Skip to navigation

Update an existing profile due to the replacement of an instrument.

Based on the Instrument Replaced event due to loss of a Card, or any other reason from an event producer, this endpoint will update the profile with a new instrument and deactivate the previous instrument.

Authentication

X-AMEX-API-KEYstring
Application API key issued during app registration.
OR
Authorizationstring

HMAC (one-way TLS). A MAC authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac

OR
Authorizationstring

HMAC over mutual TLS. Requires a client certificate in addition to the signed MAC authorization header.

OR
AuthorizationBearer

OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as Authorization: Bearer <token>.

Headers

AuthorizationstringRequired

The Authorization header for the authentication at APIGEE. The following should be in the format of this header:

  • MAC id: The Partner's Client ID. The Client ID is generated during the Partner Onboarding and the App Registration.
  • ts: A client-generated timestamp (Unix Epoch format in milli-seconds).
  • nonce: A unique identifier string. The value of nonce must be unique for the each request.
  • mac: The request mac is generated using the HMAC SHA256 algorithm. Use the Client Secret to generate a hash/signature. The Client ID and Client Secret is generated during the Partner Onboarding and App registration.

e.g., MAC id="adc3af10-7bf6-4d8a-87ea-35519ff6e1ad",ts="1466548572491",nonce="be3bd46c-b052-4ae8-9f61-993635e5bc98",bodyhash="cRPVGQWU+89HNR0ASAJFjhKqDF9X0pApGYuC/NVQNEU=",mac="NqbqNO3vSBwk6EE7pBi11DzvgLCh50IPAICCIWgjxYA="

correlation_idstringRequired

A unique identifier used to track the request. This is with the current debugging standard in mind to track the request end-to-end. This will be mainly passed by the originating server (if it's a Webapp) or empty in case of the direct browser/app calls.

e.g., GUID.

senderstringRequired

The sender contains the sender information.

e.g., Issuer or Service Provider.

keynamestringRequired

The value assigned to the key used to encrypt the payload. For HIPED operations, this value must start with 'MK'.

e.g., AA3434342323.

Request

This endpoint expects an object.
sourceenumRequired

To track from where this event was initiated.

  • Issuer
  • Servicing
  • Web
  • Mobile

Always use: Issuer.

Allowed values:
typeenumRequired

To define an event type.

Always use: v1.instrument.instrumentReplaced.

Allowed values:
timestringRequired

The event initiation time in UTC.

Always use: RFC3339 Nano format.

e.g., 2020-04-13T22:59:42.582326946Z.

dataobjectRequired

This object is required by Network Loyalty GNS. While the Card object is mandatory, the product_info object is optional.

specversionenumOptional

The Cloud event Specification version.

NOTE: Always use 0.3.

Allowed values:
idstringOptional

If populated, this should be the same as correlation_id.

Response

Acknowledged Request.

Errors

400
Bad Request Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
500
Internal Server Error