Ask before you resend
The payment may have gone through. Find out before you send anything that could charge the customer a second time.
Your answers so far
- What came back from the payment?
- Nothing. The request timed out or the connection dropped. Change
Choose one
What to build
Look the payment up by the idempotency key you sent with it. If a transaction comes back, that's your answer. If none does, resend the original request with the same key: the platform runs it once however many times it arrives.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- This only works if every create carries a key. Choose one per logical payment, store it before you send, and keep it for every attempt at that payment.
- Choose your own client timeout, and run the slow-processor scenario in the sandbox so the timeout path is code you've exercised.