> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Retrieve Authorizations

GET https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations

Returns up to the last 100 Authorizations of the Card specified in the query; a maximum of 50 approved and 50 declined Authorizations.

Reference: https://developer.americanexpress.ferndocs.com/payment-services/card-on-demand/api-reference/retrieve-authorizations

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand` (Sandbox, default)
- `https://api.americanexpress.com/commercial/v1/card_on_demand` (Production)

## Request

### Query parameters

- `cardId` (string, required) — A unique ID assigned to the Card.

## Response

### 200

Successful operation

- `cardId` (string, required) — A unique ID that is created for the Card.
- `authorizationDetails` (list of AuthorizationDetailsItems, required)

## Errors

### 400 Bad Request Error

Bad Request

- `errors` (list of 400ErrorItems, required)

### 401 Unauthorized Error

Unauthorized

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 403 Forbidden Error

Unauthenticated

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 404 Not Found Error

Resource not found

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 500 Internal Server Error

Service error

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

## Types

### AuthorizationDetailsItems

- `authorizationId` (string, optional) — A unique ID assigned for every Authorization which may be used to link the Merchant Authorizations to the transactions.
- `authorizationStatus` (string, optional) — Indicates if an Authorization was approved or declined.
- `authorizationAmount` (string, optional) — The net amount authorized by the Supplier. The amount cannot be more than the balance on the Card and is controlled by the latest domain controls applied on the Card. In cases of credits, the amount will be represented as a negative value.
- `authorizationCurrency` (enum, optional) — The Authorization Currency is the currency authorized by the Supplier.
  - Allowed values: `USD`
- `authorizationDate` (string, optional) — The date when the Supplier tried to authorize the amount on the Card. The format is: YYYY-MM-DD.
- `authorizationTimestamp` (string, optional) — The timestamp of when the Supplier tried to authorize the amount on the Card in ISO 8601 format yyyy-MM-ddThh:mm:ss+00:00.
- `authorizationDeclineReason` (string, optional) — The reason for which an Authorization on the Card was declined.
- `lastFive` (string, optional) — The last five digits of the on-demand Card on which the Authorization occurred.
- `merchantNumber` (string, optional) — The account number assigned to the Supplier within American Express.
- `merchantName` (string, optional) — The Merchant's name linked to the Supplier's Merchant Number within American Express.
- `merchantCity` (string, optional) — The city associated with the Supplier's Merchant Number within American Express.
- `merchantState` (string, optional) — The state associated with the Supplier's Merchant Number within American Express.
- `merchantCountry` (string, optional) — The country associated with the Supplier's Merchant Number within American Express.
- `digitalWallet` (string, optional) — This field indicates if the transaction was made via a digital wallet. The possible values can be Samsung Pay, Google Pay, Apple Pay or Not applicable (if digital wallet was not used).

### 400ErrorItems

- `code` (string, required) — A machine-readable field indicating the type of error.
- `message` (string, required) — Provides a short description of the error.
- `detail` (string, optional) — Provides a detailed description of the error.
- `link` (string, optional) — The link to documentation that explains the error.

## Examples

**Response**

```json
{
  "cardId": "CAEQd4zBEYrPi56",
  "authorizationDetails": [
    {
      "authorizationId": "85345",
      "authorizationStatus": "Approved",
      "authorizationAmount": "200.00",
      "authorizationCurrency": "USD",
      "authorizationDate": "2016-07-07",
      "authorizationTimestamp": "2022-12-05T18:10:10+00:00",
      "lastFive": "11111",
      "merchantNumber": "8906067845",
      "merchantName": "ABCD",
      "merchantCity": "PHOENIX",
      "merchantState": "AZ",
      "merchantCountry": "US",
      "digitalWallet": "Apple Pay"
    }
  ]
}
```

**SDK Code**

```python retrieveAuthorizations_example
import requests

url = "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations"

querystring = {"cardId":"CAEQd4zBEYrPi56"}

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers, params=querystring)

print(response.json())
```

```javascript retrieveAuthorizations_example
const url = 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go retrieveAuthorizations_example
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby retrieveAuthorizations_example
require 'uri'
require 'net/http'

url = URI("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java retrieveAuthorizations_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php retrieveAuthorizations_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp retrieveAuthorizations_example
using RestSharp;

var client = new RestClient("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift retrieveAuthorizations_example
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/authorizations?cardId=CAEQd4zBEYrPi56")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```