> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Update an existing profile due to the replacement of an instrument.

POST https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced
Content-Type: application/json

Based on the Instrument Replaced event due to loss of a Card, or any other reason from an event producer, this endpoint will update the profile with a new instrument and deactivate the previous instrument.

Reference: https://developer.americanexpress.ferndocs.com/utilities/network-loyalty/api-reference/update-an-existing-profile-due-to-the-replacement-of-an-instrument

## Authentication

- `X-AMEX-API-KEY` header (required) — Application API key issued during app registration.
- `Authorization` header (required) — HMAC (one-way TLS). A `MAC` authorization header signed with your client secret. See https://developer.americanexpress.com/documentation/api-security/hmac
- `Authorization` header (required) — HMAC over mutual TLS. Requires a client certificate in addition to the signed `MAC` authorization header.
- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://api.qa2s.americanexpress.com/loyalty` (Sandbox, default)
- `https://api.qa2s.americanexpress.com/loyalty/v1/network` (Sandbox, default)

## Request

### Headers

- `Authorization` (string, required) — The Authorization header for the authentication at APIGEE. The following should be in the format of this header:MAC id: The Partner's Client ID. The Client ID is generated during the Partner Onboarding and the App Registration.ts: A client-generated timestamp (Unix Epoch format in milli-seconds).nonce: A unique identifier string. The value of nonce must be unique for the each request.mac: The request mac is generated using the HMAC SHA256 algorithm. Use the Client Secret to generate a hash/signature. The Client ID and Client Secret is generated during the Partner Onboarding and App registration.e.g., MAC id="adc3af10-7bf6-4d8a-87ea-35519ff6e1ad",ts="1466548572491",nonce="be3bd46c-b052-4ae8-9f61-993635e5bc98",bodyhash="cRPVGQWU+89HNR0ASAJFjhKqDF9X0pApGYuC/NVQNEU=",mac="NqbqNO3vSBwk6EE7pBi11DzvgLCh50IPAICCIWgjxYA="
- `correlation_id` (string, required) — A unique identifier used to track the request. This is with the current debugging standard in mind to track the request end-to-end. This will be mainly passed by the originating server (if it's a Webapp) or empty in case of the direct browser/app calls.e.g., GUID.
- `sender` (string, required) — The sender contains the sender information.e.g., Issuer or Service Provider.
- `keyname` (string, required) — The value assigned to the key used to encrypt the payload. For HIPED operations, this value must start with 'MK'.e.g., AA3434342323.

### Body (application/json)

This endpoint expects a Replacement.

- `source` (enum, required) — To track from where this event was initiated.IssuerServicingWebMobileAlways use: Issuer.
  - Allowed values: `Issuer`, `Servicing`, `Web`, `Mobile`
- `type` (enum, required) — To define an event type.Always use: v1.instrument.instrumentReplaced.
  - Allowed values: `v1.instrument.instrumentReplaced`
- `time` (string, required) — The event initiation time in UTC.Always use: RFC3339 Nano format.e.g., 2020-04-13T22:59:42.582326946Z.
- `data` (Card_Replacement_Payload, required) — This object is required by Network Loyalty GNS. While the Card object is mandatory, the product\_info object is optional.
- `specversion` (enum, optional) — The Cloud event Specification version.NOTE: Always use 0.3.
  - Allowed values: `0.3`
- `id` (string, optional) — If populated, this should be the same as correlation\_id.

## Response

### 202

Acknowledged Request.

## Errors

### 400 Bad Request Error

Bad request.

- `error_code` (string, optional)
- `user_message` (string, optional) — An error occurred when processing your request.
- `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task.

### 403 Forbidden Error

Forbidden request.

- `error_code` (string, optional)
- `user_message` (string, optional) — An error occurred when processing your request.
- `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task.

### 404 Not Found Error

Not Found.

- `error_code` (string, optional)
- `user_message` (string, optional) — An error occurred when processing your request.
- `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task.

### 409 Conflict Error

Conflict: Business error.

- `error_code` (string, optional)
- `user_message` (string, optional) — An error occurred when processing your request.
- `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task.

### 500 Internal Server Error

Internal server error.

- `error_code` (string, optional)
- `user_message` (string, optional) — An error occurred when processing your request.
- `developer_message` (string, optional) — A named\_exception was thrown by service\_method when performing processing\_task.

## Types

### Card_Replacement_Payload

This object is required by Network Loyalty GNS. While the Card object is mandatory, the product\_info object is optional.

- `network_info` (Network_Info, required) — An object containing the GNS-related information.
- `reason_code` (enum, required) — The reason code of why an instrument was replaced.FRAUDLOSTSTOLENe.g., FRAUD.
  - Allowed values: `FRAUD`, `LOST`, `STOLEN`
- `previous_instrument` (CardReplacementPayloadPreviousInstrument, required)
- `new_instrument` (CardReplacementPayloadNewInstrument, required)

### Network_Info

An object containing the GNS-related information.

- `institution_id` (string, required) — A unique ID which recognizes the Issuer.e.g., Bank_1, Bank_2.
- `network_id` (string, optional) — A unique ID which identifies the Issuer Network and will be provided, if required.e.g., Express_Company.

### CardReplacementPayloadPreviousInstrument

- `instrument_id` (string, required) — A unique ID for an instrument that is internal to the Issuer.e.g., GUID.

### CardReplacementPayloadNewInstrument

- `instrument_id` (string, required) — A unique ID for an instrument that is internal to the Issuer.e.g., GUID.

## Examples

**Request**

```json
{
  "source": "Issuer",
  "type": "v1.instrument.instrumentReplaced",
  "time": "2020-04-13T22:59:42.582326946Z",
  "data": {
    "network_info": {
      "institution_id": "string"
    },
    "reason_code": "FRAUD",
    "previous_instrument": {
      "instrument_id": "GUID"
    },
    "new_instrument": {
      "instrument_id": "GUID"
    }
  }
}
```

**Response**

```json
{}
```

**SDK Code**

```python
import requests

url = "https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced"

payload = {
    "source": "Issuer",
    "type": "v1.instrument.instrumentReplaced",
    "time": "2020-04-13T22:59:42.582326946Z",
    "data": {
        "network_info": { "institution_id": "string" },
        "reason_code": "FRAUD",
        "previous_instrument": { "instrument_id": "GUID" },
        "new_instrument": { "instrument_id": "GUID" }
    }
}
headers = {
    "Authorization": "Authorization",
    "correlation_id": "correlation_id",
    "keyname": "keyname",
    "sender": "sender",
    "X-AMEX-API-KEY": "<apiKey>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Authorization',
    correlation_id: 'correlation_id',
    keyname: 'keyname',
    sender: 'sender',
    'X-AMEX-API-KEY': '<apiKey>',
    'Content-Type': 'application/json'
  },
  body: '{"source":"Issuer","type":"v1.instrument.instrumentReplaced","time":"2020-04-13T22:59:42.582326946Z","data":{"network_info":{"institution_id":"string"},"reason_code":"FRAUD","previous_instrument":{"instrument_id":"GUID"},"new_instrument":{"instrument_id":"GUID"}}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced"

	payload := strings.NewReader("{\n  \"source\": \"Issuer\",\n  \"type\": \"v1.instrument.instrumentReplaced\",\n  \"time\": \"2020-04-13T22:59:42.582326946Z\",\n  \"data\": {\n    \"network_info\": {\n      \"institution_id\": \"string\"\n    },\n    \"reason_code\": \"FRAUD\",\n    \"previous_instrument\": {\n      \"instrument_id\": \"GUID\"\n    },\n    \"new_instrument\": {\n      \"instrument_id\": \"GUID\"\n    }\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Authorization")
	req.Header.Add("correlation_id", "correlation_id")
	req.Header.Add("keyname", "keyname")
	req.Header.Add("sender", "sender")
	req.Header.Add("X-AMEX-API-KEY", "<apiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Authorization'
request["correlation_id"] = 'correlation_id'
request["keyname"] = 'keyname'
request["sender"] = 'sender'
request["X-AMEX-API-KEY"] = '<apiKey>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"source\": \"Issuer\",\n  \"type\": \"v1.instrument.instrumentReplaced\",\n  \"time\": \"2020-04-13T22:59:42.582326946Z\",\n  \"data\": {\n    \"network_info\": {\n      \"institution_id\": \"string\"\n    },\n    \"reason_code\": \"FRAUD\",\n    \"previous_instrument\": {\n      \"instrument_id\": \"GUID\"\n    },\n    \"new_instrument\": {\n      \"instrument_id\": \"GUID\"\n    }\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced")
  .header("Authorization", "Authorization")
  .header("correlation_id", "correlation_id")
  .header("keyname", "keyname")
  .header("sender", "sender")
  .header("X-AMEX-API-KEY", "<apiKey>")
  .header("Content-Type", "application/json")
  .body("{\n  \"source\": \"Issuer\",\n  \"type\": \"v1.instrument.instrumentReplaced\",\n  \"time\": \"2020-04-13T22:59:42.582326946Z\",\n  \"data\": {\n    \"network_info\": {\n      \"institution_id\": \"string\"\n    },\n    \"reason_code\": \"FRAUD\",\n    \"previous_instrument\": {\n      \"instrument_id\": \"GUID\"\n    },\n    \"new_instrument\": {\n      \"instrument_id\": \"GUID\"\n    }\n  }\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced', [
  'body' => '{
  "source": "Issuer",
  "type": "v1.instrument.instrumentReplaced",
  "time": "2020-04-13T22:59:42.582326946Z",
  "data": {
    "network_info": {
      "institution_id": "string"
    },
    "reason_code": "FRAUD",
    "previous_instrument": {
      "instrument_id": "GUID"
    },
    "new_instrument": {
      "instrument_id": "GUID"
    }
  }
}',
  'headers' => [
    'Authorization' => 'Authorization',
    'Content-Type' => 'application/json',
    'X-AMEX-API-KEY' => '<apiKey>',
    'correlation_id' => 'correlation_id',
    'keyname' => 'keyname',
    'sender' => 'sender',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Authorization");
request.AddHeader("correlation_id", "correlation_id");
request.AddHeader("keyname", "keyname");
request.AddHeader("sender", "sender");
request.AddHeader("X-AMEX-API-KEY", "<apiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"source\": \"Issuer\",\n  \"type\": \"v1.instrument.instrumentReplaced\",\n  \"time\": \"2020-04-13T22:59:42.582326946Z\",\n  \"data\": {\n    \"network_info\": {\n      \"institution_id\": \"string\"\n    },\n    \"reason_code\": \"FRAUD\",\n    \"previous_instrument\": {\n      \"instrument_id\": \"GUID\"\n    },\n    \"new_instrument\": {\n      \"instrument_id\": \"GUID\"\n    }\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Authorization",
  "correlation_id": "correlation_id",
  "keyname": "keyname",
  "sender": "sender",
  "X-AMEX-API-KEY": "<apiKey>",
  "Content-Type": "application/json"
]
let parameters = [
  "source": "Issuer",
  "type": "v1.instrument.instrumentReplaced",
  "time": "2020-04-13T22:59:42.582326946Z",
  "data": [
    "network_info": ["institution_id": "string"],
    "reason_code": "FRAUD",
    "previous_instrument": ["instrument_id": "GUID"],
    "new_instrument": ["instrument_id": "GUID"]
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.qa2s.americanexpress.com/loyalty/v1/instrument-replaced")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```