Stripe
Global financial infrastructure processing hundreds of billions
Stripe Architecture Blueprint
Click ▶ RUN to animate active particle streams across microservices
How Traffic Flows Through Stripe
1. Ingress & Edge Routing
User requests arrive at the edge network. Global CDNs cache static assets and media. API Gateways terminate TLS, validate JWT authentication tokens, enforce token-bucket rate limits, and scrub malicious bot traffic before forwarding to internal services.
2. Microservice Processing
Stateless domain services execute core business logic. Microservices communicate via high-performance internal gRPC/REST APIs and autoscaling worker pods, ensuring that high load on one domain never exhausts compute resources of another.
3. In-Memory Caching & Storage
Read-heavy traffic is served from in-memory Redis clusters with sub-millisecond latencies, protecting primary databases. Persistent databases (PostgreSQL, Cassandra, DynamoDB) maintain ACID consistency for financial ledgers, user accounts, and immutable state records.
4. Asynchronous Event Streams
Heavy operations (notifications, audit logging, analytics, ML training, fan-out delivery) are decoupled into durable event logs like Kafka and SQS. This prevents user-facing requests from blocking on slow external networks.
Study Stripe's database schemas, capacity math & production contracts
Beyond the visual blueprint, explore the exhaustive 7-section engineering whitepaper with real DDL schemas, API endpoints, failure mitigation matrices, and 45-minute FAANG interview scripts.
Zero Double-Charges & Distributed Financial Idempotency
In distributed internet payments, network connections drop, merchant servers timeout, and users click "Pay" multiple times. Charging a customer twice causes catastrophic fraud, customer fury, and merchant chargeback penalties.
Stripe requires client-generated idempotency keys on all mutating operations. The API gateway locks the key in an in-memory Redis cluster. If a retry arrives while processing, it waits; if it arrives after completion, Stripe immediately returns the cached original response without contacting the bank network.
⚖️ Architectural Trade-Offs & Decisions
Why the engineering team chose this specific stack over competing alternatives
Simple balance columns can be corrupted by race conditions, silent network partitions, or software bugs. In double-entry accounting, money cannot move without offsetting debit and credit journal entries. The sum of all accounts must balance to zero, providing automated mathematical proof of ledger integrity.
Card authorizations, 3D-Secure biometric challenges, and bank transfers can take seconds to hours to settle. Holding open HTTP connections is impossible across millions of merchants. Webhooks decouple processing and guarantee event delivery with exponential retry policies.
The Webhook Thundering Herd Retry Storm
A major e-commerce platform's servers crashed, returning 500 errors to Stripe webhooks. Stripe's automated retry engine began retrying millions of webhook events at identical fixed intervals, accidentally creating a self-inflicted DDoS on internal message queues.
Exponential backoff algorithms lacked randomized jitter (noise), causing millions of retried webhook requests to synchronize into periodic high-volume spikes.
Stripe introduced "Full Jitter" to all exponential backoff retry algorithms, ensuring retry attempts are spread uniformly across time windows, and implemented per-merchant fair-share rate limiters.
📋 Complete Microservice Specifications
Every service in the Stripe ecosystem with production tech stacks and failure impact
| Component | Tier / Layer | Tech Stack | Production Function | Status / Chaos |
|---|---|---|---|---|
| Customer | CLIENT | Stripe.jsElements | Consumer entering payment credentials on web checkout | |
| Merchant Server | CLIENT | RubyPythonNodeGo | E-commerce merchant backend initiating charges via Stripe API | |
| API Gateway | GATEWAY | EnvoyGoRate Limiter | API gateway handling TLS termination, API key verification, and rate limiting | |
| Payment Service | SERVICE | GoRubySaga | Core orchestration engine coordinating fraud checks, card networks, and ledger | |
| Radar Fraud ML | SERVICE | PythonMLC++ | Real-time machine learning engine evaluating fraud risk on every single transaction | |
| Card Network / Bank | EXTERNAL | ISO 8583Card Networks | Visa, Mastercard, American Express, and acquiring banks | |
| Webhook Service | SERVICE | GoSQSRedis | Guaranteed webhook delivery engine dispatching payment events to merchant servers | |
| Ledger Service | DATABASE | PostgreSQLLedger Engine | Double-entry immutable accounting ledger where total debits always equal total credits | |
| Payment DB | DATABASE | PostgreSQLSpanner | Sharded transactional database storing immutable charge records and idempotency locks | |
| Immutable Audit Log | DATABASE | ClickHouseKafka | Append-only cryptographic event log for financial regulatory compliance |