Leaderboard & Counting Service  ·  View 09 of 21  ·  Structure

Integration Surface

Four surfaces — count, read, configure, operate — and why the client write path is the narrowest.

Editable source SVG draw.io All views
Who calls in Product backend server-to-server Product client member token Tenant console Trust & safety console Leaderboard & Counting Service Counting API accept, dedup, log Query API top-N, rank, percentile Config API versioned definitions Operations API freeze, retract, rebuild What it depends on and feeds Identity Platform member tokens Member directory display names Notification service Reward service Analytics warehouse events:batch events (signed) counters retract, freeze verify resolve rank changes standings export Leaderboard & Counting Service — Integration Surface Application we own Interface / broker Security / platform synchronous event / async batch Four surfaces, deliberately separate: counting, reading, configuring and operating. The client write path is narrower than the backend path by design — it can only write counters declared client-writable. Workload identity authorises every service-to-service call and is omitted here for clarity. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • Counting, reading, configuration and operations are four separate surfaces with four different authorisation models. A single API with a mode flag would make "who may retract" a code review question.
  • The client path can only write counters a tenant has declared client-writable, and only as the authenticated member. A trusted backend path exists precisely so that is not a limitation.
  • Display names are resolved outbound, at read time, from the member directory — so the platform never becomes a second source of identity.

Contracts

  • Batch of up to 500 events per call with per-event acceptance, so one bad event does not fail the batch.
  • Conditional reads, so a polling client transfers nothing while the projection version has not advanced.
  • Rank-change events are emitted asynchronously; standings and the log export leave as batch.

Deliberately omitted

  • Workload identity on every service-to-service call, which would add an edge to every node here.
  • A public read API for third parties — named and deferred.