Fintech & Payment Gateways

Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) (100M Transactions/Day • $10 Billion Volume • Zero Double Charges)

Staff / Principal

Architect a mission-critical payment processing platform featuring idempotent charge capture, distributed Saga transactions, immutable double-entry ledger bookkeeping, and PCI-DSS tokenization vaults.

Production Scale: 100M Transactions/Day • $10 Billion Volume • Zero Double Charges

Functional Requirements

  • •Process credit card charges, ACH transfers, and refunds with zero double billing
  • •Enforce immutable double-entry ledger where sum(debits) === sum(credits) at all times
  • •Send real-time webhook event notifications with guaranteed at-least-once delivery

Non-Functional Requirements

  • •Strict ACID transaction consistency across financial accounts
  • •PCI-DSS Level 1 compliance (Zero raw card numbers stored in application databases)
  • •99.999% availability with zero silent transaction drops

Capacity & Scale Estimation

Transaction Volume100 Million charges / day (~1,200 TPS, 10k peak)
Daily Monetary Volume$10 Billion processed daily
Ledger Storage Growth~500 GB / month of immutable append-only records
Webhook Dispatch300 Million webhook payloads / day

Core Architectural Components

1Card Tokenization Vault (Isolated HSM)

Hardware Security Module (HSM) encrypting PANs with AES-256-GCM, returning non-sensitive surrogate tokens to the core app.

2Idempotency Layer (Redis Cluster)

Stores `Idempotency-Key` hash with lock state; duplicate client requests within 24h return cached responses immediately.

3Payment Orchestrator & Saga State Machine

Coordinates multi-step checkout workflow (Authorize -> Tokenize -> Acquire -> Settle -> Notify) with compensating transactions.

4Immutable Double-Entry Ledger (PostgreSQL / CockroachDB)

Append-only relational ledger enforcing zero row updates; every monetary transfer creates equal debits and credits.

5Webhook Retry Dispatcher (Kafka + Dead Letter Queue)

Dispatches HTTPS webhooks to merchant endpoints with exponential backoff retries over 72 hours.

Architectural FAQs & Interview Deep Dives

What are the core functional and non-functional requirements for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Functional requirements define user-facing capabilities, while non-functional requirements mandate high availability (99.99%), sub-100ms p99 latency, horizontal scalability, and data durability.

How do you calculate QPS, storage, and bandwidth capacity estimates for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Estimate daily active users (DAU), read/write ratio (e.g. 100:1), average payload size (e.g. 2KB), and calculate peak QPS (2–3x average) and 5-year storage projections.

How do you design the high-level API schema (REST / gRPC) for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Expose idempotent endpoints with explicit authentication headers, rate-limiting metadata, pagination cursors, and structured JSON / Protobuf error schemas.

What database paradigm (Relational SQL vs NoSQL vs Graph) is optimal for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Relational SQL (PostgreSQL) is chosen for ACID transactions and structured queries, NoSQL (Cassandra/DynamoDB) for high-write key-values, and Vector/Graph DBs for specialized relationships.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) implement database sharding and partitioning?

By using consistent hashing on user/entity IDs with virtual nodes, distributing partition keys uniformly across shards while preventing hot partitions.

How do you prevent cache stampedes (thundering herds) in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Use probabilistic early expiration (XFetch algorithm), distributed mutex locks, or pre-warming background worker threads before keys expire.

What caching strategy (Cache-Aside, Write-Through, Write-Behind) is best for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Cache-Aside is standard for read-heavy workloads, while Write-Through guarantees consistency at the cost of write latency.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) guarantee idempotency for financial transactions and mutations?

Clients send unique idempotency keys in request headers, which are stored in Redis/PostgreSQL with unique constraints to reject duplicate execution.

How do you handle distributed transactions and consistency across microservices in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Implement the Saga Pattern (choreography or orchestration) with compensating transactions to ensure eventual consistency without two-phase commit locks.

What message broker (Kafka vs RabbitMQ vs NATS) should be selected for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Apache Kafka is optimal for high-throughput event replay and partitioning, RabbitMQ for complex AMQP routing, and NATS JetStream for ultra-low latency messaging.

How do you handle message deduplication and out-of-order delivery in event streams for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Use monotonic event sequence numbers, store processed event IDs in transactional tables, and ensure consumer handlers are strictly idempotent.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) implement rate limiting at the API gateway layer?

Employ the Token Bucket or Sliding Window Log algorithm implemented with Redis Lua scripts to enforce client IP and account tier limits.

How do you design leader election and distributed consensus for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Use Raft or Paxos consensus engines (etcd, Consul, ZooKeeper) to maintain deterministic leader election and distributed lock state.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) scale WebSocket and real-time bidirectional connections?

Stateless WebSocket gateway servers maintain open TCP connections, backed by Redis Pub/Sub or Kafka to route messages across cluster nodes.

How do you handle multi-region active-active database replication in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Use CRDTs (Conflict-Free Replicated Data Types) or Last-Write-Wins timestamps with vector clocks to resolve cross-region concurrent write conflicts.

What is the Disaster Recovery (DR) strategy and RPO/RTO targets for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Define Recovery Point Objective (RPO < 1 min) and Recovery Time Objective (RTO < 5 min) supported by automated cross-region DNS failover (Route 53).

How do you prevent single points of failure (SPOF) across Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) architecture?

Ensure every component (load balancers, web servers, databases, queues) runs with at least N+1 redundancy across independent cloud Availability Zones.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) isolate noisy neighbors in multi-tenant environments?

Implement separate worker pools, per-tenant rate limits, dedicated database schemas, and fair-share queue scheduling.

How do you handle large file uploads and streaming media in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Generate presigned S3/GCS upload URLs allowing clients to upload directly to object storage with multipart chunking and background event processing.

How do you design full-text search and filtering capabilities for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Stream database CDC (Change Data Capture) events via Debezium and Kafka to Elasticsearch, OpenSearch, or ClickHouse for sub-second analytical search.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) manage connection pooling under high concurrency?

Deploy database proxy layers (PgBouncer, ProxySQL) in transaction pooling mode to multiplex thousands of client connections over a compact server pool.

How do you execute zero-downtime database schema migrations for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Follow the Expand-Contract pattern: 1) Add new column/table, 2) Dual-write to both old and new schemas, 3) Backfill historical data, 4) Read from new schema, 5) Drop old column.

How do you implement distributed tracing across microservices in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Propagate W3C Trace Context headers (`traceparent`) across HTTP/gRPC boundaries and send spans to Jaeger or Grafana Tempo via OpenTelemetry collectors.

What metrics are most critical on the primary dashboard for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Monitor the Four Golden Signals: Latency (p50, p95, p99), Traffic (QPS), Errors (5xx rate), and Saturation (CPU, RAM, connection pool usage).

How do you design graceful degradation and circuit breakers in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Implement Resilience4j / Polly circuit breakers that open when upstream failure rates exceed 50%, serving cached fallback data rather than blocking.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) secure sensitive data at rest and in transit?

Enforce TLS 1.3 encryption in transit and AES-256-GCM / KMS envelope encryption at rest, with automated key rotation.

How do you implement Role-Based Access Control (RBAC) and ABAC in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Evaluate fine-grained permissions using Open Policy Agent (OPA) or Zanzibar-style relation graphs (Ory Keto) for low-latency authorization checks.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) prevent Distributed Denial of Service (DDoS) attacks?

Deploy edge CDNs with anycast routing (Cloudflare, AWS CloudFront), implement SYN flood protection, and enforce IP reputation rate limits.

How do you handle asynchronous background jobs and retry dead-letter queues in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Enqueue tasks to background worker pools (Celery, Sidekiq, Temporal) with exponential backoff retries and route permanently failing tasks to Dead Letter Queues (DLQ).

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) optimize cloud infrastructure costs (FinOps)?

Use auto-scaling spot instances for stateless workloads, purchase reserved instances for baseline database capacity, and implement S3 object storage lifecycle policies.

How do you manage DNS routing and traffic distribution for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Use latency-based or geolocation DNS routing with health-checked weighted target endpoints.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) handle distributed locking across multiple instances?

Utilize Redis Redlock algorithm or database advisory locks with explicit TTL lease renewal.

What serialization format is best for inter-service communication in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Protobuf over gRPC for internal low-latency microservices and JSON over HTTPS for external public APIs.

How do you structure database read replicas and replica lag mitigation for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Route read-only queries to asynchronous replicas while directing time-sensitive writes to the primary database.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) prevent memory exhaustion under unconstrained pagination?

Enforce keyset / cursor-based pagination with strict maximum limit caps (e.g. max 100 items per request).

What is the best strategy for handling hot keys in the caching tier of Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Replicate hot keys across multiple cache shards using random suffix salts or local in-memory L1 cache buffers.

How do you implement change data capture (CDC) for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Read database write-ahead logs (Postgres WAL / MySQL binlog) using Debezium to stream clean entity change events.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) handle graceful server restarts during rolling deployments?

Intercept SIGTERM signals, pause inbound health checks, drain active connection pools, and exit within 30 seconds.

What strategy is used for database connection multiplexing in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Deploy transaction-level connection poolers like PgBouncer to support 10,000+ client connections without database backend thrashing.

How do you enforce security headers and CSRF protection in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Set Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), and use SameSite=Lax HttpOnly cookies.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) perform point-in-time recovery (PITR) for databases?

Archive continuous WAL segments to immutable cloud storage alongside nightly base backups.

What is the recommended logging format for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) in Kubernetes?

Emit structured JSON logs containing timestamp, level, trace_id, span_id, and service name to standard output.

How do you isolate blast radius during catastrophic service failures in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Implement bulkhead isolation patterns separating mission-critical billing workers from non-essential notification workers.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) validate semantic schema evolution in API contracts?

Use OpenAPI schemas and automated backward-compatibility linters (Spectral, Buf) in CI/CD pull request checks.

What strategy ensures zero data loss during message consumer crashes in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Disable auto-commit and acknowledge message offsets only after successful business logic execution.

How do you design multi-AZ failover for database clusters in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Configure synchronous replication to a standby instance in an adjacent Availability Zone with automated failover.

How does Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen) handle clock skew across distributed servers?

Synchronize all nodes using NTP / AWS Time Sync Service and avoid relying on physical timestamps for distributed ordering.

What approach prevents cascading failures when dependent third-party APIs slow down in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Wrap external HTTP calls in aggressive timeouts (max 2000ms) with circuit breakers and fallback responses.

How do you test system resilience against unpredictable infrastructure outages in Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Conduct automated Chaos Engineering experiments (Chaos Mesh, Gremlin) injecting simulated pod terminations and network latency.

What is the most fundamental architecture principle for Design a Distributed Payment Gateway & Immutable Double-Entry Ledger (Stripe / Adyen)?

Keep services stateless, design every operation to be idempotent, and decouple storage and compute independently.