Idempotency Keys
Client-generated keys stored atomically with the operation they guard.
5 to work through
-
advanced
A card-issuing platform exposes an API where duplicate requests would move money twice. What is the complete idempotency contract, including the cases most implementations miss?
2 min answer -
advanced
A payment API supports idempotency keys. Duplicate charges still occur occasionally. The server implementation is correct. Where is the bug?
2 min answer -
advanced
A payment integration retries on timeout. Finance reports occasional double charges. The provider supports idempotency keys and they are being used. Diagnose.
2 min answer -
advanced
A payments API must guarantee that a network retry never charges a customer twice. Design the mechanism end to end.
2 min answer -
advanced
A payments flow in a mobility app creates duplicate charges when the mobile network drops the response and the client retries. Design the idempotency mechanism and identify where teams most often get it wrong.
2 min answer
3 terms in this topic
Idempotency Key
A client-generated identifier that lets a server recognise a retried request and return the original result instead of performing the action twice.
conceptIdempotency Scope
The boundary within which an idempotency key is unique and meaningful — per account, per endpoint, or global — and the retention window it lives for.
case-studyStripe: Idempotency Keys as a Public API Contract
Stripe made safe retry a documented, client-controlled property of its API, which is why network failures during payments do not produce duplicate charges.
Neighbouring topics
API & Integration
General material on integrating systems through contracts.
REST Design
Resources, uniform methods, status codes and statelessness.
GraphQL
Client-specified queries, N+1 resolution and query-cost control.
gRPC APIs
Contract-first RPC, generated clients and protobuf compatibility rules.
Webhooks
Push callbacks, signature verification, ordering and at-least-once delivery.
API Versioning
URL, header and account-pinned versioning, and who carries the burden.
Backward Compatibility
Which changes are safe, and how to make breakage a build failure.
Contract Testing
Verifying what consumers actually rely on, without a shared environment.
API Documentation
OpenAPI as a machine-checked contract rather than as prose.
Rate Limiting
Algorithms, shared counters, and signalling rejection properly.
Pagination & Filtering
Offset versus cursor, stable ordering and unbounded result sets.
API Error Handling
Error shapes, retryability signals and machine-readable causes.
Event-Driven Integration
Publishing facts rather than commands, and versioning event schemas.
Message Formats
JSON, Protobuf, Avro — schema evolution and payload economics.
Schema Registry
Enforcing compatibility on events the way CI enforces it on code.
Integration Patterns
Routers, translators, splitters, aggregators and dead letter channels.
Legacy Integration
Reaching systems that cannot change, without importing their model.
Partner & B2B Integration
External contracts, onboarding, sandboxes and long deprecation windows.
APIs as Products
Ownership, lifecycle, deprecation policy and developer experience.