{"templateId":"markdown","sharedDataIds":{},"props":{"metadata":{"markdoc":{"tagList":["typography","box","badge"]},"redocly_category":"Articles","type":"markdown"},"seo":{"title":"Five principles of circuit breakers","description":"Circuit breakers provide a complementary protection to timeouts. But whereas timeouts exist primarily to protect a client, circuit breakers primarily protect the service.","siteUrl":"https://docs.worldpay.com/access","image":"/access/assets/worldpay-logo-light.21b7daf79984773a9fcd7d4fbcb07ae5289dfffd6023c4c3dca720c7058e53dc.33f780a6.svg","keywords":"documentation, api, openapi, sdks, developer, payments, json, payouts, 3ds","jsonLd":{"@context":"https://schema.org","@type":"Organization","url":"https://docs.worldpay.com/access","name":"Worldpay"},"meta":[{"name":"google-site-verification","content":"zjziIKaP3ImsqsfhYnEBnq1R85UabiSwl7HTXuwtZuo"},{"name":"doc_product","content":"Access"},{"name":"doc_category","content":"Documentation"}],"llmstxt":{"hide":false,"sections":[{"title":"Payments API","description":"Payment orchestration API combining fraud assessment, 3ds authentication, SCA exemptions, Worldpay Token creation and a card or wallet based payment.","includeFiles":["products/payments/@20240601/**/*"],"excludeFiles":[]},{"title":"Payment Queries API","description":"Querying your payments data, based on a variety of parameters.","includeFiles":["products/payment-queries/@v1/**/*"],"excludeFiles":[]},{"title":"Card BIN Data API","description":"Provides detailed information about a card.","includeFiles":["products/card-bin/@v1/**/*"],"excludeFiles":[]},{"title":"3DS Authentication API","description":"Request 3DS authentication to protect against fraud, be SCA compliant and to shift liability using this standalone API.","includeFiles":["products/3ds/@v3/**/*"],"excludeFiles":[]},{"title":"FraudSight API","description":"Request a risk assessment and receive a response with an outcome (e.g. lowRisk) using this standalone API.","includeFiles":["products/fraudsight/@v1/**/*"],"excludeFiles":[]},{"title":"Checkout SDK","description":"Integrate using our clientside SDKs for both web and native devices. Benefit from SAQ-A/PCI-SSF compliance.","includeFiles":["products/checkout/web/@v2/**/*","products/checkout/ios/@v4/**/*","products/checkout/android/@v4/**/*","products/checkout/react-native/@v3/**/*","products/checkout/flutter/@v1/**/*"],"excludeFiles":[]},{"title":"Tokens API","description":"Minimizes the exposure of sensitive card details and increases the security of your customer's card details.","includeFiles":["products/tokens/@v3/**/*"],"excludeFiles":[]},{"title":"Card Payments API","description":"Request a card payment using this standalone API, requires separate requests for 3DS, Fraud assessment etc.","includeFiles":["products/card-payments/@v7/**/*"],"excludeFiles":[]},{"title":"Card Verifications API","description":"Verify your customer's card to maximize your authentication rates.","includeFiles":["products/card-verifications/@v6/**/*"],"excludeFiles":[]},{"title":"Account Payouts API","description":"Send funds to your customer's bank accounts and search for payouts using parameters.","includeFiles":["products/account-payouts/@20250101/**/*"],"excludeFiles":[]},{"title":"APMs","description":"Pay using eWallets, bank transfers, direct debits, local card schemes, Postpay and eInvoice/ Buy Now Pay Later.","includeFiles":["products/apms/@20240701/**/*"],"excludeFiles":[]},{"title":"Balance API","description":"Request your account details for a single account or all accounts under an entity.","includeFiles":["products/balance/@20250101/**/*"],"excludeFiles":[]},{"title":"Card Payouts API","description":"Send funds to your customer's cards.","includeFiles":["products/card-payouts/@v4/**/*"],"excludeFiles":[]},{"title":"Events (Webhooks)","description":"Receive status updates from Access Worldpay by setting up a webhook.","includeFiles":["products/events/@v1/**/*"],"excludeFiles":[]},{"title":"FX API","description":"Manage Foreign Exchange (FX) on your payments.","includeFiles":["products/fx/@v1/**/*"],"excludeFiles":[]},{"title":"Hosted Payment Pages (HPP) API","description":"Our low-code option to take payments securely at the lowest PCI compliance level - SAQ A.","includeFiles":["products/hosted-payment-pages/@v1/**/*"],"excludeFiles":[]},{"title":"Money Transfers API","description":"Money Transfer OCTs (Original Credit Transaction) allow funds to be pushed to an eligible card in 30 minutes or less.","includeFiles":["products/money-transfers/@v1/**/*"],"excludeFiles":[]},{"title":"Parties API","description":"Create parties, manage your payout instruments and beneficial owners and carry out identity verification checks.","includeFiles":["products/parties/@20250101/**/*"],"excludeFiles":[]},{"title":"SCA Exemptions API","description":"Maximize a frictionless checkout experience by using issuer data insights to apply exemptions.","includeFiles":["products/sca-exemptions/@v1/**/*"],"excludeFiles":[]},{"title":"Split Payments API","description":"Divide funds from a single payment amongst yourself and your parties/sellers.","includeFiles":["products/split-payments/@20250625/**/*"],"excludeFiles":[]},{"title":"Statements API","description":"Retrieve your account statement and see individual entries for all credits and debits.","includeFiles":["products/statements/@20250101/**/*"],"excludeFiles":[]},{"title":"Transfers API","description":"Transfer funds from source account to target account.","includeFiles":["products/transfers/@20250101/**/*"],"excludeFiles":[]},{"title":"Verified Tokens API","description":"Verified Tokens ensures that your customer's payment details are valid and CIT compliant when creating a token.","includeFiles":["products/verified-tokens/@v3/**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Typography","attributes":{"fontSize":"1.2em","as":"div"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/articles"},"children":["← Back to articles list"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"five-principles-of-circuit-breakers","__idx":0},"children":["Five principles of circuit breakers"]},{"$$mdtype":"Tag","name":"Box","attributes":{"display":"inline-flex","gridTemplateColumns":["1fr 1fr","1fr 1fr 1fr","1fr 1fr 1fr"],"gridGap":"1rem","mt":"1rem","mb":"1rem"},"children":[{"$$mdtype":"Tag","name":"Badge","attributes":{"size":"small","fontWeight":"bold","color":"white","mt":"0rem","mb":"0.5rem","px":"1rem","py":"0.5rem","borderRadius":"6rem","bg":"var(--wp-colour-light-blue)"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Technical"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Written by ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Andy Brodie"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," ","30 November 2020"]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Circuit breakers provide a complementary protection to timeouts. Whereas timeouts exist primarily to protect a client, circuit breakers primarily protect the service. In this article, that partners the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/articles/timeouts"},"children":["\"Talking Timeouts\" article"]},", Andy Brodie explains circuit breakers. He outlines five principles to help you use them effectively when writing clients to services."," ","Circuit breakers take their name from electrical components such as fuses, or RCDs (",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.electricalsafetyfirst.org.uk/guidance/safety-around-the-home/rcds-explained/"},"children":["Residual Current Devices"]},") often found on the power supplies for electric lawnmowers. When something goes catastrophically wrong, such as mowing through the power cable, the circuit breaker opens the circuit by disconnecting it. This prevents electricity from flowing into the lawnmower housing through the blade and potentially you. So, by using an RCD, you have made the decision not to be electrocuted and not to start an electric fire. This is a better choice than continuing to supply electricity, in the hope that the problem can be sorted out and the grass can still be cut."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This analogy is why circuit breakers use the unintuitive terms of ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["closed"]}," (good, everything is working) and ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["open"]}," (bad, everything is stopped)."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In services, circuit breakers are generally wrapped around operations that might behave unpredictably or badly if further calls are made on that operation. Operations are typically calls to downstream services or third party libraries. These are analogous to the electrical components that RCDs protect."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In their default state, circuit breakers are always closed. The logic to decide whether to open a circuit is based on analysis of recent historical behavior. Once a specified failure threshold is reached, the circuit is opened which stops any future calls being made. The circuit remains open for either a period of time or until other criteria are met. Then the circuit is closed again and normal service is resumed. Criteria might include letting a small percentage of calls go through and seeing whether they work or not."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Circuit breakers are very different from timeouts but are often, mistakenly, used in an interchangeable way. So, before you use a circuit breaker, it is really important to understand what circuit breakers are really for.  The analogy with electrical circuits is extremely relevant and useful: they are for when things are (perhaps literally) on fire. Consider the impact of a single failure when calling a downstream service, and then consider the impact of ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["not even bothering to try the call in the first place"]},", i.e. assuming failure. Therefore, circuit breakers are for situations when even attempting to do something could do more damage than not trying in the first place."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To help use circuit breakers effectively, here are some principles to consider."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Circuit breakers are primarily for protecting downstream services"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If a downstream service is failing then in most cases (see next principle) it is not logical to stop trying it to call it. A failing service will be fixed and we want to maximize availability to customers, which means doing our best to fulfil their requests."," ","This is especially relevant when you're writing a client to a third-party service, such as one that calls Access Worldpay. The vast majority of the responsibility for a service to defend itself lies with the service itself, not with the clients."]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":2},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Circuit breakers MAY be used to protect the clients against impact"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Here’s an exception to the above rule. A client may open a circuit breaker if the act of sending traffic causes damage that the downstream service is unaware of."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For example: a downstream service with side effects (such as card payment authorization) continues to accept requests but does not respond. In this case it is acceptable for the calling service to open the circuit to prevent wider damage to Worldpay."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["However, it is important to ensure that the owners of the calling service have considered:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Can timeouts be relaxed to wait for an answer, in case one comes, without risking the client's stability?"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Does the operation require it? (e.g. does it have side effects, is it easily recoverable/reconcilable)?"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can open and close circuits manually"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["It is impossible to predict every kind of catastrophic failure that may need a circuit to open. In other words you don’t know exactly how the downstream service will (mis)behave."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This is important for situations where the human operators have access to information that the client does not. There must be a \"manual override\" switch on a circuit breaker to open or close the circuit to either prevent damage or continue operations."]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":4},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Circuit breaker thresholds must be agreed between owners of both client and service"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Circuit breakers break the rules of service encapsulation, as services should be responsible for defending themselves in the event of failures.  By opening a circuit, another (calling) service, by opening a circuit, is agreeing that:"]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["\"I will sacrifice the availability of my service, by not even attempting to call you for a period of time, to minimize the overall business impact of a failure.\""]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A simpler way of expressing this principle is: \"Always give humans an override switch\"."]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":5},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["When a circuit breaker is opened, it counts against the calling service's availability (when part of a critical path)"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This clarifies the \"sacrifice\" of the first principle. If the calling service does not attempt to make the call then it cannot state that the downstream service is unavailable.  It ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["possibly"]}," is, but not ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["definitely"]},".  Therefore when a circuit is open the calling service takes the hit, by default."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This assumes, of course, that the calling service doesn't have a fall-back process, or the ability to queue requests for later processing."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"conclusion","__idx":1},"children":["Conclusion"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Circuit breakers are a powerful tool. They can help make your system more resilient and minimize the impact of major incidents. However, they must be used with care so that they do not cause more harm than good."]}]},"headings":[{"value":"Five principles of circuit breakers","id":"five-principles-of-circuit-breakers","depth":1},{"value":"Conclusion","id":"conclusion","depth":2}],"frontmatter":{"seo":{"title":"Five principles of circuit breakers","description":"Circuit breakers provide a complementary protection to timeouts. But whereas timeouts exist primarily to protect a client, circuit breakers primarily protect the service."},"markdown":{"toc":{"hide":true}}},"lastModified":"2025-10-28T16:40:42.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/articles/circuit-breakers","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}