How it works
Networks fail at awkward moments: a request times out, the app retries, and the first attempt had actually worked. With an idempotency key, the client sends a unique id with the request (Stripe uses an Idempotency-Key header); the server stores the result against that key and returns the same result for any repeat instead of acting again.
The same idea protects webhook handlers, since gateways retry deliveries and may send an event more than once: record each event or payment id, skip ones already processed, and back that with a unique constraint in the database so two copies arriving together cannot both win. In HTTP, GET, PUT and DELETE are meant to be idempotent; POST is not, unless you make it so.
Related terms
More in Payments
How it works