Checkout v2: Idempotent payment webhooks
Goal
Stop double-charging customers when the payment provider retries a webhook. Every payment.succeeded event must be processed exactly once.
Steps
- 1.Add a processed_events table keyed by provider_event_id with a unique index.
- 2.Wrap the handler in a transaction: insert the event id first, then mark the order as paid.
- 3.Return 200 immediately when the event id already exists.
Open questions
Do we keep processed_events forever or expire rows after 90 days?







