Create a Points Transfer redemption order.
Create an order to redeem points from a Loyalty account and transfer those points to a Partner account.
Authentication
HMAC (one-way TLS). A MAC authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac
HMAC over mutual TLS. Requires a client certificate in addition to the signed MAC authorization header.
OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as Authorization: Bearer <token>.
Headers
The Authorization header for the authentication at APIGEE. The following should be in the format of this header:
- MAC id: The Partner's Client ID. The Client ID is generated during the Partner Onboarding and the App Registration.
- ts: A client-generated timestamp (Unix Epoch format in milli-seconds).
- nonce: A unique identifier string. The value of nonce must be unique for the each request.
- mac: The request mac is generated using the HMAC SHA256 algorithm. Use the Client Secret to generate a hash/signature. The Client ID and Client Secret is generated during the Partner Onboarding and App registration.
e.g., MAC id="adc3af10-7bf6-4d8a-87ea-35519ff6e1ad",ts="1466548572491",nonce="be3bd46c-b052-4ae8-9f61-993635e5bc98",bodyhash="cRPVGQWU+89HNR0ASAJFjhKqDF9X0pApGYuC/NVQNEU=",mac="NqbqNO3vSBwk6EE7pBi11DzvgLCh50IPAICCIWgjxYA="
A unique identifier used to track the request. This is with the current debugging standard in mind to track the request end-to-end. This will be mainly passed by the originating server (if it's a Webapp) or empty in case of the direct browser/app calls.
e.g., GUID.
The sender contains the sender information.
e.g., Issuer or Service Provider.
The value assigned to the key used to encrypt the payload. For HIPED operations, this value must start with 'MK'.
e.g., AA3434342323.
Request
A unique identifier for the Order provided by the originating system. Each request originating from this Consumer, or the Channel, should be unique across all time. This is required by Network Loyalty GNS.
e.g., GUID.
A timestamp to be provided by the originating system. This is required by Network Loyalty GNS.
e.g., yyyy-MM-dd'T'HH:mm:ss.SSS'Z'.
A unique ID for an instrument that is internal to the Issuer.
e.g., GUID.
This is required by Network Loyalty GNS. The Program name consists of the relevant Partner Program to which the Points Transfer should be applied.
- For Air France, AFKLM_FLYING_BLUE.
- For British Airways, BA_EXECUTIVE_CLUB.
- For Cathay Pacific, CATHAYPACIFIC_ASIAMILES.
- For Delta, DELTA_SKYMILES.
- For Emirates, EMIRATES_SKYWARDS.
- For Hilton, HILTON_HONORS.
- For Jumeirah, JUMEIRAH_SIRIUS.
- For Marriott, MARRIOTT_BONVOY.
- For Singapore Airlines, SINGAPORE_KRISFLYER.
e.g., HILTON_HONORS.
The Partner Account Number, which is an FFN, per legacy terminology. This is required by Network Loyalty GNS.
e.g., The Hilton Honors or the BA Executive Club number of the Customer.
An object containing the GNS-related information.
Codes requested by the Partner to denote categories by which the points were earned.
e.g.,:
- LK001 or LP001 for Hilton non-property spend
- LK002 or LP002 for Hilton on-property spend
- LK004 or LP004 for Duty Free & Air
A generic object for any amount that is related to a specific Loyalty currency. The Membership Rewards (MR) Points value is to be redeemed for a transaction, exclusive of any Excise Tax Offset (ETO) Fee (i.e., if the Consumer chooses to pay the ETO Fee using MR points). Actual redemptions will have two debits to the MR Account. The first debit is the MR Points amount used for the transfer, and the other debit is the fee charged for using the Points. This is required by Network Loyalty GNS.
A generic object for any amount that is related to a specific Loyalty currency. The Membership Rewards (MR) Points value is to be redeemed for a transaction, exclusive of any Excise Tax Offset (ETO) Fee (i.e., if the Consumer chooses to pay the ETO Fee using MR points). Actual redemptions will have two debits to the MR Account. The first debit is the MR Points amount used for the transfer, and the other debit is the fee charged for using the Points. This is required by Network Loyalty GNS.
This is required by Network Loyalty GNS. This contains all possible Customer data which can be sent by Network/Issuer to make a successful transfer.
NOTE: All the fields that follow are optional, as any Partner may have different mandatory fields. Typically, the API checks mandatory parameters from a specific program_name and validates the mandatory fields.
The default is always false. When given the value true, the Processor will run all eligibility checks without invoking the Transactions API.
e.g., false.

