What makes idempotency in commerce apis dependable?
Dependability comes from explicit record authority, safe delivery semantics, bounded recovery, and reconciliation—not from the number of endpoints. For safe retries for orders, payments, inventory, and fulfillment actions, the design must explain what happens after duplicates, delay, partial failure, and an ambiguous timeout. Repeated delivery must not repeat the business effect.
Should this use a request, webhook, queue, or batch?
Use a request when the caller needs an immediate decision, a webhook when a source announces change, a queue when work needs isolation and retry, and a batch or reconciliation job when completeness matters more than immediacy. Many durable integrations use more than one pattern.
What should be tested beyond the happy path?
Test invalid and missing data, stale versions, duplicate events, reordering, throttling, permission changes, timeout after remote commit, and replay. The route risk—duplicating irreversible actions during timeout recovery—needs a concrete test rather than a sentence in a brief. A timeout after remote commit makes blind retry especially dangerous for orders, payments, and inventory.
What evidence belongs at handoff?
Provide payload examples, mapping rules, state diagrams, failure categories, dashboards, alert ownership, replay instructions, and a reconciliation report. Run the same request concurrently and after an injected timeout; confirm one effect.