Create a new profile via acquisition.
Based on the acquisition event provided by an event producer system, this endpoint will create a Customer profile if one does not exist and associate a new profile with the provided instrument. Furthermore, the endpoint automatically enrolls the Customer into the default benefits of the associated Partner for the Cobrand Card Acquisition.
Authentication
HMAC (one-way TLS). A MAC authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac
HMAC over mutual TLS. Requires a client certificate in addition to the signed MAC authorization header.
OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as Authorization: Bearer <token>.
Headers
The Authorization header for the authentication at APIGEE. The following should be in the format of this header:
- MAC id: The Partner's Client ID. The Client ID is generated during the Partner Onboarding and the App Registration.
- ts: A client-generated timestamp (Unix Epoch format in milli-seconds).
- nonce: A unique identifier string. The value of nonce must be unique for the each request.
- mac: The request mac is generated using the HMAC SHA256 algorithm. Use the Client Secret to generate a hash/signature. The Client ID and Client Secret is generated during the Partner Onboarding and App registration.
e.g., MAC id="adc3af10-7bf6-4d8a-87ea-35519ff6e1ad",ts="1466548572491",nonce="be3bd46c-b052-4ae8-9f61-993635e5bc98",bodyhash="cRPVGQWU+89HNR0ASAJFjhKqDF9X0pApGYuC/NVQNEU=",mac="NqbqNO3vSBwk6EE7pBi11DzvgLCh50IPAICCIWgjxYA="
A unique identifier used to track the request. This is with the current debugging standard in mind to track the request end-to-end. This will be mainly passed by the originating server (if it's a Webapp) or empty in case of the direct browser/app calls.
e.g., GUID.
The sender contains the sender information.
e.g., Issuer or Service Provider.
The value assigned to the key used to encrypt the payload. For HIPED operations, this value must start with 'MK'.
e.g., AA3434342323.
Request
To track from where this event was initiated.
- Issuer
- Servicing
- Web
- Mobile
Always use: Issuer.
To define an event type.
Always use: v1.instrument.instrumentCreated.
The event initiation time in UTC.
Always use: RFC3339 Nano format.
e.g., 2020-04-13T22:59:42.582326946Z.
The acquisition payload contains data for the Issuer, Applicant/Customer, and instrument information.
The Cloud event Specification version.
NOTE: Always use 0.3.
If populated, this should be the same as the correlation_id.

