POST /citations, POST /calls, POST /sanctions and POST /webhooks accept it. Without the header, the POST goes through as is.
The key is 1 to 100 characters: letters, digits, _, -, : and dot. Otherwise, 400 invalid_idempotency_key. A new UUID per operation works well.
It is per server and is kept for at least 24 hours.
The same key with a different body or on another route is your mistake, not a retry: 422 idempotency_key_reused. The order of JSON fields does not matter.
While the first one is still running, 409 idempotency_in_progress: wait and retry.
A 4xx error is also the answer to that key and is repeated as is. A 5xx is not stored: retrying really tries again.
For CAD calls, the key is also stored on the call itself: a retry never creates a second one.