Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When a state-changing API request times out, the server may have completed it even though the response never reached the client. Retrying with a new request can create a duplicate. An idempotency key lets the server recognize repeated submissions of the same logical action and apply the API’s documented replay behavior instead.

What an idempotency key does

An idempotency key is a stable identifier for one intended operation, such as creating a payment or order. The client sends that identifier with the request; if it must retry the same operation, it sends the same key. The server can then recognize the retry and return or otherwise honor the original outcome. Stripe describes its feature as a way to retry safely without accidentally performing the same operation twice: Stripe’s idempotent requests documentation.

The key does not guarantee that every API behaves the same way, nor does it make unrelated requests safe to repeat. It works only where the API supports idempotency and according to that API’s rules.

Implement the key from client to server

1. Choose the boundary of one logical operation

Create one key for one intended action, not for every HTTP attempt. Reuse it when retrying that action after a timeout or transient transport failure. Generate a fresh key for a genuinely new action—even if its payload happens to match the earlier one. This boundary is what distinguishes a retry from a second operation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Generate a unique, non-sensitive value

Use a random value with enough entropy to make collisions negligibly unlikely. Stripe recommends UUID v4 or another random string and warns against putting sensitive information such as an email address or personal identifier in the key. Stripe documents a maximum key length of 255 characters; that limit is Stripe-specific, not a general standard. See Stripe’s key guidance.

3. Send the API’s documented key field

There is no universal header name or guarantee that every endpoint accepts a key. Stripe documents the Idempotency-Key header for its POST requests. Checkout.com documents Cko-Idempotency-Key for its /payments endpoint in its article dated June 05, 2026: Checkout.com: Prevent duplicate payment requests. Confirm the syntax and supported operation in the API documentation you are integrating; do not assume one provider’s behavior applies to another.

4. Bind the key to the request

Store enough context with the key to detect accidental reuse for a different endpoint or payload. Stripe compares incoming parameters with those from the original request and errors when they differ, to prevent accidental misuse (Stripe API reference; see also Stripe’s idempotency documentation). In a service you control, define which request properties make up the comparison or fingerprint, and decide how serialization and semantically equivalent values are handled. Those details are design choices; the provider examples do not prescribe a universal fingerprint format.

5. Prevent simultaneous requests from both executing

Sequential retries are not the only risk: two copies of a request can arrive at nearly the same time. Make claiming a key and beginning the side effect atomic, or use another coordination mechanism that prevents both requests from passing a check-then-act gap. Define what the second request receives while the first is being processed. Stripe documents that a concurrent conflict is not stored as an idempotent result and can be retried, demonstrating why concurrency behavior needs an explicit contract (Stripe API reference).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Persist the result and define replay behavior

Decide when execution has begun, what response is retained, how clients identify work still in progress, and which failures are saved. Stripe stores the first resulting status code and body after endpoint execution begins; later requests using the same key return that result, including a 500 error (Stripe API reference). That is Stripe’s policy, not a rule that every API should cache every error. Specify your own contract clearly so clients know whether a retry will replay a result, wait, or be eligible to execute.

7. Set and communicate a retention window

Keys cannot necessarily be relied on forever. Stripe says it may remove keys once they are at least 24 hours old; if a key is reused after pruning, Stripe treats the request as new (Stripe API reference). This is a provider-specific policy, not a standard duration. For an API you operate, choose retention to fit the realistic retry horizon and the consequences of repeating the operation, and document what happens after expiry.

Rank #4
ziyue 2 Pack Hook Security Magnetic Tool Key for Wall (2Pack)
  • 【Premium Material】High-quality magnet material in black ABS house, durable and never rusts.
  • 【Easy to Install】Super easy to install, no drill needed.
  • 【Wide Application】You could use them to display your items, and press the paper on the whiteboard, keep two doors closed, and little gadget to attract wrenches, keys, etc.
  • 【Package Item】There are 3 combinations for you, 1 set, 2 set, 4 set, just choose according to your need.
  • 【Satisfaction Guarantee】Your satisfaction is our top aim, if encounter any problems, please feel free to contact us.

8. Retry according to the API’s rules

Do not treat every error as permission to send the request again. Stripe says validation failures and some conflicts that occur before endpoint execution begins are not saved as idempotent results and can be retried. For other errors, follow the specific API’s retry guidance and the result-retention behavior it documents (Stripe API reference).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How provider behavior differs

The documented examples establish different header names and an endpoint-specific scope, but they do not establish identical behavior across providers. Check each API’s contract before relying on a key.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Provider and documented scope Key syntax Behavior established by the cited documentation
Stripe API Idempotency-Key header; maximum 255 characters Compares request parameters; documents replay of the first status and body after execution begins, including a 500; concurrent conflicts and pre-execution validation failures are not saved as results; keys may be pruned when at least 24 hours old. Source
Checkout.com /payments endpoint Cko-Idempotency-Key header The support article says the payments endpoint supports idempotency to prevent duplicate payment requests. The cited article does not establish the key length limit, mismatch behavior, concurrency handling, replayed outcomes, or retention window. Source

For any provider, verify supported methods and operations, key scope, payload-mismatch handling, concurrent-request behavior, stored outcomes, expiry, and retry guidance. The Checkout.com article confirms support for the named endpoint and header; it should not be read as evidence that its other rules match Stripe’s.

Checklist for an API you operate

  • Define what counts as one logical action and when a client must reuse or replace its key.
  • Specify key format, entropy expectations, length, scope, and treatment of sensitive values.
  • Bind keys to an endpoint and request identity, with a documented mismatch response.
  • Make key claiming and side-effect initiation safe under concurrent submissions.
  • Define in-progress responses, which outcomes are retained, and what a retry receives.
  • Document retention and what happens after a key expires or is pruned.
  • Publish retry rules that distinguish failures before execution from outcomes that may already have occurred.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.