# Idempotency and concurrency

Consequential mutations expose an `Idempotency-Key` contract so a transport retry does not duplicate durable state or external consequence. Update and delete operations accept `If-Match` where the resource revision must be protected against concurrent mutation.

A timeout does not prove cancellation. After ambiguous transport failure, re-read the authoritative resource or operation state and reconcile using operation identifiers and Receipts. Client-side optimism can improve interaction, but it must never invent terminal business state.
