Unit 1 — exactly-once charges under retries and concurrency
PaymentIntent & Idempotency
A customer taps Pay on a checkout page. The phone is on hotel Wi-Fi, the request times out, and the app does what every well-behaved client does: it retries. Behind the scenes that single tap can become three identical POST /charge calls hitting your API within a few hundred milliseconds. If your payment service is naive, the customer is now charged three times for one coffee — and you have a support ticket, a chargeback, and a trust problem.
This unit builds the primitive that makes that impossible: a PaymentIntent with an idempotency key, the contract that lets a client retry freely while the money moves exactly once.
