Any request can time out after the server has already acted. The client cannot tell that from a request that never arrived, and the only safe response to uncertainty is to retry — which, without help, charges the card twice.
Backend and product engineers designing software behavior.
Your approach: Use diagrams, tables or prose for customer contracts, state transitions and data ownership; include APIs only to the depth the question requests.
Idempotency Keys. Any request can time out after the server has already acted. The client cannot tell that from a request that never arrived, and the only safe response to uncertainty is to retry — which, without help, charges the card twice. Work from the scoping questions below. State assumptions for any unspecified load, guarantee or target, then trace your design end to end. Explain one difficult case and a credible alternative; the worked example is a reference, not a required implementation.
Resolve the scoping questions for Idempotency Keys. Separate stated behavior from assumptions, and identify what is outside your design.
Declare relevant volume, latency, freshness, quality or cost targets with units. Show calculations or an evaluation plan that can test them; unspecified targets are your assumptions, not hidden pass criteria.
Explain how your guarantees hold in a difficult case relevant to this subject. Address: What should a retry observe while the first request is still running? What happens after the effect commits but before a response is recorded?
Identify users, required behavior and exclusions. Answer: Which retried operation must have only one business effect? Who chooses the request identity and how long is it remembered?
Define the information owned by the system and the inputs, outputs and errors at its boundaries. Resolve: What if the same identity arrives with a different payload? What should a retry observe while the first request is still running?
Estimate the dominant workload and resource demand with units and explicit assumptions. For a learned system, also state how quality is measured and what data is available.
Draw or describe the responsibilities needed for Idempotency Keys. Trace a representative request, event or job from its input to a visible result; identify durable state owners.
Walk through a difficult case step by step, including detection and recovery. Consider: What happens after the effect commits but before a response is recorded?
Compare a credible alternative using your chosen workload and guarantees. Explain a remaining risk, a signal to watch and when you would change the design.