Trust the evidence. Recover the uncertainty.
Inbound verification, duplicate handling and durable processing form one outcome pipeline.
Verify before applying effects.
A provider event is untrusted input until verified for its specific connection. The approved contract determines whether verification uses a signature or an authenticated provider lookup. Match the bound account, order/reference, amount and asset before a success can affect records.
Event identity supports deduplication. Durable intake and downstream effects have distinct responsibilities. The integration acceptance plan must exercise repeated delivery, invalid verification, delayed delivery and processing interruption.
Recover with the same reference.
Re-query an uncertain provider request using its existing reference. Do not create another charge to discover whether the first succeeded. Define what happens when lookup is unavailable, returns pending or contradicts a prior result; unresolved evidence should remain visible for review.
Inbound provider event handling is not a promise of a public outbound developer webhook service. Delivery subscriptions, signing contracts and retry guarantees for a future developer product need their own reviewed specification.