Why duplicates happen
Networks time out, and the safe response to a timeout is to try again. Payment providers resend webhook events until they are acknowledged. So the same event can arrive more than once, and the sender cannot know whether the first attempt landed.
How it is handled
Each event carries a unique ID. The receiving system records the IDs it has already processed and ignores repeats, doing the work and recording the ID together so a crash in between cannot half-apply it. Only the receiver can do this, because only it knows what it has already recorded.
How we build it
Every webhook router we build carries retries, idempotency and a failure digest that reaches a person. On Norpex, a marketplace we built and run, a Stripe event router sits behind one checkout across all vendors, with an escrow cron between sale and release. Business OS uses the same patterns across its 117 workflows.
When it still fails
Retries cover the common case; an event that keeps failing needs a person. That is what the failure digest is for — a stuck payment becomes a line someone reads, not money that quietly went missing.