Take webhooks, and reconcile each window on a schedule
The stream carries the payments, and a scheduled query proves the window is complete instead of assuming it.
Your answers so far
Choose one
What to build
Subscribe to the transaction events and load each one as it arrives, then run a filtered query over the closed window on your reporting cadence and insert anything the stream didn't deliver. At this volume the stream is what makes the load affordable, and the sweep is what makes it trustworthy: a receiver that was down for an hour loses that hour, and only a query notices.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Delivery is at least once. Record the event id you have already handled and ignore a repeat, because a retry after a slow acknowledgement is an ordinary event rather than a fault.
- Acknowledge within five seconds. Put the raw body on a queue and process it after you have answered, because slow handling is retried and a retry is a duplicate you then have to discard.
- Sweep a window that has already closed, and overlap it slightly with the one before. A sweep that reaches into the current window keeps finding payments that were about to arrive anyway.
- Make the load idempotent on the payment id. The sweep and the stream will hand you the same payment, which is the design working rather than failing.