architecture · 4 min read · 4 days ago
How we solved Stripe webhook replay attacks and double-billing in distributed Astro/Node workers
M
Marcos Bolaños @marcosb
Founder of InvoiceBot
✓ $4.2k MRR
⚡ 68
A deep look at distributed lock leases, PostgreSQL advisory locks, and event deduplication tables for bulletproof SaaS billing.
When processing thousands of Stripe webhook events (`invoice.payment_succeeded`, `customer.subscription.updated`), network jitter and retry policies will deliver duplicate payloads concurrently.
### Idempotency Pattern
1. Extract `event.id` from Stripe payload.
2. Insert into PostgreSQL `webhook_events` table with `ON CONFLICT (id) DO NOTHING`.
3. Acquire transactional advisory lock before adjusting subscription quotas or unlocking escrow.
This eliminated 100% of race condition support tickets across our platform.
#Stripe
#PostgreSQL
#Idempotency
#Node.js