American Express · Authentication Profile
American Express Authentication
Authentication
American Express developer APIs are onboarding-gated and secured with a layered scheme: mutual TLS (two-way client-certificate authentication), request-level HMAC message authentication (MAC) signatures, and OAuth 2.0 bearer tokens for authorization. No public OpenAPI is published, so this profile is captured from the Amex for Developers API Security documentation rather than derived from a machine-readable spec.
American Express secures its APIs with mutualTLS, http, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
Credit CardsFinancial ServicesPaymentsCard NetworkTokenizationFraud PreventionOpen BankingRewardsUnited StatesFortune 100
Methods: mutualTLS, http, oauth2
Schemes: 3
OAuth flows: clientCredentials
API key in:
Security Schemes
mutualTLS mutualTLS
hmac http
oauth2 oauth2