Q: Your enterprise monetizes API calls (LLM tokens, API requests, data transfer). Every customer request must be metered, aggregated, and billed accurately. If the metering pipeline drops events, company revenue is lost; if it double-counts events, customers are illegally overcharged. How do you design an audit-compliant usage metering architecture handling 200,000 events/sec with guaranteed exactly-once billing accuracy?
Architectural design for a high-throughput, audit-compliant API usage metering and usage-based billing aggregation engine processing 200,000 API calls/sec with exactly-once aggregation in ClickHouse and Stripe integration.
Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Emit Cryptographically Signed Metering Events at API Gateway Edge
Capture consumption events at the ingress gateway without adding latency:
- Edge Metering Filter: Envoy / API Gateway generates an immutable metering event upon request completion:
{ 'event_id': 'uuidv7', 'tenant_id': 'org_99', 'metric': 'llm_tokens', 'quantity': 450, 'timestamp': 1762391029 }. - Asynchronous Non-Blocking Emission: Metering events flush to local memory buffers and stream asynchronously over gRPC, adding < 0.1ms to client response latency.
Buffer & Order Metering Events via Idempotent Apache Kafka
Prevent event loss during downstream database maintenance or traffic surges:
- Idempotent Producers: Configured Kafka producers with
enable.idempotence=trueandacks=all. - Partition Key: Partitioned Kafka topics by
tenant_idto ensure all events for a given customer are processed sequentially. - Durability: Retains 7 days of raw unaggregated metering events, allowing complete historical reprocessing if billing algorithms are updated.
Execute Exactly-Once Aggregation in ClickHouse ReplacingMergeTree
Deduplicate incoming events and compute real-time hourly and monthly billing totals:
- Deduplication Engine: Raw events write to ClickHouse table using
ReplacingMergeTree(event_id)ordered by(tenant_id, metric, event_id). - Materialized Views: Configured Materialized Views automatically aggregating consumption into 1-hour windows:
SUM(quantity) GROUP BY tenant_id, metric, toStartOfHour(timestamp). - Sub-Second Invoicing Queries: Aggregating billions of events into invoice line items executes in < 80ms.
Synchronize Aggregated Usage with Billing APIs (Stripe Metered Billing)
Push reconciled billing units to external payment gateways safely:
- Hourly Reconciliation Worker: Background worker reads confirmed hourly aggregates and calls Stripe Usage Records API:
stripe.subscriptionItems.createUsageRecord(itemId, { quantity, timestamp, action: 'set' }). - Action=Set Idempotency: Using
action: 'set'with explicit timestamps guarantees that retrying the Stripe API call never increments the customer's bill twice. - Audit Reconciliation: Nightly ledger reconciliation matches raw gateway logs against Stripe invoices with 100.000% mathematical parity.
- Emit immutable UUIDv7 metering events at the API Gateway edge with zero client latency overhead.
- Buffer events in Kafka with acks=all and idempotence enabled, partitioned by tenant_id.
- Deduplicate and aggregate billions of events in ClickHouse ReplacingMergeTree tables.
- Push reconciled usage to Stripe using idempotent action='set' calls, guaranteeing zero billing discrepancies.