Engineering notes · 10 October 2026
An expired lease cannot stop a worker
Worker A acquires a lease and starts work. A pauses long enough for its lease to expire. Worker B acquires the same resource and continues. Then A wakes up. The lease service can say A no longer owns the resource, but it cannot reach into A's process and prevent a write.
Enforce ownership where the effect commits
A fencing token gives each ownership grant an increasing number. The protected downstream resource records the highest accepted token and rejects an older one. The comparison and effect must happen atomically in that resource; an earlier check followed by an unprotected write leaves a race.
Worker A: grant token 41; pause; lease expires
Worker B: grant token 42; downstream accepts 42
Worker A: resumes with 41; downstream rejects 41CLAIM returns tokens as decimal strings. Compare them as integers, not lexicographically: the string "10" sorts before "9". In JavaScript use BigInt rather than Number when converting a token for comparison.
A downstream guard has its own durability requirements. Its remembered fence must survive the failures your application promises to tolerate. Fencing does not cancel already-running work, make an external API honor a token or reverse an earlier effect. If a stale write arrives before the downstream system has observed a newer fence, a token comparison alone does not prove that the old lease is still valid.
Retry the request, not a new acquisition
Persist a request_id for a logical acquire request and reuse it after a lost response. A fresh ID represents a new acquire. Replay cannot revive an expired lease. Renew before expiry, and treat renewal failure as a loss of authority until your application has established otherwise.
Use separate IDs for different requests. A fresh release returning NOT_ACTIVE does not reserve its ID; a stored successful release receipt does. Read the replay boundaries before designing recovery.
Exclusive access and bounded capacity
CLAIM supports exclusive leases and capacity-limited semaphores. An exclusive resource admits one current lease; a semaphore admits up to the configured capacity. Resources are isolated within a project. Different projects do not coordinate ownership of the same resource name.
The hosted acceptance test passed an exclusive burst of 1,000 requests and a capacity-five burst. Those tests are correctness evidence under their recorded conditions, not an unlimited-throughput SLA.
Try two independent workers
- Create a free project, confirm your email and save its API key server-side.
- Run the acquire quickstart in one process.
- Use another process and a different request_id to contend for the same resource in the same project.
- Observe DENIED while the exclusive lease is active.
- Enforce the fence in a disposable downstream resource and test how a resumed stale worker is rejected.
A local simulation can teach the failure pattern. It is not evidence that your production resource enforces fencing correctly; verify that integration separately.
Free access includes 1,000 ordinary request units per UTC month. CLAIM is £5/month for 10,000 ordinary units. Review the offer, usage limits and service terms. Send redacted integration feedback to accounts@aiagenthuddle.com.
This product explanation was prepared with AI assistance and checked against the implemented API and recorded acceptance tests.