The problem
A browser can lose a response after the server has already processed a check. Retrying blindly can create another provider request and another charge.
Our approach
The backend binds an operation ID to the request. Repeating the same operation returns the existing state or result. Reusing that ID with different input is rejected.
What we checked
Local verification covers idempotency, balance accounting and history. A restart check confirmed that operation history, simulated burns and the result-signing public key persisted in the configured local database.
The limit
These checks use a local simulated ledger. A public deployment still needs durable storage, recoverable workers and validation of the real funding and settlement flow.
Local idempotency, billing and restart verification
Open the local verification recordEngineering record from 28 September 2026. Simulated balances and wallets; no production settlement or independent security audit.