The first call does not need Idempotency-Key. Creating a contact is POST with display_name. Not duplicating a person is POST /contacts/upsert by email/phone. The header exists only when the client retries the same write after a timeout or 500 — the host returns the first response instead of creating another row.
Accepted on POST of contacts, companies, deals, tasks, webhooks, tags and upsert. Replay by organization + method + path + key string, 24 hours, with X-Idempotent-Replayed: true. It does not hash the body.
| You send | Result |
|---|---|
| Same key + same body | Original status and body. No second row. |
| Same key + different body | Still the first response. Treat as a client bug. |
| New key | New write. |