Skip to content
APIs & Webhooks

What is Idempotency Key?

A client-supplied unique key letting servers recognize retried requests and return the original result. Payment endpoints require one per checkout attempt so double-clicks and timeouts never charge twice.

Example

A Paddle checkout route stores the idempotency key with the order; when the client retries after a timeout, the server returns the stored order instead of creating a second charge.

What people get wrong

Generating a fresh key on every retry. The key must stay constant across retries of the same intent, or the server cannot match them.

Frequently asked questions

Where should the key live?

Clients generate one UUID per user intent and send it as a header; servers store it beside the order and match retries exactly.

How long must keys persist?

At least as long as clients may retry — hours for checkouts, longer for background jobs. Expire them only after the retry window closes.

Sources

Browse all APIs & Webhooks terms →