Research

Notes from production work. Each entry states the finding, the evidence, and what changed because of it.

Server-side pricing beats client-reported costs

Finding: When clients report their own AI spend, the numbers can’t be trusted — models drift, prices change, and callers round. The reliable pattern is to ingest raw token counts and price them server-side against a versioned table.

Evidence: Ondari (ondari.dev) prices every event from inputTokens/outputTokens against a live price table with source and verification date. Unknown models are accepted but marked unpriced rather than rejected or guessed. A measured production event — 2,400 input + 800 output tokens on claude-sonnet-4.5 — prices at $0.0192, reproducible to the token.

Changed: Client SDKs never send prices. The price table is itself a product surface (live pricing page, change feed).

ORM codegen can fail silently — gate the deploy, not just the tests

Finding: Prisma’s client generator can emit an empty client (zero models) while reporting success and exiting 0. The failure survived version changes (5.22.0, 6.4.1, 6.19.3), minimal schemas, and three hosts (macOS, Linux, Docker), which points upstream rather than local. Filed as prisma/orm#30267.

Evidence: prisma validate and prisma db push stayed healthy — only the codegen compiler output was empty. Full matrix documented before stopping the version hunt.

Changed: Two mitigations shipped the same week: (1) new tables via raw DDL + parameterized $queryRaw/$executeRaw, proven end-to-end before use; (2) a pre-restart deploy gate that verifies build output and a loadable client, refusing to restart the live app on failure. Tests passing is not the same as safe to ship.

Idempotency keys make event ingestion replay-safe

Finding: Retries are inevitable (timeouts, 429s, deploys mid-batch). Without idempotency, every retry risks double-counting spend — the worst failure mode for a cost tracker.

Evidence: Every ingested event carries an idempotency_key backed by a uniqueness constraint; replays return the original result instead of duplicating. SDKs generate one automatically when the caller omits it, and batch mode (up to 1,000 events) stays atomic per event.

Changed: Retry-with-same-key is the documented safe pattern across all three SDKs (Python, JS, PHP).