Our services
If you can think it, we can make it brainsoft.
If you can think it, we can make it brainsoft.
Written By: BrainSoft In Backend
You've built an integration that sends orders to a fulfillment service. One day the network hiccups, the request times out, and your code retries. Now the customer gets two shipments. Retries are necessary for reliability, but without idempotency they can cause chaos. The fix is to make every operation safe to repeat.
Idempotency means that performing the same operation multiple times has the same effect as doing it once. To make your integration idempotent, you attach a unique key to each request, check if that key was already processed, and ensure your side effects are atomic. This post walks through the steps to implement that reliably.
When you send a request and don't get a response, you don't know if the server processed it. The request might have failed before reaching the server, or the server might have completed the work but the response got lost. If you retry, you risk duplicating the action. This is especially dangerous for operations that create resources, charge payments, or send notifications.
The solution is to give each logical operation a unique identifier—an idempotency key—and have the server use that key to detect and ignore duplicates. The client generates the key once and reuses it for all retries of the same operation.
import uuid
idempotency_key = str(uuid.uuid4())
INSERT INTO idempotency_keys (key, status) VALUES ('...', 'pending');
Idempotency-Key or in the request body. The server must use it to deduplicate.
headers = {'Idempotency-Key': idempotency_key}
response = requests.post(url, json=payload, headers=headers)
if response.ok:
UPDATE idempotency_keys SET status = 'completed' WHERE key = '...';
SELECT status, result FROM idempotency_keys WHERE key = '...';
CREATE TABLE idempotency (key TEXT PRIMARY KEY, response JSONB);
DELETE FROM idempotency_keys WHERE created_at < NOW() - INTERVAL '24 hours';
curl or your test suite to simulate retries.
curl -X POST -H "Idempotency-Key: abc123" ...
Even with idempotency keys, things can go wrong. Here are a few traps:
If you're building integrations that must be reliable, consider working with a team that has done it before. At BrainSoft, we help clients design and implement idempotent integrations as part of our services.
An idempotency key is a unique value that a client generates and sends with a request. The server uses it to recognize repeated attempts of the same operation and ensures the operation is executed only once.
It depends on your retry window. A common practice is to keep keys for 24 hours. After that, the likelihood of a duplicate request is low, and you can safely delete them to save space.
If the server doesn't support idempotency keys, you can implement deduplication on your side by checking if the operation was already performed. For example, before creating a resource, query the server to see if it already exists. Alternatively, use a middleware that caches responses.