Rules
- Keys are stored per organization and Developer API key for 24 hours.
- The stored record covers the method, the route, and the request body.
- Reusing a key with the same method, route, and body returns the original response.
- Reusing a key with a different method, route, or body returns
409 idempotency_key_reused. - Sending the key again while the first request is still running returns
409 idempotency_request_in_progress. Retry the same request after a short wait. - Use deterministic keys for imports, approvals, and lifecycle actions.
- Do not use the same idempotency key across unrelated operations.
Routes that require a key
These writes return400 idempotency_key_required when the Idempotency-Key header
is missing or blank:
On other writes the key is optional but recommended.
Replays and rate limits
An exact replay does not spend rate-limit budget. The per-key limit is skipped only when all of these hold:- the request is a
POST,PUT,PATCH, orDELETEunder/api/v1; - a completed record exists for the same organization, API key, and idempotency key;
- the method, the concrete route, and the body match that record.
GET requests never skip the limit.