freecoding.school100% FREE · NO SIGNUP
Gateway RidgeISSUE #4 of 35

idempotency keys · safe retries

Gateway GusVSTimeout Titan
Gateway Gus saysIdempotency keys make retried POSTs safe — the server dedupes by the key.

POSTs aren't idempotent, so a retried "create payment" could charge twice. The fix: the client sends a unique Idempotency-Key header; the server records it and, on a repeat with the same key, returns the original result instead of acting again. This is how payment APIs (Stripe) make retries safe. Generate a fresh key per logical operation.

Power-ups you unlock

Timeout Titan attacks — common mistakes

Boss battleExplain how an idempotency key prevents a double charge on retry.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>POST /charges
Idempotency-Key: req_8f3a
retry with same key → server returns the SAME charge
→ no double charge</pre></body></html>
▶ Open the interactive comic issue
‹ Retry-After · Backoff · IdempotencyCaching · Etag · Last-Modified ›