Friday, August 21, 2026

JWT Authentication & Authorization — Complete Flow


Imagine the application has:

  • Angular / React frontend

  • ASP.NET Core Web API

  • SQL Server database

  • JWT-based authentication

The overall flow is:

User
  |
  | 1. Login: username + password
  v
Frontend
  |
  | 2. POST /api/auth/login
  v
Web API
  |
  | 3. Validate credentials
  v
Database
  |
  | 4. User is valid
  v
Web API
  |
  | 5. Create JWT
  v
Frontend
  |
  | 6. Store JWT
  |
  | 7. Send JWT in Authorization Header
  v
Web API
  |
  | 8. Validate JWT
  |
  | 9. Authentication
  |
  | 10. Authorization
  v
Controller
  |
  v
Response

Now let's understand every step.


1. What problem does JWT solve?

Suppose a user logs into your application.

Username: mahesh
Password: ********

The API verifies the username and password.

But after login, the API needs to know:

"Who is making this next request?"

For example:

GET /api/orders

The API needs to know:

Which user?
Is the user authenticated?
What roles does the user have?
Is the user allowed to access orders?

JWT provides a way for the client to prove its identity on subsequent requests.


2. Where does the JWT flow start?

The JWT authentication flow starts when the user performs login.

For example:

POST /api/auth/login

Request:

{
    "username": "mahesh",
    "password": "Password123"
}

The request reaches the Authentication API.


3. Step 1 — User sends credentials

The frontend sends:

Username
Password

to:

POST /api/auth/login

For example:

Angular Application
       |
       | username + password
       v
ASP.NET Core Web API

The password should be transmitted over HTTPS, not plain HTTP.


4. Step 2 — API validates the user

The API receives the credentials.

It queries the database:

SELECT Id, UserName, PasswordHash, Role
FROM Users
WHERE UserName = 'mahesh'

The application should compare the supplied password against the stored password hash.

It should not store plain-text passwords.

If authentication fails:

401 Unauthorized

If authentication succeeds:

UserId       = 101
Username     = mahesh
Role         = Customer

Now the API can create a JWT.


5. Step 3 — JWT is created

A JWT normally looks like this:

xxxxx.yyyyy.zzzzz

There are three parts:

HEADER.PAYLOAD.SIGNATURE

For example:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
.
eyJzdWIiOiIxMDEiLCJyb2xlIjoiQ3VzdG9tZXIifQ
.
abc123xyz...

These three parts have different responsibilities.


6. JWT Header

The header contains information about the token.

Example:

{
  "alg": "HS256",
  "typ": "JWT"
}

alg

This tells the receiver which signing algorithm is being used.

For example:

HS256

or:

RS256

typ

This tells us the token type:

JWT

Conceptually:

HEADER
   |
   +-- Algorithm
   |
   +-- Token Type

7. JWT Payload

The payload contains claims.

For example:

{
  "sub": "101",
  "name": "Mahesh",
  "role": "Customer",
  "email": "mahesh@example.com",
  "exp": 1787220000
}

These are called claims.

Common claims include:

ClaimMeaning
subSubject/User ID
nameUser name
emailEmail
roleUser role
issToken issuer
audIntended audience
iatIssued-at time
expExpiration time

For example:

{
   "sub": "101",
   "role": "Admin"
}

means:

User ID = 101
Role = Admin

Important security point

The JWT payload is encoded, not encrypted, in a normal JWT.

Therefore, don't put sensitive information such as:

Password
Credit card number
Secret keys

inside the payload.


8. JWT Signature

This is the most important part for understanding JWT security.

Conceptually, the server takes:

Base64Url(Header)
+
"."
+
Base64Url(Payload)

and signs that data using a secret/private key.

For example, conceptually with HMAC:

Signature =
HMACSHA256(
    Base64Url(Header) + "." +
    Base64Url(Payload),
    SecretKey
)

The result becomes:

HEADER.PAYLOAD.SIGNATURE

9. Why do we need the Signature?

Imagine the original payload is:

{
    "userId": 101,
    "role": "Customer"
}

An attacker might try to change it to:

{
    "userId": 101,
    "role": "Admin"
}

But the attacker doesn't have the signing secret/private key.

Therefore, they cannot generate a valid signature for the modified payload.

When the API receives the token, it validates the signature.

If the token was modified:

Payload changed
      ↓
Signature no longer matches
      ↓
JWT validation fails
      ↓
401 Unauthorized

So the signature provides integrity/authenticity of the token, assuming the signing key is properly protected.


10. JWT is returned to the client

After successful login:

Web API
   |
   | JWT
   v
Frontend

For example:

{
    "accessToken": "eyJhbGciOiJIUzI1NiIs..."
}

Now the frontend has the access token.


11. What happens on the next API request?

Suppose the user wants to see orders.

Frontend sends:

GET /api/orders

But how does the API know who the user is?

The frontend sends the JWT using the HTTP Authorization header.

Authorization: Bearer eyJhbGciOiJIUzI1NiIs...

This is extremely important.


12. What is the Authorization Header?

The HTTP request looks like:

GET /api/orders HTTP/1.1
Host: api.example.com
Authorization: Bearer eyJhbGciOiJIUzI1NiIs...

There are two important pieces:

Authorization
      |
      +-- Bearer
      |
      +-- JWT Token

Bearer essentially means:

"The caller is presenting this access token as its credential."


13. Complete request flow

Now we can visualize the entire process:

                    LOGIN
                      |
                      v
              +---------------+
              |    Frontend   |
              +---------------+
                      |
                      | username/password
                      v
              +---------------+
              |   Auth API    |
              +---------------+
                      |
                      | Validate credentials
                      v
              +---------------+
              |   Database    |
              +---------------+
                      |
                      | User valid
                      v
              +---------------+
              |   Auth API    |
              +---------------+
                      |
                      | Create JWT
                      v
          +-------------------------+
          | HEADER.PAYLOAD.SIGNATURE|
          +-------------------------+
                      |
                      | JWT
                      v
              +---------------+
              |    Frontend   |
              +---------------+

Then:

                API REQUEST
                     |
                     v
              +-------------+
              |  Frontend   |
              +-------------+
                     |
                     | Authorization:
                     | Bearer JWT
                     v
              +-------------+
              |  Web API    |
              +-------------+
                     |
                     v
              JWT Middleware
                     |
             +-------+-------+
             |               |
          Invalid           Valid
             |               |
             v               v
           401          User.Identity
                           created
                              |
                              v
                       Authorization
                              |
                    +---------+---------+
                    |                   |
                 Allowed              Denied
                    |                   |
                    v                   v
                Controller             403

14. What happens inside ASP.NET Core?

Suppose we have:

[Authorize]
[HttpGet("orders")]
public IActionResult GetOrders()
{
    return Ok();
}

The request arrives:

GET /api/orders
Authorization: Bearer <JWT>

ASP.NET Core's JWT authentication middleware processes the token before the controller action executes.

Conceptually:

HTTP Request
     |
     v
ASP.NET Core Middleware
     |
     v
JWT Authentication Handler
     |
     v
Read Authorization Header
     |
     v
Extract Bearer Token
     |
     v
Validate JWT
     |
     v
Create ClaimsPrincipal
     |
     v
Authorization
     |
     v
Controller

15. JWT Validation

The API validates several things depending on its configuration.

For example:

Signature

Is the signature valid?

Issuer

Who issued this token?

Example:

https://my-auth-server

Audience

Is this token intended for my API?

Example:

my-ecommerce-api

Expiration

Has the token expired?

For example:

{
    "exp": 1787220000
}

If the current time is beyond the expiration time, the token is rejected.


16. Authentication vs Authorization

This is one of the most important interview questions.

Authentication

Authentication answers:

Who are you?

Example:

User logs in
     ↓
Username/password validated
     ↓
JWT issued
     ↓
JWT presented to API
     ↓
API validates JWT
     ↓
User is authenticated

Authentication establishes the user's identity.


17. Authorization

Authorization answers:

What are you allowed to do?

Suppose we have:

Admin
Customer
Manager

JWT:

{
    "sub": "101",
    "role": "Customer"
}

Then:

[Authorize]

means:

An authenticated user can access this endpoint.

But:

[Authorize(Roles = "Admin")]

means:

Only authenticated users with the Admin role can access this endpoint.

If a Customer calls it:

Authenticated? YES

Authorized? NO

Result:
403 Forbidden

18. 401 vs 403

This is another important interview question.

401 Unauthorized

Usually means:

Authentication failed / no valid authentication

Examples:

No token
Invalid token
Expired token
Invalid signature

Conceptually:

Who are you?
→ I can't authenticate you.

403 Forbidden

Means:

You are authenticated,
but you don't have permission.

Example:

User = Customer

Endpoint requires = Admin

Result:

403 Forbidden

Think:

401 = I don't know who you are.

403 = I know who you are,
      but you're not allowed.

19. Authentication + Authorization Example

Suppose:

[Authorize]
[HttpGet("profile")]
public IActionResult Profile()
{
    return Ok();
}

Any authenticated user can access it.

But:

[Authorize(Roles = "Admin")]
[HttpDelete("users/{id}")]
public IActionResult DeleteUser(int id)
{
    return Ok();
}

Only Admin users can access it.

The flow becomes:

JWT
 |
 v
Signature validation
 |
 v
Token valid?
 |
 +---- NO ----> 401
 |
 YES
 |
 v
Authentication successful
 |
 v
Read Claims
 |
 v
Role = Customer?
 |
 v
Endpoint requires Admin
 |
 v
Authorization fails
 |
 v
403 Forbidden

20. Where does the Role come from?

The role can be included as a JWT claim.

Example:

{
    "sub": "101",
    "name": "Mahesh",
    "role": "Admin"
}

ASP.NET Core converts JWT claims into a ClaimsPrincipal.

You can then access claims:

var userId = User.FindFirst("sub")?.Value;

or:

var role = User.FindFirst("role")?.Value;

Depending on configuration, role claims can also be accessed through:

User.IsInRole("Admin")

21. How does ASP.NET Core know which JWT to validate?

You configure JWT authentication in the application.

Conceptually:

builder.Services
    .AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(options =>
    {
        options.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateIssuer = true,
            ValidateAudience = true,
            ValidateLifetime = true,
            ValidateIssuerSigningKey = true,

            ValidIssuer = "...",
            ValidAudience = "...",
            IssuerSigningKey = ...
        };
    });

And:

app.UseAuthentication();
app.UseAuthorization();

The order is important:

UseAuthentication()
        ↓
UseAuthorization()
        ↓
MapControllers()

Authentication must establish the user's identity before authorization makes the access decision.


22. Why is the Header important?

There are actually two places where "header" can mean different things.

JWT Header

Inside the JWT:

{
   "alg": "HS256",
   "typ": "JWT"
}

This describes the token.

HTTP Authorization Header

Outside the JWT:

Authorization: Bearer <token>

This transports the JWT from the client to the API.

So:

JWT Header
     ↓
Describes JWT

HTTP Authorization Header
     ↓
Carries JWT to API

Don't confuse these two.


23. Complete E-Commerce Example

Let's imagine an e-commerce application.

User:

Mahesh
UserId = 101
Role = Customer

Step 1 — Login

POST /api/auth/login
{
   "username": "mahesh",
   "password": "********"
}

Step 2 — Database validation

Username exists?
        ↓
Password valid?
        ↓
Role = Customer
        ↓
YES

Step 3 — JWT creation

Payload:

{
   "sub": "101",
   "name": "Mahesh",
   "role": "Customer",
   "exp": "..."
}

JWT:

HEADER.PAYLOAD.SIGNATURE

Step 4 — JWT returned

Authentication API
       ↓
      JWT
       ↓
    Frontend

Step 5 — Get orders

GET /api/orders
Authorization: Bearer <JWT>

Step 6 — API validates JWT

Token exists?
     ↓
Signature valid?
     ↓
Issuer valid?
     ↓
Audience valid?
     ↓
Token expired?
     ↓
All valid

Step 7 — Authentication

User = Mahesh
UserId = 101
Role = Customer

Step 8 — Authorization

Suppose:

[Authorize]

Customer is allowed.

Therefore:

Controller executes

24. What if the JWT is modified?

Original:

{
   "userId": 101,
   "role": "Customer"
}

Attacker changes it:

{
   "userId": 101,
   "role": "Admin"
}

The attacker doesn't have the signing key.

Therefore:

Modified Payload
       ↓
Signature doesn't match
       ↓
JWT validation fails
       ↓
Authentication fails
       ↓
401

This is why the signature is critical.


25. What if the JWT is expired?

Suppose:

{
   "sub": "101",
   "exp": 1787220000
}

The API checks:

Current time > exp?

If yes:

Token expired
     ↓
Authentication fails
     ↓
401 Unauthorized

The frontend can then obtain a new access token using an appropriate token renewal mechanism, such as a refresh-token flow, depending on the authentication architecture.


26. Does every API call query the User table?

Not necessarily.

That's one of the major benefits of JWT.

For a properly configured self-contained JWT, the API can validate:

Signature
Issuer
Audience
Expiration
Claims

without querying the user database on every request.

For example:

Request
   ↓
JWT
   ↓
Signature validation
   ↓
Claims
   ↓
Authorization
   ↓
Controller

However, applications sometimes still consult a database/cache for things such as account status, revocation, permissions that must change immediately, or other business rules.


27. Where is the JWT stored?

This depends on the frontend architecture and security requirements.

A common browser approach is to use secure cookie-based mechanisms, especially when designed to mitigate token theft/XSS risks.

Another approach is storing an access token in browser storage, but storing long-lived authentication tokens in localStorage has important security trade-offs because JavaScript can access it.

For a production system, token storage should be designed together with:

HTTPS
XSS protection
CSRF protection
Token lifetime
Refresh-token strategy
Cookie settings

28. JWT Flow — Start to End

Here's the complete flow you can remember for interviews:

                 ┌──────────────┐
                 │     USER     │
                 └──────┬───────┘
                        │
                        │ Login
                        ▼
                 ┌──────────────┐
                 │   FRONTEND   │
                 └──────┬───────┘
                        │
                        │ username/password
                        ▼
                 ┌──────────────┐
                 │  AUTH API    │
                 └──────┬───────┘
                        │
                        │ Validate
                        ▼
                 ┌──────────────┐
                 │   DATABASE   │
                 └──────┬───────┘
                        │
                        │ Valid
                        ▼
                 ┌──────────────┐
                 │  JWT CREATE  │
                 └──────┬───────┘
                        │
                        │
                HEADER.PAYLOAD
                  .SIGNATURE
                        │
                        ▼
                 ┌──────────────┐
                 │   FRONTEND   │
                 └──────┬───────┘
                        │
                        │ Authorization:
                        │ Bearer JWT
                        ▼
                 ┌──────────────┐
                 │   WEB API    │
                 └──────┬───────┘
                        │
                        ▼
                JWT VALIDATION
                        │
             ┌──────────┴──────────┐
             │                     │
          Invalid                 Valid
             │                     │
             ▼                     ▼
            401              Authentication
                                  │
                                  ▼
                            Authorization
                                  │
                    ┌─────────────┴────────────┐
                    │                          │
                 Allowed                    Denied
                    │                          │
                    ▼                          ▼
               Controller                    403
                    │
                    ▼
                 Response

29. The most important distinction

Remember these three concepts:

Header

What algorithm/type is this JWT using?

Payload

Who is the user?
What claims/attributes are associated with the token?

Signature

Has the token been altered,
and can it be validated using the expected signing key?

And remember:

HTTP Authorization Header
        ↓
Carries JWT

JWT Header
        ↓
Describes JWT

JWT Payload
        ↓
Contains Claims

JWT Signature
        ↓
Protects token integrity/authenticity

30. One-line interview answer

If an interviewer asks:

"Explain JWT authentication flow."

A strong answer is:

"When a user logs in, the authentication service validates the credentials and creates a signed JWT containing claims such as user ID, issuer, audience, role and expiration. The client then sends that token with subsequent API requests in the HTTP Authorization header using the Bearer scheme. ASP.NET Core's JWT authentication middleware extracts and validates the token's signature, issuer, audience and lifetime and creates the authenticated ClaimsPrincipal. The authorization middleware then evaluates policies or roles, such as [Authorize(Roles = "Admin")]. If authentication fails, the API returns 401; if authentication succeeds but authorization fails, it returns 403. If both succeed, the request reaches the controller."

That is the complete JWT authentication → authorization flow from login to API response.

Thursday, August 20, 2026

Saga Design Pattern – Complete Guide with E-Commerce Example

1. What Problem Does Saga Solve?

Imagine an e-commerce application with these microservices:

                    E-Commerce Application
                            |
        +-------------------+-------------------+
        |                   |                   |
   Order Service       Payment Service     Inventory Service
        |                   |                   |
        +-------------------+-------------------+
                            |
                    Shipping Service

A customer places an order.

The business process might be:

Create Order
    ↓
Reserve Inventory
    ↓
Process Payment
    ↓
Create Shipment
    ↓
Order Completed

The problem is that each operation belongs to a different database.

For example:

Order Service       → OrderDB
Inventory Service   → InventoryDB
Payment Service     → PaymentDB
Shipping Service    → ShippingDB

We cannot normally use a single SQL transaction such as:

BEGIN TRANSACTION

OrderDB
InventoryDB
PaymentDB
ShippingDB

COMMIT

because these are independent microservices.

This is where Saga Pattern comes in.


2. What Is Saga Design Pattern?

A Saga is a sequence of local transactions where each microservice performs its own transaction.

If one transaction fails, previously completed transactions are compensated by executing corresponding compensating transactions.

Conceptually:

Transaction 1
     ↓
Transaction 2
     ↓
Transaction 3
     ↓
Transaction 4

If Transaction 3 fails:

Transaction 1 ✓
Transaction 2 ✓
Transaction 3 ✗

        ↓

Compensation 2
        ↓
Compensation 1

So instead of a traditional distributed ACID transaction, Saga provides eventual consistency using local transactions + compensation.


3. E-Commerce Example

Suppose customer places an order:

Order #1001

Product: Laptop
Quantity: 1
Price: ₹80,000

The workflow is:

Customer
   |
   ↓
Order Service
   |
   ↓
Inventory Service
   |
   ↓
Payment Service
   |
   ↓
Shipping Service
   |
   ↓
Order Completed

Let's define the transactions.

T1 – Create Order

Order Service:

Order Status = Pending

T2 – Reserve Inventory

Inventory Service:

Laptop Stock
100 → 99

T3 – Process Payment

Payment Service:

₹80,000 charged

T4 – Create Shipment

Shipping Service:

Shipment Created

Finally:

Order Status = Confirmed

4. What Happens If Payment Fails?

Suppose:

T1 Create Order        ✓
T2 Reserve Inventory   ✓
T3 Payment             ✗

We cannot simply rollback T1 and T2 using a normal database rollback because they happened in different databases.

Instead:

Payment Failed
      ↓
Release Inventory
      ↓
Cancel Order

So:

T1 Create Order ✓
       ↓
T2 Reserve Stock ✓
       ↓
T3 Payment ✗
       ↓
C2 Release Stock ✓
       ↓
C1 Cancel Order ✓

This is the core concept of Saga.


5. Saga Has Two Main Approaches

There are two major implementations.

Approach 1 – Choreography

Services communicate through events.

Order Service
     |
 OrderCreated
     ↓
Inventory Service
     |
InventoryReserved
     ↓
Payment Service
     |
PaymentCompleted
     ↓
Shipping Service

There is no central coordinator.


Approach 2 – Orchestration

A central Saga Orchestrator controls the workflow.

                 Saga Orchestrator
                        |
          +-------------+-------------+
          |             |             |
          ↓             ↓             ↓
      Order          Inventory      Payment
      Service         Service       Service
                                      |
                                      ↓
                                  Shipping

The orchestrator says:

Reserve inventory

then:

Process payment

then:

Create shipment

If something fails:

Release inventory
Cancel order

For an enterprise e-commerce application, orchestration is often easier to understand and manage, especially when the workflow becomes complex.


6. Which One Should We Use?

FeatureChoreographyOrchestration
Central controllerNoYes
Simple workflowsExcellentGood
Complex workflowsDifficultExcellent
DebuggingDifficultEasier
Business workflow visibilityLowerHigher
CouplingEvent-basedOrchestrator-based
Failure handlingDistributedCentralized
Large enterprise workflowsCan become complicatedOften preferable

For the example below, I'll use Saga Orchestration.


7. Overall Architecture

Let's design the system.

                         Client
                           |
                           ↓
                    API Gateway
                           |
                           ↓
                    Order Service
                           |
                           ↓
                  Saga Orchestrator
                           |
          +----------------+----------------+
          |                |                |
          ↓                ↓                ↓
     Inventory          Payment          Shipping
      Service           Service           Service
          |                |                |
      InventoryDB       PaymentDB       ShippingDB

Communication could use:

Azure Service Bus
Kafka
RabbitMQ

For an Azure-based .NET system, Azure Service Bus is a natural choice.


8. Database Design

An important Saga principle is:

Each microservice owns its own database.

Don't do this:

Order Service
       |
       ↓
Shared Database
       ↑
       |
Inventory Service

Instead:

Order Service
     ↓
OrderDB

Inventory Service
     ↓
InventoryDB

Payment Service
     ↓
PaymentDB

Shipping Service
     ↓
ShippingDB

9. Order Model

Order Service might have:

public class Order
{
    public Guid Id { get; set; }

    public Guid CustomerId { get; set; }

    public decimal TotalAmount { get; set; }

    public OrderStatus Status { get; set; }

    public DateTime CreatedAt { get; set; }
}

Status:

public enum OrderStatus
{
    Pending,
    InventoryReserved,
    PaymentProcessing,
    Confirmed,
    Failed,
    Cancelled
}

10. Order Items

public class OrderItem
{
    public Guid Id { get; set; }

    public Guid OrderId { get; set; }

    public Guid ProductId { get; set; }

    public int Quantity { get; set; }

    public decimal Price { get; set; }
}

11. Inventory Model

Inventory Service owns:

public class Inventory
{
    public Guid ProductId { get; set; }

    public int AvailableQuantity { get; set; }

    public int ReservedQuantity { get; set; }
}

Example:

Product       Available     Reserved

Laptop          100            0

After reservation:

Laptop           99            1

12. Inventory Reservation Model

We should maintain a separate reservation record.

public class InventoryReservation
{
    public Guid Id { get; set; }

    public Guid OrderId { get; set; }

    public Guid ProductId { get; set; }

    public int Quantity { get; set; }

    public ReservationStatus Status { get; set; }
}

Status:

public enum ReservationStatus
{
    Reserved,
    Released
}

Why?

Because Saga requires us to know:

What exactly should I compensate?


13. Payment Model

Payment Service:

public class Payment
{
    public Guid Id { get; set; }

    public Guid OrderId { get; set; }

    public decimal Amount { get; set; }

    public PaymentStatus Status { get; set; }

    public string TransactionReference { get; set; }
}

Status:

public enum PaymentStatus
{
    Pending,
    Completed,
    Failed,
    Refunded
}

14. Shipment Model

Shipping Service:

public class Shipment
{
    public Guid Id { get; set; }

    public Guid OrderId { get; set; }

    public string Address { get; set; }

    public ShipmentStatus Status { get; set; }
}

15. Saga State Model

The orchestrator should maintain Saga state.

For example:

public class OrderSaga
{
    public Guid SagaId { get; set; }

    public Guid OrderId { get; set; }

    public SagaStatus Status { get; set; }

    public bool OrderCreated { get; set; }

    public bool InventoryReserved { get; set; }

    public bool PaymentCompleted { get; set; }

    public bool ShipmentCreated { get; set; }

    public DateTime CreatedAt { get; set; }

    public DateTime UpdatedAt { get; set; }
}

This becomes very useful for:

  • monitoring

  • retries

  • recovery

  • debugging

  • compensation


16. Complete Saga Flow

Let's look at the complete process.

Customer
   |
   | Place Order
   ↓
Order Service
   |
   | Order Created
   ↓
Saga Orchestrator
   |
   | Reserve Inventory
   ↓
Inventory Service
   |
   | Inventory Reserved
   ↓
Saga Orchestrator
   |
   | Process Payment
   ↓
Payment Service
   |
   | Payment Completed
   ↓
Saga Orchestrator
   |
   | Create Shipment
   ↓
Shipping Service
   |
   | Shipment Created
   ↓
Saga Orchestrator
   |
   ↓
Order Confirmed

17. Step 1 – Customer Creates Order

Client:

POST /api/orders

Request:

{
  "customerId": "C001",
  "items": [
    {
      "productId": "P100",
      "quantity": 1
    }
  ]
}

Order Service creates:

OrderId = 1001
Status = Pending

Database:

Orders

1001 | C001 | 80000 | Pending

Then publish:

OrderCreated

Event:

public record OrderCreatedEvent(
    Guid OrderId,
    Guid CustomerId,
    decimal Amount);

18. Step 2 – Saga Starts

The orchestrator receives:

OrderCreated

It creates:

SagaId = S1001
OrderId = 1001
Status = Started

Then sends:

ReserveInventory

19. Step 3 – Inventory Reservation

Inventory Service receives:

{
  "sagaId": "S1001",
  "orderId": "1001",
  "productId": "P100",
  "quantity": 1
}

It executes a local database transaction.

For example:

BEGIN TRANSACTION

Check available stock

Available = Available - 1

Create Reservation

COMMIT

Database becomes:

Available = 99
Reserved = 1

Then publish:

InventoryReserved

20. Step 4 – Payment

Saga orchestrator receives:

InventoryReserved

Then sends:

ProcessPayment

Payment Service:

BEGIN TRANSACTION

Create Payment
Status = Processing

Call payment provider

Payment successful

Status = Completed

COMMIT

Then:

PaymentCompleted

21. Step 5 – Shipping

Saga receives:

PaymentCompleted

Then:

CreateShipment

Shipping Service creates:

ShipmentId = SH1001
OrderId = 1001
Status = Created

Then publishes:

ShipmentCreated

22. Step 6 – Complete Saga

Saga Orchestrator receives:

ShipmentCreated

Now:

OrderCreated       ✓
InventoryReserved  ✓
PaymentCompleted   ✓
ShipmentCreated    ✓

So:

Saga Status = Completed

And Order Service is instructed:

ConfirmOrder

Order:

1001 | Confirmed

23. What Happens When Payment Fails?

This is where Saga becomes interesting.

Suppose:

Order Created       ✓
Inventory Reserved  ✓
Payment             ✗

The orchestrator receives:

PaymentFailed

It knows:

InventoryReserved = true
PaymentCompleted = false

Therefore compensation is required.


24. Compensation Flow

The orchestrator sends:

ReleaseInventory

Inventory Service:

BEGIN TRANSACTION

Available = Available + 1

Reservation.Status = Released

COMMIT

Now:

Available = 100
Reserved = 0

Then orchestrator sends:

CancelOrder

Order Service:

Order.Status = Cancelled

Final state:

Order       = Cancelled
Inventory   = Released
Payment     = Failed
Saga        = Compensated

25. Important Point – Compensation Is NOT Rollback

This is one of the most important interview concepts.

Traditional transaction:

BEGIN

Operation A
Operation B
Operation C

ROLLBACK

Saga:

Operation A
Operation B
Operation C → FAILED

Compensation B
Compensation A

There is no global database rollback.

Instead:

A compensating transaction semantically reverses the business effect of a previous transaction.


26. Example: Payment Succeeds but Shipping Fails

Consider:

Order        ✓
Inventory    ✓
Payment      ✓
Shipping     ✗

Now we need to compensate.

Possible sequence:

Shipping Failed
       ↓
Refund Payment
       ↓
Release Inventory
       ↓
Cancel Order

So:

T1 Create Order       ✓
T2 Reserve Inventory  ✓
T3 Payment            ✓
T4 Shipping           ✗

C3 Refund Payment     ✓
C2 Release Inventory  ✓
C1 Cancel Order       ✓

Final:

Order = Cancelled
Inventory = Released
Payment = Refunded
Shipping = Failed

27. What If Compensation Also Fails?

This is a very important real-world scenario.

Suppose:

Payment Failed
      ↓
Release Inventory
      ↓
Inventory Service FAILED

Now:

Order = Pending
Inventory = Reserved
Payment = Failed

We cannot simply give up.

The Saga must retry the compensation.

ReleaseInventory
      ↓
FAILED
      ↓
Retry
      ↓
FAILED
      ↓
Retry
      ↓
SUCCESS

Therefore Saga implementations need:

  • Retry

  • Dead-letter queue

  • Idempotency

  • Timeout

  • Monitoring

  • Manual recovery


28. Retry Strategy

For example:

Attempt 1
   ↓
5 seconds
   ↓
Attempt 2
   ↓
30 seconds
   ↓
Attempt 3
   ↓
5 minutes

This is called exponential backoff.

For Azure Service Bus, failed messages can eventually be moved to a dead-letter queue.


29. Idempotency Is Extremely Important

Suppose:

ReserveInventory

message is delivered twice.

Without idempotency:

Message 1 → Reserve 1 item
Message 2 → Reserve another item

Incorrect:

Stock: 100 → 98

But we wanted:

Stock: 100 → 99

Therefore every command should have a unique identifier.

Example:

public class ProcessedMessage
{
    public Guid MessageId { get; set; }

    public DateTime ProcessedAt { get; set; }
}

Before processing:

Has MessageId already been processed?

If yes:

Ignore

Otherwise:

Process
Save MessageId

30. Better Idempotency Model

Instead of only MessageId, use a business operation ID.

Example:

SagaId = S1001
OrderId = 1001
Operation = ReserveInventory

Create unique constraint:

(SagaId, Operation)

Then duplicate commands cannot create duplicate reservations.


31. Transactional Outbox Pattern

There is another major problem.

Suppose Order Service does:

BEGIN TRANSACTION

Insert Order

COMMIT

Then:

Publish OrderCreated

What if the application crashes between these operations?

Database Insert ✓
Publish Event ✗

Now the order exists but Saga never receives the event.

This is where Transactional Outbox Pattern is commonly combined with Saga.


32. Outbox Table

Order Service database:

Orders
OutboxMessages

When creating the order:

BEGIN TRANSACTION

INSERT INTO Orders

INSERT INTO OutboxMessages

COMMIT

Both happen in the same local database transaction.

Example:

Orders

OrderId = 1001
Status = Pending

And:

OutboxMessages

MessageId = M1001
Type = OrderCreated
Payload = {...}
Published = false

A background publisher then reads:

Published = false

and sends the message.

After successful publishing:

Published = true

This greatly improves reliability.


33. Saga + Outbox Architecture

A robust architecture becomes:

                         Saga Orchestrator
                                |
                         Message Broker
                                |
          +---------------------+---------------------+
          |                     |                     |
          ↓                     ↓                     ↓
      Order Service        Inventory Service      Payment
          |                     |                     |
       OrderDB              InventoryDB           PaymentDB
          |                     |                     |
       Outbox                 Outbox                Outbox
          |                     |                     |
          +---------------------+---------------------+
                                |
                         Azure Service Bus

34. Commands vs Events

This distinction is important.

Command

A command tells another service:

Do something.

Examples:

CreateOrder
ReserveInventory
ProcessPayment
CreateShipment
RefundPayment
ReleaseInventory
CancelOrder

Event

An event says:

Something happened.

Examples:

OrderCreated
InventoryReserved
InventoryReservationFailed
PaymentCompleted
PaymentFailed
ShipmentCreated
ShipmentFailed

35. Example Command

public record ReserveInventoryCommand(
    Guid MessageId,
    Guid SagaId,
    Guid OrderId,
    Guid ProductId,
    int Quantity);

36. Example Event

public record InventoryReservedEvent(
    Guid MessageId,
    Guid SagaId,
    Guid OrderId);

Failure:

public record InventoryReservationFailedEvent(
    Guid MessageId,
    Guid SagaId,
    Guid OrderId,
    string Reason);

37. Saga State Machine

The orchestrator can be modeled as a state machine.

             OrderCreated
                  |
                  ↓
          InventoryPending
                  |
        +---------+---------+
        |                   |
     Success              Failure
        |                   |
        ↓                   ↓
 PaymentPending        CancelOrder
        |
   +----+----+
   |         |
Success     Failure
   |         |
   ↓         ↓
Shipping   ReleaseInventory
Pending       |
   |          ↓
Success    CancelOrder
   |
   ↓
Completed

This is a very good way to explain Saga in an interview.


38. Orchestrator Pseudocode

Conceptually:

public async Task Handle(OrderCreatedEvent message)
{
    await ReserveInventory(message);
}

When inventory succeeds:

public async Task Handle(InventoryReservedEvent message)
{
    await ProcessPayment(message);
}

Payment succeeds:

public async Task Handle(PaymentCompletedEvent message)
{
    await CreateShipment(message);
}

Shipment succeeds:

public async Task Handle(ShipmentCreatedEvent message)
{
    await ConfirmOrder(message);
}

Payment fails:

public async Task Handle(PaymentFailedEvent message)
{
    await ReleaseInventory(message);
    await CancelOrder(message);
}

39. Compensation Table

A useful way to design a Saga is to create a compensation matrix.

Forward TransactionCompensation
Create OrderCancel Order
Reserve InventoryRelease Inventory
Process PaymentRefund Payment
Create ShipmentCancel Shipment
Apply CouponRestore Coupon
Allocate Loyalty PointsReturn Loyalty Points

For every business transaction, ask:

If this succeeds and something later fails, how do I undo its business effect?

If you cannot answer that, your Saga design isn't complete.


40. Data Consistency

A common question is:

How does Saga maintain data consistency?

It does not provide immediate strong consistency across all databases like a single ACID transaction.

Instead it provides:

Eventual Consistency

For example:

Initially:

Order = Pending
Inventory = Reserved
Payment = Processing

After processing:

Order = Confirmed
Inventory = Reserved
Payment = Completed

Or if failure occurs:

Order = Cancelled
Inventory = Released
Payment = Failed

The system may temporarily have intermediate states, but eventually it reaches a valid business state.


41. Important: Don't Compensate Everything Blindly

Suppose:

Inventory reserved
Payment completed
Shipping failed

You shouldn't simply execute compensation commands without knowing the actual state.

Maintain Saga state:

InventoryReserved = true
PaymentCompleted = true
ShipmentCreated = false

Then compensation is based on completed steps.

if PaymentCompleted
    RefundPayment()

if InventoryReserved
    ReleaseInventory()

if OrderCreated
    CancelOrder()

42. Timeout Handling

Suppose Payment Service doesn't respond.

Payment Request
      ↓
Waiting...
      ↓
Waiting...
      ↓
Timeout

The orchestrator should not wait forever.

For example:

Payment timeout = 5 minutes

Then:

Payment Timeout
      ↓
Check payment status
      ↓
If unknown → retry/query provider
      ↓
If definitely failed → compensate

This is especially important with external payment gateways.


43. Why Payment Status Needs Special Care

Imagine:

Payment Service → Payment Gateway

Payment request is sent.

Gateway processes it.

But response is lost.

Your service sees:

Timeout

You must not automatically refund or retry blindly because the first payment might actually have succeeded.

You may accidentally charge the customer twice.

Instead use:

Idempotency Key

For example:

OrderId = 1001
PaymentAttempt = 1
IdempotencyKey = ORDER-1001-PAYMENT

The payment provider should treat repeated requests with the same key as the same logical operation where its API supports idempotency.


44. Handling Concurrent Orders

Suppose only one laptop remains.

Stock = 1

Two customers simultaneously order.

Customer A → Reserve
Customer B → Reserve

Inventory Service must use appropriate concurrency control.

For example:

UPDATE Inventory
SET AvailableQuantity = AvailableQuantity - 1
WHERE ProductId = @ProductId
AND AvailableQuantity >= 1;

Then check:

Rows affected = 1

Reservation succeeds.

If:

Rows affected = 0

reservation fails.

This prevents overselling.


45. Saga Failure Scenarios

Scenario 1

Order ✓
Inventory ✓
Payment ✓
Shipping ✓

Result:

Completed

Scenario 2

Order ✓
Inventory ✗

Compensation:

Cancel Order

Scenario 3

Order ✓
Inventory ✓
Payment ✗

Compensation:

Release Inventory
Cancel Order

Scenario 4

Order ✓
Inventory ✓
Payment ✓
Shipping ✗

Compensation:

Refund Payment
Release Inventory
Cancel Order

Scenario 5

Compensation fails

Solution:

Retry
 ↓
Retry
 ↓
Dead Letter Queue
 ↓
Operational Alert
 ↓
Manual Recovery

46. Azure Implementation

Since you're working with Azure/.NET, one possible architecture is:

ASP.NET Core
      |
      ↓
Order Service
      |
      ↓
Azure Service Bus
      |
      ↓
Saga Orchestrator
      |
      +----------------+
      |                |
      ↓                ↓
Inventory          Payment
Service            Service
      |                |
      ↓                ↓
 Azure SQL          Azure SQL

And:

Shipping Service
       |
       ↓
   Azure SQL

For monitoring:

Application Insights
Azure Monitor

For secrets:

Azure Key Vault

47. Azure Service Bus Structure

You might design:

Topic: ecommerce-events

Subscriptions:

order
inventory
payment
shipping
saga

Or use separate command queues:

inventory-commands
payment-commands
shipping-commands
order-commands

For orchestration, a command queue per service plus an event topic is often a clean conceptual model.


48. Message Flow

Example:

Order Service
     |
     | OrderCreated
     ↓
Service Bus
     |
     ↓
Saga Orchestrator
     |
     | ReserveInventory
     ↓
Inventory Queue
     |
     ↓
Inventory Service
     |
     | InventoryReserved
     ↓
Service Bus
     |
     ↓
Saga
     |
     | ProcessPayment
     ↓
Payment Queue

And so on.


49. Database Transactions Are Still Used

This is another important point.

Saga does not mean:

Don't use database transactions.

Each microservice should still use normal local transactions.

For example:

Inventory Service

BEGIN TRANSACTION

UPDATE Inventory

INSERT Reservation

INSERT OutboxMessage

COMMIT

This is a local ACID transaction.

Saga coordinates these local transactions.


50. The Golden Rule

Think about Saga like this:

Saga
 =
Multiple Local Transactions
 +
Messages
 +
State Machine
 +
Compensating Transactions
 +
Retry
 +
Idempotency
 +
Timeout Handling
 +
Observability

That is a much more accurate real-world definition than simply saying:

Saga is rollback for microservices.

It is not a distributed rollback mechanism.


51. Complete E-Commerce Flow

Here's the complete picture:

                         CUSTOMER
                            |
                            ↓
                       API Gateway
                            |
                            ↓
                     ORDER SERVICE
                            |
                       Create Order
                            |
                            ↓
                      OrderCreated
                            |
                            ↓
                   SAGA ORCHESTRATOR
                            |
                    Reserve Inventory
                            |
                            ↓
                   INVENTORY SERVICE
                            |
                   Inventory Reserved
                            |
                            ↓
                   SAGA ORCHESTRATOR
                            |
                     Process Payment
                            |
                            ↓
                    PAYMENT SERVICE
                            |
                     Payment Success
                            |
                            ↓
                   SAGA ORCHESTRATOR
                            |
                     Create Shipment
                            |
                            ↓
                   SHIPPING SERVICE
                            |
                    Shipment Created
                            |
                            ↓
                   SAGA ORCHESTRATOR
                            |
                            ↓
                     Confirm Order

Failure:

Payment Failed
      |
      ↓
Saga Orchestrator
      |
      +------→ Release Inventory
      |
      +------→ Cancel Order
      |
      ↓
Saga Compensated

52. Production-Grade Saga Checklist

When implementing Saga in a real application, consider all of these:

  • Saga ID

  • Correlation ID

  • Message ID

  • Idempotency

  • Saga state persistence

  • Local database transactions

  • Transactional Outbox

  • Reliable messaging

  • Retries

  • Exponential backoff

  • Timeouts

  • Dead-letter queues

  • Compensating transactions

  • Concurrency control

  • Optimistic/pessimistic locking where appropriate

  • Observability

  • Distributed tracing

  • Audit logging

  • Manual recovery

  • Poison message handling


53. Saga vs Two-Phase Commit

A common interview question is:

2PC

Coordinator
    |
    +--- DB1
    +--- DB2
    +--- DB3

Prepare
Prepare
Prepare

Commit
Commit
Commit

It attempts to provide distributed transactional atomicity, but can introduce blocking, coordination overhead, and operational complexity.

Saga:

Local Transaction
      ↓
Message
      ↓
Local Transaction
      ↓
Message

Failure:

Compensating Transaction

Saga is generally better suited to independently deployable microservices where business operations can be compensated.


54. Interview Answer

If an interviewer asks:

"Explain Saga Design Pattern with an e-commerce example."

A strong answer would be:

"Saga is a distributed transaction pattern used in microservices where a business transaction is divided into a sequence of local transactions. Each service commits its own transaction independently. If a later transaction fails, the Saga executes compensating transactions for the previously completed operations.

For example, in an e-commerce system, placing an order may involve creating the order, reserving inventory, processing payment, and creating a shipment. If payment fails after inventory has been reserved, the Saga doesn't perform a database rollback across services. Instead, it executes a compensating transaction to release the inventory and then cancels the order.

Saga can be implemented using choreography, where services communicate through events, or orchestration, where a central Saga orchestrator manages the workflow. In a production system, I would also use an outbox pattern, idempotent message processing, retries, timeouts, dead-letter queues, correlation IDs, and persistent Saga state to achieve reliable eventual consistency."


55. Recommended .NET Architecture

For a production .NET implementation, I would structure it approximately like this:

src
│
├── OrderService
│   ├── Controllers
│   ├── Domain
│   ├── Application
│   ├── Infrastructure
│   └── Messaging
│
├── InventoryService
│   ├── Domain
│   ├── Application
│   ├── Infrastructure
│   └── Messaging
│
├── PaymentService
│   ├── Domain
│   ├── Application
│   ├── Infrastructure
│   └── Messaging
│
├── ShippingService
│   ├── Domain
│   ├── Application
│   ├── Infrastructure
│   └── Messaging
│
└── OrderSaga
    ├── StateMachine
    ├── Commands
    ├── Events
    ├── Consumers
    └── Persistence

A particularly robust combination is:

Microservices
     +
Saga Orchestration
     +
Azure Service Bus
     +
Transactional Outbox
     +
Idempotent Consumers
     +
Retry/Timeout
     +
Dead Letter Queue
     +
Azure SQL
     +
Application Insights

The key idea to remember is:

Saga does not make multiple databases behave like one database. It coordinates independent local transactions and uses compensating actions to bring the overall business process to a consistent state.


Don't Copy

Protected by Copyscape Online Plagiarism Checker