Stress-test an idempotency key rule before key formats, TTL windows, and client retry guidance harden into what every mutating call will quote.
Idempotency rules fail when the TTL invents storage the cache never had, when keys dual-count the same request as new and as replay, when clients still retry without keys on money paths, and when ops cannot show who owns collision review after a partial outage. A neat RFC-style memo is not evidence.
What to put on the table
One sentence for why the rule exists, which endpoints and verbs it covers, who owns key storage and client SDK updates, and the rollback trigger if duplicate writes or collision rates past a named threshold. Attach the endpoint list, sample client code, storage design, and the measured path from first attempt to safe replay. If platform, payments, and client owners disagree on which calls are truly covered, stop and reconcile first.
Name the decision you will make if the stress test finds nothing new, and the delay criteria if any money path still lacks a named key owner or a verified replay test.
Pressure map
- TTL fiction: windows that look firm while storage still evicts under load.
- Key blur: formats that still say "client choice" without a named collision check.
- Client theater: SDKs that still retry money paths without keys.
- Ops lag: collision reviews that trail the duplicate charge customers already saw.
- Partial-write silence: failures that land without a replay owner or measured lag.
Optional finance seat if duplicate charges bind the form. Optional support seat if ticket volume will spike on day one.
How to run it
Feed Pingpong the draft rule, endpoint map, and open risk list. Early passes steelman the design. Later passes attack from platform, payments, client, ops, and skeptic seats. End with a pass that turns surviving objections into clearer owners, a timed chaos replay, or a hold. Delete invented "clients already send keys" claims and dual-counted success rates.
Ask platform and payments seats to price the behavior the published rule will invite. If day-one docs promise safe retries while the last dry run double-posted mid-market charges, buyers will treat the rule as false. Write the intended endpoints, the storage checks, and the language you will refuse, then attack whether trust still holds under that discipline.
When the rule coincides with a webhook change or a checkout rewrite, force eng and product seats to map every claim that still assumes the old retry paths. Partner docs, mobile SDKs, and internal workers count. A rule that looks clean in a PDF while a worker still posts without keys will fail on the first retry storm. Related: stress-test a webhook retry policy, stress-test a webhook contract, pretend you are the CTO, pretend you are the QA lead, and the war-game decisions hub. Process: how to run a Pingpong.