NOTE / SECPRIVA

Why retries create duplicate records (and how to fix idempotency)

A retry is not a new business event. It is another attempt to deliver the original event.

Networks fail, workers time out, and providers retry requests. The dangerous assumption is that every delivery should be processed as new. If the first attempt committed the record but the response was lost, the retry can create a duplicate.

const key = request.headers.get("Idempotency-Key");
if (await alreadyProcessed(key)) return response.json({ ok: true });
await processOnce(key, payload);

The key should come from the source event when possible, not from the receiving request timestamp. Verification should replay the same event, force a timeout, and confirm that the destination still contains one record.

NEXT STEP

Bring us the part that is not working.

Start a conversation