Idempotency-Key in practice: retrying POSTs safely, deduping concurrent requests, and documenting it in OpenAPI
A network timeout never tells the client whether the charge happened. Retrying a plain POST double-creates; an Idempotency-Key header turns the retry into a replay. Here is the header contract, the in-flight 409 versus the stored response, key lifetime and scope, and the OpenAPI that makes SDKs...