Home/Labs/Idempotency & Status Codes
All 280 Labs
INTERACTIVE LAB🔁

HTTP Methods & Status Codes Lab (Interactive)

Lose the first response, retry the request, and count duplicate charges across GET, POST, PUT, and DELETE. Model safe vs idempotent method semantics, Idempotency-Key deduplication on POST, and 401 vs 403 vs 201 vs 204 status behavior.

HTTP Methods, Retries & Status Codes Lab

The first response is lost in the network — replay the request and watch which methods duplicate side effects.

POST: Unsafe and non-idempotent: N executions create N resources unless deduplicated. Not safe. Not idempotent.

Resources created
4
Duplicate charges
3
Safe to auto-retry?
NO
201 attempt #1 — INSERT INTO orders → duplicate #1⚠ response lost → client timed out and retried
201 attempt #2 — INSERT INTO orders → duplicate #2
201 attempt #3 — INSERT INTO orders → duplicate #3
201 attempt #4 — INSERT INTO orders → duplicate #4

201 Created with Location: /orders/{id} is the correct POST success code.

A real client hitting these failures would also honour Retry-After on 429/503 before backing off.

How It Works Under the Hood

Distributed systems fail in the gray zone: a request is processed but its response is lost, so the client retries. GET is safe and idempotent; PUT and DELETE change state but converge — replaying them is harmless. POST creates a new resource every time, so two timeouts mean three orders and three charges unless the client sends an Idempotency-Key that lets the server recognize the replay and return the cached 201. Status codes encode the retry decision: 401 means authenticate, 403 means never retry, 429 and 503 demand honoring Retry-After, and 502/504 tell load balancers and circuit breakers when to trip.

Core Architectural Principles

  • Idempotent methods (GET, PUT, DELETE) are safe to auto-retry after a network timeout; POST is not.
  • Idempotency-Key header (often stored in Redis) deduplicates POST retries into one side effect.
  • 401 = missing/invalid credentials; 403 = authenticated but unauthorized; 201 returns Location for new resources.
Interview Round Script

When designing payments or any write path, volunteer the idempotency story: "POSTs carry a client-generated Idempotency-Key; the server caches the first response in Redis and replays it on retry, so network timeouts never double-charge." Then nail the 401 vs 403 distinction — both are classic senior-round probes.

Key Trade-Offs

Automatic retries heal transient failures but multiply side effects on non-idempotent operations unless deduplication keys are designed in.

Related Curriculum Chapter

HTTP Methods, Status Codes, & Headers

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs