Networks fail, workers time out, and providers retry requests. The dangerous assumption is that every delivery should be processed as new. If the first attempt committed the record but the response was lost, the retry can create a duplicate.
const key = request.headers.get("Idempotency-Key");
if (await alreadyProcessed(key)) return response.json({ ok: true });
await processOnce(key, payload);The key should come from the source event when possible, not from the receiving request timestamp. Verification should replay the same event, force a timeout, and confirm that the destination still contains one record.