DEV Community

Axiru
Axiru

Posted on

What happens when an AI agent refund times out

A support agent has a live Stripe key. A customer wants a $240 refund. The agent calls refunds.create. The HTTP client times out after 30 seconds.

The agent does not know whether Stripe accepted the refund. Retry logic fires. Same charge, same amount. Stripe accepts both. The customer sees two credits. Finance sees $480 leave for a $240 problem.

This is a sample scenario, not a named customer story. The failure mode is common enough that teams building AI support agents should design for it on purpose.

Why the retry looks rational to the agent

From the agent's point of view, a timeout is an error. The obvious fix is try again. Stripe's API will happily create a second refund unless you built idempotency and duplicate detection yourself. Most prototype agent loops do not.

The same shape shows up in other places:

  • Refund after a dispute is already open
  • Payout to a payee the agent has never seen
  • Credit issued twice because the first confirmation was lost

What a policy gate actually returns

A policy gate sits between the agent and the rail. It does not hold money and it does not move money. It evaluates the request and returns one of three outcomes:

  1. allow — the agent may proceed to the rail
  2. hold — a human must decide
  3. deny — with a reason code

Every outcome should leave a receipt you can show later, ideally hash-chained so the log is tamper-evident.

For the timeout case, useful rules look like:

  • Same charge_id refunded or held in the last 24 hours → hold (DUPLICATE_REFUND_WINDOW)
  • Prior attempt still in flight → deny (PRIOR_ATTEMPT_IN_FLIGHT)
  • Amount over the agent's daily cap → hold for a reviewer

How to check your history without blocking live traffic

If you already have Stripe outflows, run a read-only shadow review of the last ~90 days. Connect Stripe sync or upload a CSV. You get a report of what would have been allowed, held, or denied. Nothing is blocked until you turn enforcement on.

Axiru is one implementation of that gate (Stripe, agent card payments, x402, USDC on Solana). The free shadow review is at https://axiru.com/start-free. Deeper Q&A lives at https://axiru.com/faq.

What this post is not claiming

No named customer. No "we saved $X." The dollar amounts above are sample figures so the sequence is easy to follow. If you have a real incident of your own, write that up with your own numbers. The industry needs more concrete postmortems and fewer slogans.

Top comments (0)