Idempotency keys

Context#

Clients send Idempotency-Key (or similar) so retries do not double-charge. Bugs appear when keys are ignored on PATCH, shared across users, truncated, or cleared after a short TTL while the client still retries.

Theory#

Correct behavior: same key + same body → same effect; same key + different body → 409 or clear error. Many implementations skip the body hash.

Practice#

  • Replay the same POST with the same key and a changed amount in a sandbox; compare responses and backend state.

Tools#

  • curl with custom headers
  • Burp Suite

Cookie Consent

We use cookies to enhance your experience. Learn more