OptionalgetResolve a claimed operation for restart/replica callback settlement.
Atomically install the first terminal winner. Exact retries return that
winner; an exact already-installed retry returns duplicate, and a
different terminal value returns conflict without replacing it. If a
pending settlement was installed first, implementations MUST atomically
validate its callback operation, create_media_buy task type, and any
already-bound seller task ID before committing. Invalid descriptors
return conflict without changing state. A valid pending settlement is
promoted instead of the caller's candidate and returned as
pending_completed. Promotion MUST atomically persist the pending
settlement's serverTaskId as the operation's sellerTaskId when no
seller task has been bound yet, so later exact task recording succeeds.
OptionalrecordAtomically retain an authenticated terminal callback that arrived before
the seller response bound its task ID. Durable stores should implement
this together with getByCallbackOperationId,
acknowledgePendingSettlement, and recordDeferredTaskToken for
replica-safe callbacks.
The write must be atomic with duplicate/conflict comparison and retained
through the operation's replayExpiresAt fence. Sender-callback writes at
or beyond that instant return conflict. An SDK-owned terminal observation
(publicationSource: 'sdk') may be installed later because already
dispatched seller work can finish after its monitoring window; that
pending outbox must be retained until exact-owner acknowledgement. Every
accepted sender- or SDK-owned terminal outbox extends replayExpiresAt by
at least LEGACY_PURCHASE_PUBLICATION_PROOF_RETENTION_MS from admission so
handler retry and cross-store finalization remain crash-recoverable. If a
seller task is already bound, a different settlement serverTaskId must
return conflict. A completed operation with no pending outbox or
acknowledgement proof accepts an exact terminal settlement as a
publication reservation before application dispatch. Concurrent
re-emissions of that same terminal observation may carry different
delivery idempotency keys; the first stored descriptor wins and later
callers return duplicate without replacing it. A different terminal
observation returns conflict.
OptionalacknowledgeAtomically replace a completed callback outbox entry after adopter
publication succeeds: clear pendingSettlement and install the stable,
nonempty fingerprint of that exact settlement in
acknowledgedSettlementFingerprint. The proof must be retained through
replayExpiresAt and returned by get() and
getByCallbackOperationId(). When the exact terminal result was completed
without an outbox entry, the method installs the same proof after
publication succeeds. Exact already-acknowledged retries validate that
proof and return true; a mismatched claim, settlement, or proof returns
false. Acknowledging an SDK-owned outbox must also extend
replayExpiresAt by at least
LEGACY_PURCHASE_PUBLICATION_PROOF_RETENTION_MS from acknowledgement so a
crash before deferred-checkpoint finalization remains recoverable. When
pendingSettlement exists, publicationOwnerId is mandatory
and must exactly match its current publication lease; it may be omitted
only for the completed/no-pending proof-installation case. Use
legacyPurchaseSettlementFingerprint() to compute the proof.
OptionalpublicationOwnerId: stringOptionalclaimAtomically acquire or renew publication ownership for the exact pending
settlement. Another unexpired owner returns false; an expired owner may
be replaced. lease.ownerId must be a string containing at least one
non-whitespace character; invalid values return false without storing a
lease. Implementations retain the lease only while pending remains.
OptionalreleaseRelease only the exact current publication owner, leaving the outbox retryable.
Atomically bind the seller task identity using first-writer-wins semantics.
The first bind returns true; an exact same-ID retry also returns true;
a different ID returns false and must never replace the stored ID. A
different ID already retained by pendingSettlement also returns false.
OptionalrecordAtomically replace the expected SDK continuation token for callback checkpoint recovery. Initial binding requires both stored and expected tokens to be absent. A nested pause replaces only the exact expected token; a stale expected token returns false. An exact already-installed token returns true without changing state. The operation must remain claimed, unexpired, and free of a pending terminal settlement at the atomic write boundary. Tokens are bearer capabilities: require either UUIDv4 or 43-256 URL-safe characters and reject weaker values without changing state.
OptionalexpectedDeferredTaskToken: string
Persistence contract for legacy purchase continuations.
createis an atomic put-if-absent by issuanceFingerprint.claimatomically verifies bindings and expiry, enforces the operation-wide idempotency index, and moves an available token to claimed. Implementations must not return live mutable references. Restart/replica callback recovery is an optional capability, but stores that opt in must implement callback lookup, the pending-settlement inbox, publication claim/release lease, publication acknowledgement, and deferred-token binding together.