card. In cases of credits, the amount will be represented as a negative value.
- `authorizationDate` (string, required) — The date when the Supplier tried to authorize the amount on the Card. The format is: YYYY-MM-DD.
- `authorizationTimestamp` (string, required) — The timestamp of when the Supplier tried to authorize the amount on the Card in ISO 8601 format yyyy-MM-ddThh:mm:ss+00:00.
- `authorizationStatus` (string, required) — Indicates if an Authorization was approved or declined.
- `lastFive` (string, required) — The last five digits of the Account.
- `merchantNumber` (string, required) — The account number assigned to the Supplier within American Express.
- `merchantName` (string, required) — The Merchant's name linked to the Supplier's Merchant Number within American Express.
- `merchantCity` (string, required) — The city associated with the Supplier's Merchant Number within American Express.
- `merchantState` (string, required) — The state associated with the Supplier's Merchant Number within American Express.
- `merchantCountry` (string, required) — The country associated with the Supplier's Merchant Number within American Express.
- `authorizationId` (string, required) — A unique ID assigned for every Authorization which may be used to link the Merchant Authorizations to the transactions.
- `authorizationCurrency` (enum, required) — The currency of the Authorization by the Supplier.
  - Allowed values: `USD`

### 400ErrorItems

- `code` (string, required) — A machine-readable field indicating the type of error.
- `message` (string, required) — Provides a short description of the error.
- `detail` (string, optional) — Provides a detailed description of the error.
- `link` (string, optional) — The link to documentation that explains the error.

## Examples

**Request**

```json
{
  "cardId": " CAEQd4zBEYrPi56",
  "authorizationDetails": [
    {
      "authorizationAmount": "200.00",
      "authorizationCurrency": "USD",
      "merchantNumber": "8906067845",
      "merchantName": "ABCD",
      "merchantCity": "Phoenix",
      "merchantState": "AZ",
      "merchantCountry": "US",
      "digitalWallet": "Apple Pay"
    }
  ]
}
```

**Response**

```json
{
  "cardId": "CADT8UJhrYUscMR",
  "accountId": "CRXe8JnRUNOZCDn",
  "cardDetails": {
    "cardReferenceId": " PO12345-AB7890"
  },
  "authorizationDetails": [
    {
      "authorizationAmount": "200.00",
      "authorizationDate": "2016-07-07",
      "authorizationTimestamp": "2023-10-09T17:48:46+00:00",
      "authorizationStatus": "APPROVED",
      "lastFive": "11111",
      "merchantNumber": "8906067845",
      "merchantName": "ABCD",
      "merchantCity": "Phoenix",
      "merchantState": "AZ",
      "merchantCountry": "US",
      "authorizationId": "85345",
      "authorizationCurrency": "USD"
    }
  ]
}
```

**SDK Code**

```python createAuthorizations_example
import requests

url = "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations"

payload = {
    "cardId": " CAEQd4zBEYrPi56",
    "authorizationDetails": [
        {
            "authorizationAmount": "200.00",
            "authorizationCurrency": "USD",
            "merchantNumber": "8906067845",
            "merchantName": "ABCD",
            "merchantCity": "Phoenix",
            "merchantState": "AZ",
            "merchantCountry": "US",
            "digitalWallet": "Apple Pay"
        }
    ]
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript createAuthorizations_example
const url = 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"cardId":" CAEQd4zBEYrPi56","authorizationDetails":[{"authorizationAmount":"200.00","authorizationCurrency":"USD","merchantNumber":"8906067845","merchantName":"ABCD","merchantCity":"Phoenix","merchantState":"AZ","merchantCountry":"US","digitalWallet":"Apple Pay"}]}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go createAuthorizations_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations"

	payload := strings.NewReader("{\n  \"cardId\": \" CAEQd4zBEYrPi56\",\n  \"authorizationDetails\": [\n    {\n      \"authorizationAmount\": \"200.00\",\n      \"authorizationCurrency\": \"USD\",\n      \"merchantNumber\": \"8906067845\",\n      \"merchantName\": \"ABCD\",\n      \"merchantCity\": \"Phoenix\",\n      \"merchantState\": \"AZ\",\n      \"merchantCountry\": \"US\",\n      \"digitalWallet\": \"Apple Pay\"\n    }\n  ]\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby createAuthorizations_example
require 'uri'
require 'net/http'

url = URI("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"cardId\": \" CAEQd4zBEYrPi56\",\n  \"authorizationDetails\": [\n    {\n      \"authorizationAmount\": \"200.00\",\n      \"authorizationCurrency\": \"USD\",\n      \"merchantNumber\": \"8906067845\",\n      \"merchantName\": \"ABCD\",\n      \"merchantCity\": \"Phoenix\",\n      \"merchantState\": \"AZ\",\n      \"merchantCountry\": \"US\",\n      \"digitalWallet\": \"Apple Pay\"\n    }\n  ]\n}"

response = http.request(request)
puts response.read_body
```

```java createAuthorizations_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"cardId\": \" CAEQd4zBEYrPi56\",\n  \"authorizationDetails\": [\n    {\n      \"authorizationAmount\": \"200.00\",\n      \"authorizationCurrency\": \"USD\",\n      \"merchantNumber\": \"8906067845\",\n      \"merchantName\": \"ABCD\",\n      \"merchantCity\": \"Phoenix\",\n      \"merchantState\": \"AZ\",\n      \"merchantCountry\": \"US\",\n      \"digitalWallet\": \"Apple Pay\"\n    }\n  ]\n}")
  .asString();
```

```php createAuthorizations_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations', [
  'body' => '{
  "cardId": " CAEQd4zBEYrPi56",
  "authorizationDetails": [
    {
      "authorizationAmount": "200.00",
      "authorizationCurrency": "USD",
      "merchantNumber": "8906067845",
      "merchantName": "ABCD",
      "merchantCity": "Phoenix",
      "merchantState": "AZ",
      "merchantCountry": "US",
      "digitalWallet": "Apple Pay"
    }
  ]
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp createAuthorizations_example
using RestSharp;

var client = new RestClient("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"cardId\": \" CAEQd4zBEYrPi56\",\n  \"authorizationDetails\": [\n    {\n      \"authorizationAmount\": \"200.00\",\n      \"authorizationCurrency\": \"USD\",\n      \"merchantNumber\": \"8906067845\",\n      \"merchantName\": \"ABCD\",\n      \"merchantCity\": \"Phoenix\",\n      \"merchantState\": \"AZ\",\n      \"merchantCountry\": \"US\",\n      \"digitalWallet\": \"Apple Pay\"\n    }\n  ]\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift createAuthorizations_example
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "cardId": " CAEQd4zBEYrPi56",
  "authorizationDetails": [
    [
      "authorizationAmount": "200.00",
      "authorizationCurrency": "USD",
      "merchantNumber": "8906067845",
      "merchantName": "ABCD",
      "merchantCity": "Phoenix",
      "merchantState": "AZ",
      "merchantCountry": "US",
      "digitalWallet": "Apple Pay"
    ]
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```