architecture · 4 min read · 4 days ago

How we solved Stripe webhook replay attacks and double-billing in distributed Astro/Node workers

A deep look at distributed lock leases, PostgreSQL advisory locks, and event deduplication tables for bulletproof SaaS billing.

When processing thousands of Stripe webhook events (`invoice.payment_succeeded`, `customer.subscription.updated`), network jitter and retry policies will deliver duplicate payloads concurrently. ### Idempotency Pattern 1. Extract `event.id` from Stripe payload. 2. Insert into PostgreSQL `webhook_events` table with `ON CONFLICT (id) DO NOTHING`. 3. Acquire transactional advisory lock before adjusting subscription quotas or unlocking escrow. This eliminated 100% of race condition support tickets across our platform.
#Stripe #PostgreSQL #Idempotency #Node.js

Discussion (0)

Public peer review & architectural Q&A

No comments yet. Start the architectural discussion below.