Unit 3 — at-least-once delivery, backoff, signatures, and dead letters
Webhooks & Reliable Delivery
When the charge from Unit 1 succeeds and the ledger entry from Unit 2 is posted, the merchant's own systems need to know — to ship the order, send a receipt, provision access. They are not polling your API millions of times a minute. You push them an event: a webhook.
The hard part is not sending the HTTP request. It is guaranteeing the event eventually arrives even when the merchant's endpoint is down, slow, or flaky — without melting their server or yours. This unit builds reliable, at-least-once webhook delivery with exponential backoff, signature verification, and a dead-letter queue.
