Recover safely
Design for lost responses and interrupted connections before sending an economic instruction.
Lost acknowledgement#
Keep the selected account, original method/path/body and idempotency key. Restore current account access, then use the contract's authoritative lookup or exact-key replay. A new key can create a second instruction.
The proposed order API still needs an authoritative order-operation projection and lookup contract before this recovery path can be used for orders.
Same key, changed request#
A different body or selected account under the same key must not be treated as a matching retry. Reconcile the original operation. A new price, fee, destination or amount requires a separately reviewed instruction.
Cancellation racing a fill#
Read the order after cancellation acceptance. Preserve fills and their fees. Do not release funds based only on a pending cancellation or a disconnected stream. Final cancel/fill precedence is a contract question; do not invent a local rule.
Duplicate or missing stream events#
Deduplicate by stable identity and only apply contiguous updates to a compatible snapshot. On a gap, obtain authoritative state and re-establish the snapshot/update boundary. Reconnecting cannot be the only source of an order's outcome.
See the proposed book update.
Know when an unchanged retry cannot help#
Malformed amounts, unsupported assets, insufficient funds, changed terms and expired authority need correction or fresh acceptance. Transport retry guidance does not authorize broader access or a new movement.
Use the error code reference.