Webhooks & events
Delivery and inbound event contracts, retries, and idempotency - not API-key hygiene alone.
Event order vs ledger posting
Out-of-order DLR and MO events must not break prepaid debit posting rules — arrival sequence is not money law.
Webhook consumer ops at volume
Queues, backoff, and DLQ ownership when webhook event rate leaves the pilot — one consumer rhythm product and finance can open without hero threads.
Duplicate webhook must not create a second debit
Fail path: retries and replays stay idempotent on prepaid money and inbox — one event ID, one debit row, one inbox line.
Signature and replay-window gate
Prod gate: verify signature and bound the replay window before any webhook becomes money or status truth — unsigned or stale events stay fail-closed.
Webhook contract before the first send
Buyer path: agree signed URL, event types, and idempotency key before the first prepaid send — contract first, paid traffic later.