One matching economic effect is independently proven.
Exactly one external effect, linked to exactly one ledger posting, with matching authorization binding and passing receipt integrity.
Payment recovery · evidence & verdicts
A provider can prove its own request state. The hard part is proving one economic outcome across the provider, the external rail, the recipient, and the customer ledger — before an automated retry is permitted.
A method and a published sandbox result — not a payment processor, not a custody service, and not a claim of universal exactly-once execution.
The chain that must agree
A verdict is only as strong as the weakest independently observed link in this chain.
Was the request accepted?
Provable by the provider alone. This is the only link most systems can prove.
Did money actually move?
Must be observed independently, never inferred from acceptance.
Was the credit received?
Confirms the effect landed where the intent said it should.
Is it recorded exactly once?
One posting linked to one intent — or the books disagree with reality.
provider → external rail → recipient → customer ledger
Four verdicts
Every post-timeout state resolves into exactly one of four verdicts, and each verdict says clearly whether a retry is allowed.
One matching economic effect is independently proven.
Exactly one external effect, linked to exactly one ledger posting, with matching authorization binding and passing receipt integrity.
Zero external effects and a pre-effect rejection are proven.
The request was refused before any movement occurred and no ledger posting exists, so a new attempt cannot duplicate an effect.
The provider accepted, but the expected external effect is absent.
Acceptance is not finality. Until the effect is observed independently, the outcome is not established either way.
The effect may have happened or evidence disagrees, so blind retry remains blocked.
Sources conflict or observation is unavailable. The path stays closed to automation until reconciliation produces a single answer.
Public sandbox proof
A published sandbox run where 24 concurrent retry attempts contend for one payment intent.
24
retry attempts
1
durable reservation owner
23
stale or duplicate attempts rejected
1
external rail effect
1
linked customer-ledger posting
PASS
receipt integrity
Boundary of this result
These numbers prove only the declared sandbox boundary. They do not prove universal exactly-once execution, and they say nothing about any production system, provider, or rail outside that boundary.
Seven-question self-test
Any question you cannot answer with a confident yes is a place where an automated retry can create a second economic effect.
Downloads
Plain text and JSON, no form required.
Request the kit
Tell me which transition goes unknown in your workflow after a timeout. It shapes what gets published next.