> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.americanexpress.ferndocs.com/utilities/network-loyalty/api-reference/retrieve-a-notification-from-r-42/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server. # Retrieve a notification from R42. POST https://api.qa2s.americanexpress.com/loyalty/v1/event/notify Content-Type: application/json This endpoint is used to receive a notification from R42. Reference: https://developer.americanexpress.ferndocs.com/utilities/network-loyalty/api-reference/retrieve-a-notification-from-r-42 ## Authentication - `X-AMEX-API-KEY` header (required) — Application API key issued during app registration. - `Authorization` header (required) — HMAC (one-way TLS). A `MAC` authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac - `Authorization` header (required) — HMAC over mutual TLS. Requires a client certificate in addition to the signed `MAC` authorization header. - `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer `. ## Servers - `https://api.qa2s.americanexpress.com/loyalty` (Sandbox, default) - `https://api.qa2s.americanexpress.com/loyalty/v1/network` (Sandbox, default) ## Request ### Headers - `Authorization` (string, required) — The Authorization header for the authentication at APIGEE. The following should be in the format of this header:MAC id: The Partner's Client ID. The Client ID is generated during the Partner Onboarding and the App Registration.ts: A client-generated timestamp (Unix Epoch format in milli-seconds).nonce: A unique identifier string. The value of nonce must be unique for the each request.mac: The request mac is generated using the HMAC SHA256 algorithm. Use the Client Secret to generate a hash/signature. The Client ID and Client Secret is generated during the Partner Onboarding and App registration.e.g., MAC id="adc3af10-7bf6-4d8a-87ea-35519ff6e1ad",ts="1466548572491",nonce="be3bd46c-b052-4ae8-9f61-993635e5bc98",bodyhash="cRPVGQWU+89HNR0ASAJFjhKqDF9X0pApGYuC/NVQNEU=",mac="NqbqNO3vSBwk6EE7pBi11DzvgLCh50IPAICCIWgjxYA=" - `correlation_id` (string, required) — A unique identifier used to track the request. This is with the current debugging standard in mind to track the request end-to-end. This will be mainly passed by the originating server (if it's a Webapp) or empty in case of the direct browser/app calls.e.g., GUID. ### Body (application/json) This endpoint expects a Notification. - `source` (enum, required) — To track where this event was initiated from.R42-data-pressIssuerServicingWebMobileAlways use: Issuer. - Allowed values: `R42-data-press`, `Issuer`, `Servicing`, `Web`, `Mobile` - `type` (enum, required) — To identify a type of the event.Bullet list:For acquisition, r42.v1.acquisition.For benefit enrollment, r42.v1.benefitEnrolled.For points transfer, r42.v1.partner.award.For replacement, r42.demographic.replaced.For cancellation, r42.v1.cancellation.For reinstatement, r42.v1.reinstatement.e.g., r42.v1.acquisition. - Allowed values: `r42.v1.acquisition`, `r42.v1.benefitEnrolled`, `r42.v1.partner.award`, `r42.demographic.replaced`, `r42.v1.cancellation`, `r42.v1.productTransfer`, `r42.v1.reinstatement` - `time` (string, required) — The event initiation time in UTC.Always use: RFC3339 Nano format.e.g., 2020-04-13T22:59:42.582326946Z. - `data` (NotificationData, required) - `specversion` (enum, optional) — The Cloud event Specification version.NOTE: Always use 0.3. - Allowed values: `0.3` - `id` (string, optional) — A unique ID with respect to the particular event (i.e., Acquisition, Points Transfer, Benefits) based on the Correlation ID and the other elements.e.g., GUID. - `requestor_order_id` (string, optional) — A unique ID of an event given by the Issuer banks, which uniquely identifies a Points Transfer request.e.g., GUID. ## Response ### 202 Successfully accepted. ## Errors ### 400 Bad Request Error Bad request. - `error_code` (string, optional) - `user_message` (string, optional) — An error occurred when processing your request. - `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task. ### 403 Forbidden Error Forbidden request. - `error_code` (string, optional) - `user_message` (string, optional) — An error occurred when processing your request. - `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task. ### 404 Not Found Error Not Found. - `error_code` (string, optional) - `user_message` (string, optional) — An error occurred when processing your request. - `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task. ### 409 Conflict Error Conflict: Business error. - `error_code` (string, optional) - `user_message` (string, optional) — An error occurred when processing your request. - `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task. ### 500 Internal Server Error Internal server error. - `error_code` (string, optional) - `user_message` (string, optional) — An error occurred when processing your request. - `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task. ## Types ### NotificationData - `code` (enum, required) — The status code of the event.e.g., SUCCESS. - Allowed values: `SUCCESS`, `FAILURE` - `program_account_id` (string, optional) — This is the Partner Program Account Number, which is typically referred to as the Frequent Flyer Number (FFN) for for AIRLINE, or Frequent Guest Number (FGN) for the HOTEL.e.g., 6512148008. - `reason_code` (string, optional) — In case of a failure, this will be optionally sent. Specific error codes for a particular failure are returned from the Partner, if applicable.e.g., 1001. - `description` (string, optional) — A short description of the status code for the auditing/monitoring/alerts.e.g., A Transfer event failed. - `developer_message` (string, optional) — An optional message for the developer debugging.e.g., A named_exception was thrown by service_method when performing processing_task. ## Examples **Request** ```json { "source": "Issuer", "type": "r42.v1.acquisition", "time": "2020-04-13T22:59:42.582326946Z", "data": { "code": "SUCCESS" } } ``` **Response** ```json {} ``` **SDK Code** ```python import requests url = "https://api.qa2s.americanexpress.com/loyalty/v1/event/notify" payload = { "source": "Issuer", "type": "r42.v1.acquisition", "time": "2020-04-13T22:59:42.582326946Z", "data": { "code": "SUCCESS" } } headers = { "Authorization": "Authorization", "correlation_id": "correlation_id", "X-AMEX-API-KEY": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.qa2s.americanexpress.com/loyalty/v1/event/notify'; const options = { method: 'POST', headers: { Authorization: 'Authorization', correlation_id: 'correlation_id', 'X-AMEX-API-KEY': '', 'Content-Type': 'application/json' }, body: '{"source":"Issuer","type":"r42.v1.acquisition","time":"2020-04-13T22:59:42.582326946Z","data":{"code":"SUCCESS"}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.qa2s.americanexpress.com/loyalty/v1/event/notify" payload := strings.NewReader("{\n \"source\": \"Issuer\",\n \"type\": \"r42.v1.acquisition\",\n \"time\": \"2020-04-13T22:59:42.582326946Z\",\n \"data\": {\n \"code\": \"SUCCESS\"\n }\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "Authorization") req.Header.Add("correlation_id", "correlation_id") req.Header.Add("X-AMEX-API-KEY", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.qa2s.americanexpress.com/loyalty/v1/event/notify") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Authorization' request["correlation_id"] = 'correlation_id' request["X-AMEX-API-KEY"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"source\": \"Issuer\",\n \"type\": \"r42.v1.acquisition\",\n \"time\": \"2020-04-13T22:59:42.582326946Z\",\n \"data\": {\n \"code\": \"SUCCESS\"\n }\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.qa2s.americanexpress.com/loyalty/v1/event/notify") .header("Authorization", "Authorization") .header("correlation_id", "correlation_id") .header("X-AMEX-API-KEY", "") .header("Content-Type", "application/json") .body("{\n \"source\": \"Issuer\",\n \"type\": \"r42.v1.acquisition\",\n \"time\": \"2020-04-13T22:59:42.582326946Z\",\n \"data\": {\n \"code\": \"SUCCESS\"\n }\n}") .asString(); ``` ```php request('POST', 'https://api.qa2s.americanexpress.com/loyalty/v1/event/notify', [ 'body' => '{ "source": "Issuer", "type": "r42.v1.acquisition", "time": "2020-04-13T22:59:42.582326946Z", "data": { "code": "SUCCESS" } }', 'headers' => [ 'Authorization' => 'Authorization', 'Content-Type' => 'application/json', 'X-AMEX-API-KEY' => '', 'correlation_id' => 'correlation_id', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api.qa2s.americanexpress.com/loyalty/v1/event/notify"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", "Authorization"); request.AddHeader("correlation_id", "correlation_id"); request.AddHeader("X-AMEX-API-KEY", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"source\": \"Issuer\",\n \"type\": \"r42.v1.acquisition\",\n \"time\": \"2020-04-13T22:59:42.582326946Z\",\n \"data\": {\n \"code\": \"SUCCESS\"\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "Authorization", "correlation_id": "correlation_id", "X-AMEX-API-KEY": "", "Content-Type": "application/json" ] let parameters = [ "source": "Issuer", "type": "r42.v1.acquisition", "time": "2020-04-13T22:59:42.582326946Z", "data": ["code": "SUCCESS"] ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.qa2s.americanexpress.com/loyalty/v1/event/notify")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```