Principles
Idempotency
Idempotency is implemented with the x-idempotency-key header, carried on both directions of
the external API.
Calls into LightCMS (Provided API)
x-idempotency-key is optional and accepted on the card lifecycle endpoints and on the token read endpoints.
On the ingest endpoints (cardCreateResponse,
holdEventResponse, subjectUpdate, accountUpdate), it acts as a deduplication key: resending the same key is a no-op that still returns 2xx. If it's omitted, no deduplication happens.
Calls out of LightCMS (Required API)
x-idempotency-key is always sent and required on every call LightCMS makes to the external system. It
is derived per message in the form D-<uuid>.<n>. The external system must treat repeated keys as the same logical request. On retryable failures, LightCMS retries the same key: POST endpoints get 1 initial attempt + 4 retries (1 s apart, 10 s timeout); GET endpoints get 1 initial attempt + 3 retries (1 s apart, 10 s timeout). If the last attempt fails, the message is dead-lettered.
400, 401, 403 and 404 responses are not retried — the message is dead-lettered at once.
Tracing
Tracing information is carried by the X-Dobito-TraceId header. Both directions also support
the generic traceparent W3C trace context header, propagated end to end wherever it's present
on the originating message.
X-Dobito-TraceId carries the LightCMS trace id — 32 lowercase hex characters, the trace-id
field of W3C traceparent (e.g. 6aa320f79fb62abf913622d14b42fc6a). It identifies an
operation and is shared by every message of it. It is not a pairing key: requests and
their asynchronous results are matched by the identifiers in the body (e.g. card.cardId,
authcoreHoldId / externalHoldId).
Calls into LightCMS (Provided API)
X-Dobito-TraceId is optional and can be sent on any endpoint. When you report the outcome of
an asynchronous request via POST /v3/cards/cardCreateResponse / POST /v3/holdEventResponse, echo the
X-Dobito-TraceId of the originating POST /v3/cardCreateRequest / POST /v3/holdEventRequest request, so the
result continues the original trace. On error responses that follow the Problem Details
contract, the response body includes a traceId field (alongside tenant) to help diagnose
the failing request.
Calls out of LightCMS (Required API)
X-Dobito-TraceId is sent on every call LightCMS makes to the external system whenever the
originating message carries trace context. It is never sent as an empty header.